Item logo image for OttoKey - 2FA code fetcher

OttoKey - 2FA code fetcher

jeanlucponsard.dev
ExtensionTools4 users
Item media 4 (screenshot) for OttoKey - 2FA code fetcher
Item media 1 (screenshot) for OttoKey - 2FA code fetcher
Item media 2 (screenshot) for OttoKey - 2FA code fetcher
Item media 3 (screenshot) for OttoKey - 2FA code fetcher
Item media 4 (screenshot) for OttoKey - 2FA code fetcher
Item media 1 (screenshot) for OttoKey - 2FA code fetcher
Item media 1 (screenshot) for OttoKey - 2FA code fetcher
Item media 2 (screenshot) for OttoKey - 2FA code fetcher
Item media 3 (screenshot) for OttoKey - 2FA code fetcher
Item media 4 (screenshot) for OttoKey - 2FA code fetcher

Overview

Detects logins, reads the 2FA code from your Gmail or Outlook inbox on your own device, and fills it in. Open source, no server.

OttoKey fills in your verification codes so you don't have to go and find them. When a site asks for a 2FA code, OttoKey notices, checks your inbox for the email that just arrived, reads the code out of it, and types it into the page. No switching tabs, no copy-paste, no squinting at six digits. HOW IT WORKS 1. You hit a login page that wants a verification code. 2. OttoKey spots the code field and starts watching your inbox. 3. The email arrives. OttoKey reads the code and fills it in. 4. You press sign in. OttoKey never submits the form for you. WORKS WITH • Gmail • Outlook / Hotmail / Live • Up to five inboxes linked at once IT ALL HAPPENS ON YOUR DEVICE There is no OttoKey server. The extension talks straight to Google's or Microsoft's mail API from your own browser, and nowhere else. Chrome enforces that: the extension declares exactly two permitted hosts, and it cannot reach any other server. That means no account to create, no analytics, no tracking, nothing logged, and no data sold or shared. Your codes and the token for your inbox stay in your browser's local storage, and uninstalling OttoKey deletes them. OPEN SOURCE — DON'T TAKE OUR WORD FOR IT Every line is public under the MIT licence: https://github.com/amogus0471/OttoKey You don't even have to read all of it. Open manifest.json and look at host_permissions — two entries, both belonging to your own mail provider. That one file is the whole privacy story. FEATURES • Detects code fields automatically, including split one-digit-per-box layouts • Auto-fill, with the option to keep the window from popping up • Desktop notification when a code lands • One-tap copy, plus a local history of recent codes you can wipe any time • Optional "Tidy up inbox" — moves the email a code came from to Trash after reading it. Off by default, asks you to confirm, and Trash stays recoverable for 30 days. • Reads the code locally: order numbers, invoices, prices, tracking numbers and meeting IDs are filtered out, so it grabs the code and not the wrong number. WORTH KNOWING Auto-filling a code on the same device you are logging in from means the "second factor" is no longer on a separate device. That is a fair trade for everyday accounts — it is what iOS SMS autofill does — but think twice before using it on your bank. You can revoke OttoKey's access to your inbox in one click at any time, from your Google or Microsoft account permissions. Privacy policy: https://jeanlucponsard.dev/otto/privacy Terms of service: https://jeanlucponsard.dev/otto/terms Source code: https://github.com/amogus0471/OttoKey

Details

  • Version
    2.0
  • Updated
    August 4, 2026
  • Size
    53.95KiB
  • Languages
    English
  • Developer
    Website
    Email
    jeanlucponsard10@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps