Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Rust
  3. cotp

cotp

GPL-3.0Rustv1.10.0

A command-line TOTP/HOTP authenticator with strong encryption, import capabilities, and an interactive dashboard.

GitHubGitHub
390 stars29 forks0 contributors

What is cotp?

cotp is a secure, encrypted command-line application for managing two-factor authentication (2FA) codes. It generates TOTP and HOTP codes, storing them in an encrypted database to protect authentication data. The tool offers an interactive dashboard for browsing and copying codes, even in SSH remote shells.

Target Audience

Developers, system administrators, and security-conscious users who prefer command-line tools and need a secure, minimalist way to manage 2FA codes across Linux, Windows, and macOS systems.

Value Proposition

Developers choose cotp for its strong encryption using XChaCha20Poly1305 and Argon2id, broad compatibility with various OTP types and authenticator apps, and its cross-platform, desktop-accessible design that works seamlessly in remote shells.

Overview

Encrypted, command-line TOTP/HOTP authenticator app with import functionality.

Use Cases

Best For

  • Securely managing TOTP and HOTP codes from the command line with encrypted storage.
  • Migrating 2FA codes from popular authenticator apps like Aegis, andOTP, Authy, Google Authenticator, and Microsoft Authenticator.
  • Generating Steam, Yandex, and MOTP codes with customizable HMAC algorithms and digits.
  • Using an interactive dashboard to browse and copy OTP codes in SSH remote shells.
  • Cross-platform 2FA management on Linux, Windows, and macOS with minimal dependencies.
  • Importing and exporting encrypted OTP databases for backup and migration purposes.

Not Ideal For

  • Teams needing shared, real-time access to 2FA codes across multiple devices, as cotp uses a local encrypted database without cloud synchronization.
  • Mobile-only users who require on-the-go 2FA generation via smartphone apps, since cotp is command-line based and not designed for mobile platforms.
  • Users who prefer graphical interfaces and find CLI tools cumbersome for daily authentication tasks, given cotp's minimalist terminal-only approach.
  • Environments where quick, scriptable 2FA integration is critical, as cotp's interactive dashboard and encryption overhead add complexity compared to plain-text secret storage.

Pros & Cons

Pros

Strong Encryption Foundation

Uses XChaCha20Poly1305 authenticated encryption and Argon2id for key derivation, ensuring high security for stored OTP data as explicitly stated in the README's encryption section.

Interactive SSH Dashboard

Provides an arrow-key navigable interface that works even in remote SSH shells, allowing code browsing and copying without GUI dependencies, demonstrated in the demo GIF.

Broad OTP Compatibility

Supports TOTP, HOTP, Steam, Yandex, and MOTP codes with customizable HMAC algorithms and digits, covering various authentication systems as highlighted in the compatibility section.

Comprehensive Migration Tools

Offers import from apps like Aegis, Authy, and Google Authenticator, with detailed conversion scripts provided for complex cases, as shown in the migration table with specific arguments.

Cons

Complex Import Processes

Importing from apps like Authy or Google Authenticator requires running additional Python scripts to convert backup files, adding manual steps and potential points of failure, as admitted in the migration table.

Dependency on External Libraries

On Linux, installation needs libxcb and related dependencies for clipboard functionality, which can complicate setup on minimal systems, as noted in the install instructions for various distros.

No Cloud Sync

The database is locally encrypted without automatic cloud synchronization or multi-device access, making it impractical for users who need seamless access across platforms or fear data loss.

Limited Recovery Options

Forgetting the encryption password leads to permanent data loss, as there's no built-in recovery mechanism, relying solely on user backups via the export command.

Open Source Alternative To

cotp is an open-source alternative to the following products:

Google Authenticator
Google Authenticator

A mobile app that generates two-factor authentication (2FA) codes for signing into Google accounts and other services that support time-based one-time passwords.

Microsoft Authenticator
Microsoft Authenticator

Microsoft Authenticator is a mobile app that provides two-factor authentication for Microsoft accounts and other services using time-based one-time passwords or push notifications.

Authy
Authy

Authy is a two-factor authentication (2FA) application that provides secure login verification via time-based one-time passwords (TOTP) and push notifications. It is owned by Twilio.

Frequently Asked Questions

Quick Stats

Stars390
Forks29
Contributors0
Open Issues0
Last commit8 days ago
CreatedSince 2020

Tags

#totp#xchacha20-poly1305#authentication#authenticator#two-factor-authentication#cli-tool#clipboard#encryption#security#tui-rs#linux#cross-platform#command-line#rust#windows#hotp

Built With

R
Rust

Included in

Rust56.6k
Auto-fetched 21 hours ago

Related Projects

rustscanrustscan

🤖 The Modern Port Scanner 🤖

Stars20,505
Forks1,387
Last commit1 day ago
feroxbusterferoxbuster

A fast, simple, recursive content discovery tool written in Rust.

Stars8,107
Forks635
Last commit1 month ago
rayhunterrayhunter

Rust tool to detect cell site simulators on an orbic mobile hotspot

Stars5,923
Forks504
Last commit1 day ago
rustnetrustnet

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Stars5,093
Forks239
Last commit1 day ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub