This roadmap tracks product direction at a high level. README.md remains the best source for the currently implemented surface.
- Rust workspace and repository setup
- Git repository initialization
- baseline project structure
-
core,storage,cli,gui - encrypted local vault
- TOTP add, list, token, remove, and metadata export
- Windows MSI packaging
- atomic writes and backup/restore strategy
- password rotation with vault re-encryption
-
otpauth://import via shared domain logic - QR parsing for
otpauth:// - richer validation and migration support
- richer search, internal metadata, and project directories
- optional OS keychain or keyfile strategy
- Rust-native desktop shell
- vault initialize and unlock workflow
- account add, edit, remove, token, and export flows
- persistent light and dark theme
- live countdown and explicit copy action
- visual project directories and inline account actions
- account history and restore UX
- deletion of empty workspace and subdirectory nodes
- multi-selection and bulk account deletion
- wider release validation of Windows secondary verification
- native unlock window for local automation access
- process-scoped session over JSON
stdio - persistent agent/MCP lifecycle hardening with EOF shutdown, Win32 message pumping, bounded native waits, session identity, and broker recovery
- machine-readable account and token operations
- explicit short-lived grants for sensitive operations
- password rotation inside the local automation boundary
- loopback-only HTTP API
- broader client-scoped authorization model
- CSV import
- selective import from external authenticators and managers
- controlled export formats beyond metadata-only JSON
- browser integration
- SSH agent integration
- Secret Service equivalent
- challenge-response hardware support
- HOTP
- WebAuthn and passkeys
- hardware-backed options
- dedicated
mfa-forge-mcpbinary - dedicated
mfa-forge-agentbinary - dedicated
mfa-forge-launcherbinary - minimal MCP server over JSON-RPC
stdio - local audit trail for sensitive automation actions
- validated local
RC17 -> RC18upgrade path - validated startup-updater proof on
RC25 -> RC26 - stable public release publication
- hotfix
1.0.2issue closure for lifecycle, audit/storage boundaries, module split, test KDF isolation, and mixed-DPI window behavior - broader client-scoped deny-by-default policy model
- deeper audit and reporting workflows