OTPClient
by Paolo Stivanin
Application for managing TOTP/HOTP tokens with built-in encryption
Dangerous permissions
Verified creator
GPL-3.0+
v5.1.8
About
OTPClient is a secure and easy-to-use desktop client for TOTP and HOTP one-time passwords, built with GTK4 and libadwaita. Features:
- multiple databases with sidebar management and cross-database search
- token grouping with quick filtering
- desktop search provider for GNOME Shell and KDE KRunner (opt-in trigger keyword)
- command-line companion (otpclient-cli) with scriptable table/JSON/CSV output
- support for TOTP, HOTP, and Steam codes
- configurable digits (4 to 10), period (1 to 120 seconds), and algorithm (SHA1, SHA256, SHA512)
- import and export of encrypted/plain Aegis backups
- import and export of encrypted/plain Authenticator Pro and 2FAS backups
- import and export of plain FreeOTP+ backups (key URI format)
- import of Google Authenticator migration QR codes (file, screen, webcam, clipboard)
- integration with the OS secret service provider via libsecret (opt-in)
- local database encrypted with AES-256-GCM and Argon2id key derivation; plaintext lives only in libgcrypt secure memory while unlocked
Permissions
2 permissions weaken the sandbox. Flatsonar asks before installing.
- all devices (/dev): webcams, disks, raw hardware
--device=all - your keyring / saved passwords
--talk-name=org.freedesktop.secrets - inter-process communication (needed for X11)
--share=ipc - X11 display, only when Wayland is unavailable
--socket=fallback-x11 - Wayland display
--socket=wayland - access to xdg-run/gvfsd
--filesystem=xdg-run/gvfsd - system tray
--talk-name=org.kde.StatusNotifierWatcher - talks to org.gnome.ScreenSaver
--talk-name=org.gnome.ScreenSaver - talks to org.gtk.vfs.*
--talk-name=org.gtk.vfs.* - talks to org.cinnamon.ScreenSaver
--talk-name=org.cinnamon.ScreenSaver - screensaver inhibit
--talk-name=org.freedesktop.ScreenSaver - talks to com.canonical.Unity
--talk-name=com.canonical.Unity
Who publishes this
The creator demonstrably controls this app id: Flathub verification, the hosting account owns the namespace, or a well-known file on their domain.
- verified on Flathub: the developer proved they control this app id
publisher:flathub
Maintenance
Recent activity on the upstream repository, or built and reviewed by Flathub.
No staleness signals: recent activity, or built and reviewed by Flathub.