bkey
Overview
Phone-mediated biometric TOTP autofill.
bkey fills two-factor authentication (2FA) one-time codes into websites, but nothing is filled until you ask for it and approve it on your phone. How it works: 1. Pair this browser with the bkey app by scanning a QR code and confirming the matching words on your phone. 2. When a website asks for a one-time code, a small bkey button appears on the code field. 3. Click it, approve on your phone with Face ID, and bkey fills the approved code into that field. Why it's different: • Phone-mediated — a code is requested only after you click the bkey button, and released only after you approve on your paired phone. Nothing is filled silently. • Secrets stay on the phone — your TOTP secrets live in the bkey app and are never copied into the browser. The extension receives a single approved code for the site you are on. • Limited browser storage — the extension stores pairing keys plus opaque site-match metadata. It never stores your one-time-code secrets or page contents. • Private site matching — your phone publishes one-way hashes of the sites that have a code saved, so a web page cannot learn what else is in your vault. Requires the bkey iOS app and a one-time pairing. Note: this version fills one-time codes only. It does not fill usernames or passwords, and it does not read SMS or email.
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedJuly 30, 2026
- Offered byBKey Inc.
- Size122KiB
- LanguagesEnglish
- DeveloperBKey Inc.
1834 Walden Office Square Ste 220 Schaumburg, IL 60173-4296 USEmail
support@bkey.idPhone
+1 650-307-0614 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
Privacy
bkey has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
bkey handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes