Clockwork
A TOTP two-factor authenticator for Android and the browser that never makes network connections.
Open source (MIT)By keco216
Compare Clockwork with another product
View the Clockwork source code
Alternatives
See all alternativesAbout Clockwork
Clockwork generates time-based two-factor codes entirely on your device. The Android app declares no INTERNET permission, so it cannot open a connection, and the web version makes no network requests. The RFC 4226 and 6238 algorithms are implemented from scratch.
You can add accounts from a secret, an otpauth link, a QR image, the camera or a Google Authenticator otpauth-migration export. By default nothing is stored; an optional vault encrypts entries with your passphrase using PBKDF2-SHA-256 and AES-256-GCM, and locks automatically after a set time.
Strengths
- Android app has no internet permission at all
- Imports secrets, otpauth links, QR images and migration exports
- Optional passphrase-encrypted vault with auto-lock
- Also works in a browser with no install
Limitations
- No cloud sync or backup between devices
- Stores nothing by default, so secrets must be re-entered unless the vault is on
- Small, young project
Details
- Pricing
- FreeFree and open source under the MIT licence.
- License
- MIT
- Developer
- keco216
- Platforms
- Android, Web
- How it runs
- Downloadable app, Web application
- Account
- Not required
- Works offline
- Yes
- Best suited for
- People who want a 2FA code generator that cannot leak secrets over the network
- Categories
- Password managers, Security tools
- Last verified
- Added