Your vault stays on this device
Secrets are encrypted before they enter Chrome local storage. LukaOTP makes no external network requests and transmits no user data; it contains no analytics, trackers, or ads.
Scan MFA QR codes from the current tab or a local image, then keep your one-time passwords in an encrypted vault inside Chrome. No account, no phone dependency, and no external network requests or user data transmitted.
Free to use · Chrome Manifest V3 · English / 简体中文 / 繁體中文
602 418
175 930
LukaOTP is designed around the real MFA setup flow: import the QR code you are already looking at, keep it locally encrypted, and get back to signing in.
Choose a strong master password. It never leaves your browser.
Scan the current tab, select a QR image, or enter the secret manually.
Search, click, and paste the code where you need it.
Actual extension UI
A dense account list keeps the next login close: search, watch the timer, and copy without leaving Chrome.
A focused authenticator that does one job well—generate your codes locally, without creating another cloud account.
Secrets are encrypted before they enter Chrome local storage. LukaOTP makes no external network requests and transmits no user data; it contains no analytics, trackers, or ads.
Import a QR code from the visible tab or a local image. Page capture happens only after your click and is processed in memory.
Search by service or account, see the countdown, and copy a 6- or 8-digit code in one click.
Your master password derives an encryption key with Argon2id. Account secrets are protected with authenticated AES-256-GCM encryption and stored locally by Chrome.
The current Chrome release is deliberately local-only and makes no external network requests. A future Sync phase is planned as opt-in end-to-end encrypted recovery across Chrome, Windows, and later mobile apps, with updated disclosures before launch.
LukaOTP is built for a specific preference: quick desktop access with no cloud service in the loop. Choose the model that matches your threat model.
Tradeoff: no built-in cloud recovery; browser and OTP share one device.
Good fit when continuity across devices matters most.
Good fit when independent-device isolation matters most.
Good fit when speed and integrated autofill matter most.
Comparison based on public product documentation: 2FAS, Ente Auth, Google Authenticator, Authenticator Extension. Reviewed August 2026.
LukaOTP deliberately has no cloud recovery. If you forget your master password, uninstall the extension, or clear its local data, your vault may be unrecoverable.
Before you begin: keep each service’s recovery codes in a separate safe place. For high-value accounts, prefer passkeys or hardware security keys when available.
No. The developer does not receive or transmit user data. The extension makes no external network requests; account names, possible email usernames, TOTP keys, codes, and one-time tab screenshots are processed locally for the stated features and are not shared.
Only to scan a QR code visible on the tab you explicitly choose. The captured image is processed in memory and is not saved or uploaded.
Yes. LukaOTP runs directly in Chrome and does not require phone pairing. This is convenient, but it means the browser and OTP code are on the same device.
There is no password reset or cloud recovery. Keep your service recovery codes safely stored outside LukaOTP.
The interface supports English, Simplified Chinese, and Traditional Chinese. It generates standards-based RFC 6238 TOTP codes with 6 or 8 digits.
Not in the current local-only release. End-to-end encrypted Sync is on the roadmap and must ship as an opt-in feature with updated privacy disclosures before any network service is enabled.
Free to use. No account required.