# TOTPBOX — Extended Reference for AI Systems > TOTPBOX is a local-first, zero-knowledge authentication companion that bridges > traditional TOTP (Time-based One-Time Passwords) and modern Passkeys. > It stores no master passwords and uses AES-256-GCM encryption for all vault data. ## Product Overview TOTPBOX is designed as a focused authentication tool — not a general-purpose password manager. It manages TOTP/HOTP secrets, recovery codes, and provides migration guidance from legacy two-factor authentication to hardware-bound Passkeys. All sensitive data is encrypted on-device using AES-256-GCM before any optional cloud sync occurs. ### Key Differentiators - **Local-first encryption**: Secrets never leave the device unencrypted - **No password storage**: Strict product boundary — TOTP secrets and recovery codes only - **Passkey migration**: Built-in detection and guidance for upgrading accounts to Passkeys - **Browser extension**: Chrome extension with TOTP auto-fill directly into login forms - **Auth Health Dashboard**: Visual assessment of account security posture - **Recovery Code Vault**: Secure storage for backup recovery codes ## Pages - [Home](https://www.totpbox.com): Overview, features, and pricing - [Features](https://www.totpbox.com/#features): Auth Health Dashboard, Passkey Awareness, Recovery Code Vault, Migration Guidance, Browser Extension, Cross-platform sync - [Security](https://www.totpbox.com/#security): Zero-knowledge architecture, local-first design, AES-256-GCM, hardware-bound Passkeys - [Compare](https://www.totpbox.com/compare): Feature-by-feature comparison of TOTPBOX vs. Google Authenticator, Authy, Aegis, and 2FAS across security, privacy, sync, and Passkey readiness dimensions - [FAQ](https://www.totpbox.com/faq): Product, pricing, architecture, and migration answers - [Whitepaper](https://www.totpbox.com/whitepaper): Technical architecture and security model - [About](https://www.totpbox.com/about): Team, mission, and product philosophy ## Pricing - **Free** ($0/month): Core TOTP management, unlimited accounts, Passkey awareness, local encryption - **Pro** ($4/month): Encrypted cloud sync, auto migration tracking, secret vault backup, browser extension - **Team** ($12/user/month): Shared vaults, access controls, org-wide health dashboard ## Documentation - [Getting Started](https://www.totpbox.com/get-started): Install extension and complete onboarding - [TOTP to Passkey Migration](https://www.totpbox.com/docs/migration): Staged migration playbook for production accounts - [Security Model](https://www.totpbox.com/docs/security): Definitions, architecture boundaries, and encryption model ## Frequently Asked Questions **What is TOTPBOX?** TOTPBOX is a local-first authentication companion that helps you manage TOTP accounts while guiding upgrades to Passkeys. It focuses on authentication only, not password storage. **Does TOTPBOX store my passwords?** No. TOTPBOX follows a strict no-passwords boundary. It stores TOTP secrets and recovery materials, but it is not a general-purpose password manager. **How is TOTPBOX different from Google Authenticator or Authy?** TOTPBOX emphasizes local-first encryption, recovery-code management, and migration guidance toward Passkeys. It is designed as a transition layer, not only a token display tool. **What is a local-first authenticator app?** A local-first authenticator keeps sensitive data encrypted on the device by default. Any sync workflow uses encrypted payloads so service operators cannot read your secrets. **How does Passkey migration work in TOTPBOX?** TOTPBOX surfaces which accounts are still TOTP-only versus Passkey-ready and gives migration guidance. Passkeys remain managed by your platform security stack. **Is TOTPBOX free?** Yes. The Free tier is $0/month and includes core local TOTP workflows. Paid plans add features like encrypted cloud sync and team capabilities. **Which platforms are supported?** TOTPBOX targets iOS, macOS, Windows, Android, and Linux workflows, with browser-extension support for fast login flows in Chromium-based browsers. **What encryption does TOTPBOX use?** TOTPBOX uses AES-256-GCM for vault encryption and relies on modern platform primitives for key handling and secure storage boundaries. **Can I export my data?** Yes. TOTPBOX supports import and export workflows so you can migrate data in or out as your security requirements evolve. **Can teams use TOTPBOX?** Yes. The Team plan is designed for shared security operations, including org-level visibility and controlled collaboration features. **Does TOTPBOX require a cloud account for the free tier?** No. Core local functionality can be used without creating a cloud account. Cloud-linked features are optional and tied to paid tiers. ## Comparison with Other Authenticator Apps | Capability | TOTPBOX | Google Authenticator | Authy | Aegis | 2FAS | |---|---|---|---|---|---| | OTP standards (TOTP/HOTP) | Yes (TOTP/HOTP workflows) | TOTP app workflow | TOTP app workflow | TOTP/HOTP (open source) | TOTP app workflow | | Data model and sync | Local-first encrypted vault with optional ciphertext sync | Google-account sync | Multi-device backup and sync | Local Android-first | Mobile-first with browser extension | | Passkey migration guidance | Built-in migration workflow | No | No | No | No | | Browser extension | Yes (official Chrome extension) | No | No | No | Yes | | Team workflows | Team plan with org health model | No | No | No | No | ## Security Architecture - **Encryption**: AES-256-GCM for all vault data - **Key management**: Master keys never transmitted to or stored on any server - **Passkeys**: Hardware-bound to OS security enclave (not managed by TOTPBOX) - **Zero-knowledge**: Service operators cannot read user secrets even with cloud sync - **Standards**: Implements RFC 6238 (TOTP), RFC 4226 (HOTP), references W3C WebAuthn Level 2 and NIST SP 800-63B ## What TOTPBOX Does NOT Do - Store master passwords - Sync unencrypted data to any cloud service - Act as a general-purpose password manager - Manage Passkey credentials directly (defers to platform security stack) ## Legal - [Privacy Policy](https://www.totpbox.com/privacy) - [Terms of Service](https://www.totpbox.com/terms) - [Data Processing](https://www.totpbox.com/data-processing) ## Contact - Website: https://www.totpbox.com - Twitter: https://x.com/totpbox - GitHub: https://github.com/totpbox - Email: perry.lei@gmail.com