{"repo":"token2/TOTPVault","free":true,"listed":false,"github":"https://github.com/token2/TOTPVault","clone":"git clone https://github.com/token2/TOTPVault.git","description":"A self-hosted TOTP manager built with PHP","language":"PHP","stars":15,"topics":[],"license":"GPL-3.0","category":"self-hosted-apps","readme_excerpt":"TOTPVault A self-hosted TOTP (Time-based One-Time Password) manager built with PHP. Secret keys are AES-256-GCM encrypted on the server and never transmitted to the client . OTP codes are generated server-side and can be shared with teammates without ever exposing the underlying secrets. --- Features - Server-side code generation — secrets are decrypted in memory only at generation time and never sent to the browser - AES-256-GCM encryption — every secret is encrypted at rest with a unique 96-bit nonce per record - Multiple login methods — OAuth 2.0/OIDC via Google, Microsoft, GitHub, or Keycloak; passwordless magic links via email - Token sharing — share individual OTP profiles with colleagues by email; they can view codes (or optionally edit settings) without ever seeing the secret - QR code import — paste or drag an otpauth:// QR image directly in the browser to auto-fill all token fields - Hide mode — mask a token's code until clicked; it reveals for 10 seconds then hides itself again - Full RFC 6238 support — SHA1, SHA256, SHA512 · 6, 8, or 10 digit codes · configurable time periods - Icon & colour tagging — assign any Font Awesome brand or solid icon and one of 16 accent colours to each token for quick visual identification - Google Authenticator bulk import - import your Google Authenticator accounts via the otpauth-migration QR images - Export profiles — download your TOTP profiles (owned or with edit rights) as a CSV file containing decrypted seeds, compatible with M","default_branch":null,"files":null,"tree":[],"storefront":"/r/token2","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/token2/TOTPVault/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}