Terms of service
These terms describe the features, handling of account data, user responsibilities, and service limits for the AuthTool online authenticator. By using the site, you confirm that you have read and understood them.
Service and feature scope
AuthTool is an online authenticator and TOTP code generator. You can enter an account name and Base32 secret manually, paste an otpauth:// TOTP URI, or upload a QR image for local browser detection. The tool calculates a current code from the secret and settings such as algorithm, digit count, and time period, and provides an account list, countdown, and copy function. AuthTool does not connect to the target account, verify your identity, enable Google 2-Step Verification, or change security settings for another service.
Account security and local data responsibility
Authenticator secrets and related account data are encrypted in the current browser; there is no cloud backup or cross-device sync. Keep the password used for protection safe and use a trusted private device. The password is not stored. If you forget it while protection is on, the accounts cannot be decrypted, and resetting clears the local vault. Turning protection off allows automatic unlocking in this browser, so do not disable it on a shared or untrusted device. Keep recovery codes from the account provider separately.
Code accuracy and use
A code works only when the setup secret is correct, the device and service clocks are aligned, and the algorithm, digit count, and period match the target service. Services may use different TOTP settings, so follow the setup information provided by that service. Use a code before its countdown expires. If codes continue to fail, check the clock, secret, and account settings, then contact the target service through its official support channel. AuthTool cannot recover your service account, password, or two-step verification recovery codes.
Acceptable use
Only add setup secrets for accounts you own or are authorized to manage, and follow the target service’s terms and applicable laws. Do not use the site to attempt unauthorized access, interfere with or disrupt services, bypass security controls, distribute malicious code, or violate another person’s rights. To protect accounts, do not share setup secrets, QR codes, verification codes, or vault passwords.
Availability and third-party dependencies
The site may be temporarily unavailable because of maintenance, network failures, browser compatibility, unavailable third-party resources, or other causes. Features, interface, and supported browser capabilities may change or be discontinued. AuthTool does not promise continuous, error-free service or compatibility with every device. Code generation and local storage require supported browser security and storage APIs; QR detection also depends on browser support. Use the tool over a valid HTTPS connection.
Disclaimer and limits
AuthTool is provided in its current state and is intended only to generate codes from the TOTP settings you provide. Check the source of a secret before entering it, and keep other sign-in and recovery methods supplied by the target service for important accounts. AuthTool cannot guarantee recovery from or prevention of sign-in failures, data loss, or other harm caused by an incorrect secret, device clock, browser failure, lost device, forgotten password, or changes to a third-party service. To the extent permitted by applicable law, the site provides no express or implied warranties. These terms do not exclude liability that cannot legally be excluded.
Brands, intellectual property, and changes
Names, interface, and content on the AuthTool site are protected by applicable intellectual property rules. Google Authenticator, Google 2-Step Verification, and related marks belong to Google LLC or their respective owners. AuthTool is not affiliated with Google and is not an official Google app. We may update these terms when features or operations change, and publish the revised text on this page. Review the current terms before continuing to use the site.