We take the security of 2FA Authenticator seriously. Because this extension stores TOTP secrets, any vulnerability has direct impact on user account security across third-party services.
Reviewing this extension for your organisation? How it works covers the cryptography, key management, storage, permissions, network egress, threat model and how to reproduce the published build.
Please do not report security issues through public GitHub issues, the Chrome Web Store reviews, or social media. Instead, email security@authenticator.sh with a description of the issue, steps to reproduce, the affected version, and your name or handle if you would like public credit.
If you do not receive a response within 72 hours, please follow up — your message may have been filtered.
We will not pursue legal action against researchers who:
We follow coordinated disclosure. Please give us a reasonable window (typically 90 days, or sooner if a fix ships) before public disclosure. We credit reporters in release notes unless you prefer to remain anonymous.
Machine-readable contact: /.well-known/security.txt