Security & Privacy of the 2FA Auth Online Authenticator
How this online 2FA authenticator treats your secret key and 2FA codes, which third-party resources are involved, and how to use any online authenticator safely.
Privacy is the main reason people choose a simple authenticator, so this page states plainly what the site does and what it does not. Everything in the first table comes from the site’s own source code, which is public on GitHub.
What 2FA Auth does and does not do
| Question | Answer |
|---|---|
| Where is the 2FA code calculated? | In your browser, with the Web Crypto API (HMAC-SHA-1). |
| Does the page send your secret key anywhere? | The page’s code contains no request that transmits your key or your codes. |
| Is there an account, login or user database? | No. The site is a set of static pages served by a small web server. |
| Is your key saved? | No. It lives only in the open page and is gone when you reload or close it. The only thing stored in your browser is your language choice. |
| Does QR scanning upload the camera image? | No. Frames are decoded in your browser. Browsers without built-in QR detection load the open-source jsQR library from the jsDelivr CDN when you press “Scan QR”. |
| Other third-party resources? | Fonts are loaded from Google Fonts. Google AdSense is prepared for ads and only loads if ads are switched on. See the privacy policy. |
What we cannot promise
- Like most websites, the hosting provider may keep standard technical logs such as IP addresses and page requests. These do not include your secret key, because the key is never part of a page request.
- We cannot protect a device that already has malware, a hostile browser extension or a shared screen.
- An online tool runs in a web page and is therefore more exposed than a dedicated app on a locked phone. That trade-off is real, and the advice below exists for that reason.
Using an online authenticator safely
- Use a device you trust. Avoid public or shared computers.
- Check the address bar. Make sure you are on
2fauth.onlinebefore entering a key. - Keep your own copy of the key. We cannot restore a key for you.
- Keep your backup codes offline and know how to recover each important account.
- Close the tab when you are done and clear the key field with the clear button.
- Use stronger options for critical accounts. If a service supports hardware security keys or passkeys, enable them in addition to or instead of codes.
2FA security basics
- Enable 2FA on your email first – it is the key to resetting every other password.
- Use unique passwords. 2FA protects you if one leaks, but it is not a substitute.
- Never give a verification code to anyone who contacts you.
- Keep your device clock on automatic time so codes stay correct.
New to the topic? Start with what is 2FA or read about protecting your 2FA key.
Reporting a security issue
If you find a vulnerability or something that contradicts this page, write to support@2fauth.online. Please include the page, your browser and steps to reproduce the problem.