Minimal, fully-encrypted, cross-platform TOTP authenticator written in Rust.
monotp is a clean, black-and-white TOTP (Time-based One-Time Password) authenticator. It stores every account secret fully encrypted on disk, protected by a master password that is stretched with Argon2id. Secrets live only briefly in memory and are zeroized the moment they are no longer needed. One binary, no telemetry, no cloud.
Built by X-croot.
- RFC 6238 TOTP — SHA1 / SHA256 / SHA512, 6–8 digits, configurable period.
- Full encryption at rest — vault sealed with XChaCha20-Poly1305 (AEAD).
- Argon2id master key — memory-hard key derivation (~64 MiB, tunable).
- Zeroize everywhere — master key and plaintext secrets are wiped from RAM on drop/lock.
- Smart paste — drop an
otpauth://link or a raw base32 secret; issuer, account, digits, period and algorithm are auto-filled. Naming an entry anything you like never breaks code generation. - Live search — instantly filter accounts by issuer or name.
- Add / edit / delete — full account management with a live code preview while adding.
- Reveal / copy — one-click copy with confirmation, plus per-entry secret reveal.
- Two ways to reset your password:
- Change master password — the vault is decrypted in memory, then re-encrypted and overwritten with the new password. Your accounts stay intact.
- Forgot password — a guarded, type-
DELETEwipe that erases everything and lets you set up a fresh vault (there is no recovery — by design).
- Real black & white app icon — bundled as the window/taskbar icon and compiled straight into the Windows
.exeviabuild.rs. - Platform-native storage — each OS keeps data in its own conventional directory:
- Linux:
~/.config/monotp/config.toml+~/.local/share/monotp/vault.enc - Windows:
%APPDATA%\X-croot\monotp\config\+...\data\ - macOS:
~/Library/Application Support/com.X-croot.monotp/
- Linux:
- Themes —
System,Dark,Light,Sakura, and a pureMonochrome(black & white) theme. - Copy-to-clipboard with a live countdown ring and a shrinking progress bar.
- Autostart on login — one toggle, handled per OS (Linux
.desktop, WindowsRunregistry key). - Config as TOML — human-readable, portable settings file.
| Theme | Description |
|---|---|
| System | Follows the OS light/dark preference |
| Dark | Deep neutral dark |
| Light | Clean light |
| Sakura | Soft cherry-blossom pink |
| Monochrome | Pure black & white, high contrast |
Requires the Rust toolchain.
# Debug run
cargo run
# Optimized release build
cargo build --release
# Binary: target/release/monotp (monotp.exe on Windows)rustup target add x86_64-pc-windows-gnu
cargo build --release --target x86_64-pc-windows-gnu- On first launch, create a master password (min. 8 characters). This seals your vault — it is never stored and cannot be recovered.
- Click + Add account, then either paste an
otpauth://URI or fill in the fields manually (issuer, account, base32 secret). - Codes refresh automatically; click Copy to place the current code on your clipboard.
- Use Lock to wipe secrets from memory; unlock again with your master password.
- The master password is stretched with Argon2id using a random 16-byte salt (stored in
config.toml). - The derived 256-bit key never touches disk; only the encrypted vault (
vault.enc) is persisted. - Encryption uses XChaCha20-Poly1305 with a fresh random 24-byte nonce per save.
- Sensitive buffers implement
Zeroize/Dropso they are cleared from memory deterministically. - There is no backdoor and no recovery: lose the master password and the vault is unrecoverable — by design.
Rust · eframe/egui (cross-platform GUI) · argon2 · chacha20poly1305 · zeroize · directories · serde/toml · hmac/sha1/sha2 · data-encoding
MIT © X-croot