TOTPBOX is a local-first authentication companion that manages your TOTP two-factor codes while guiding you toward modern Passkeys. Unlike password managers that bolt on TOTP as an afterthought, TOTPBOX focuses exclusively on authentication factors. Your secrets are encrypted with AES-256-GCM on-device — master keys never touch a server. What makes it different: Passkey migration built in Recovery Code Vault Browser auto-fill Stores TOTP secrets and recovery codes, never passwords
No reviews yetBe the first to leave a review for TOTPBOX
Maker
📌
Hey Product Hunt! I'm Perry, and I built TOTPBOX because I was frustrated with the state of 2FA apps.
Here's the thing: every password manager now includes TOTP codes. That's convenient, but it means a single breach exposes both your passwords AND your second factor. The whole point of 2FA is separation.
TOTPBOX enforces that boundary — it stores TOTP secrets and recovery codes, but never passwords. A breach of TOTPBOX yields no usable login credentials.
But the bigger reason I built this is the Passkey transition. TOTP was designed in 2011 (RFC 6238). Passkeys are the future — phishing-resistant, hardware-bound, no shared secrets. But adoption is uneven. You might have Passkeys for Google but still use TOTP for your bank, your VPN, and dozens of other services.
TOTPBOX helps you manage both worlds. The Auth Health Dashboard shows which accounts are still TOTP-only vs. Passkey-ready, and migration guidance walks you through upgrading each one.
Everything runs local-first. AES-256-GCM encryption on-device. Optional cloud sync operates on ciphertext only — even we can't read your data.
Would love your feedback — especially on what features would make the transition to Passkeys easier for you.