Security & Privacy of the 2FA Auth Online Authenticator

How this online 2FA authenticator treats your secret key and 2FA codes, which third-party resources are involved, and how to use any online authenticator safely.

Last updated: October 8, 2026

Privacy is the main reason people choose a simple authenticator, so this page states plainly what the site does and what it does not. Everything in the first table comes from the site’s own source code, which is public on GitHub.

What 2FA Auth does and does not do

QuestionAnswer
Where is the 2FA code calculated?In your browser, with the Web Crypto API (HMAC-SHA-1).
Does the page send your secret key anywhere?The page’s code contains no request that transmits your key or your codes.
Is there an account, login or user database?No. The site is a set of static pages served by a small web server.
Is your key saved?No. It lives only in the open page and is gone when you reload or close it. The only thing stored in your browser is your language choice.
Does QR scanning upload the camera image?No. Frames are decoded in your browser. Browsers without built-in QR detection load the open-source jsQR library from the jsDelivr CDN when you press “Scan QR”.
Other third-party resources?Fonts are loaded from Google Fonts. Google AdSense is prepared for ads and only loads if ads are switched on. See the privacy policy.

What we cannot promise

Using an online authenticator safely

  1. Use a device you trust. Avoid public or shared computers.
  2. Check the address bar. Make sure you are on 2fauth.online before entering a key.
  3. Keep your own copy of the key. We cannot restore a key for you.
  4. Keep your backup codes offline and know how to recover each important account.
  5. Close the tab when you are done and clear the key field with the clear button.
  6. Use stronger options for critical accounts. If a service supports hardware security keys or passkeys, enable them in addition to or instead of codes.

2FA security basics

New to the topic? Start with what is 2FA or read about protecting your 2FA key.

Reporting a security issue

If you find a vulnerability or something that contradicts this page, write to support@2fauth.online. Please include the page, your browser and steps to reproduce the problem.