{"repo":"soruly/pasu","free":true,"listed":false,"github":"https://github.com/soruly/pasu","clone":"git clone https://github.com/soruly/pasu.git","description":"Self-hosted TOTP authenticator PWA with FIDO2 (WebAuthn)","language":"TypeScript","stars":15,"topics":["2fa","fido2","pwa","totp","webauthn"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"pasu Self-hosted TOTP authenticator PWA with FIDO2 (WebAuthn) Features - 2FA secrets stored in your own server instead of your own device - Codes are generated on server side and push to all clients via server-sent events - Installable PWA - Allow others to access the OTP of your accounts - or, Secured by FIDO2 (WebAuthn) - Support password-less login via Fingerprint/TouchID/Windows Hello/YubiKey/pin code via FIDO2 - User-Agent block list - IP block list Warning This PWA is open to public by default. \\ Everyone is able to access your OTP. Do not use it for any serious businesses.\\ The author does not bear any losses caused by this app. Demo https://user-images.githubusercontent.com/1979746/174453876-f4d81b10-bf43-41b9-b135-442b68234660.mp4 Getting Started Note: In order for PWA to work, you must host the server behind a reverse proxy (like nginx) with HTTPS Example nginx config: Environment Variables - Copy .env.example to .env - Edit .env as you need To register a new device with WebAuthn, turn on both ENABLE FIDO2 and ALLOW REGISTER , then visit https://your.server/reg to continue. It is suggested you turn off ALLOW REGISTER when not needed. Run as systemd Put this file to /etc/systemd/system/pasu.service","default_branch":null,"files":null,"tree":[],"storefront":"/r/soruly","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/soruly/pasu/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}