// the find
rsc/2fa
Two-factor authentication on the command line
A minimal command-line TOTP/HOTP generator by Russ Cox, meant to replace a phone authenticator app for people who live in a terminal. It stores your 2FA seeds locally and prints codes on demand, with optional clipboard copy.
Single main.go you can read in five minutes and verify it isn't doing anything sketchy with your secrets. Correctly implements both TOTP and HOTP with configurable digit counts (6/7/8), which covers the handful of services that deviate from the Google Authenticator default. Zero-friction UX for people who already live in a shell — 'go install' and you're generating codes, no app, no QR scanning gymnastics.
The keychain is stored completely unencrypted in $HOME/.2fa — for a tool whose entire job is securing your accounts, this is a real problem; anyone with read access to your home directory (malware, a shared machine, a backup leak) gets every one of your 2FA seeds in plaintext. No passphrase or OS keychain integration option at all. Single point of failure with no built-in backup/export story — lose the file, lose every account's second factor, with no documented recovery path. Last push was August 2024 and it's effectively a finished, unmaintained utility at this point — fine if you just want it to keep working, but don't expect new features or a security hardening pass.