TOTP Vault With AutoFill version history - 1 version
TOTP Vault With AutoFill by Skeletor
TOTP Vault With AutoFill version history - 1 version
Be careful with old versions! These versions are displayed for testing and reference purposes.You should always use the latest version of an add-on.
Latest version
Version 1.2.6
Released Sep 24, 2026 - 89.32 KBWorks with firefox 142.0 and later- Replaced the vault password for new vaults and normal unlocking with an exactly four-digit PIN. Leading zeros are supported.
- Added a one-time conversion for existing password-protected vaults. Enter the current password and confirm a new PIN; saved accounts, URL matching rules and selected input fields are preserved.
- Added a 60-second delay after five incorrect attempts. Further incorrect attempts increase the delay up to 15 minutes. Attempts persist across browser restarts and reset after successful unlocking.
- Local TOTP QR image import in Add account, using a file picker, drag-and-drop or Ctrl+V image paste.
- PNG, JPEG and WebP support, limited to 10 MB and 24 megapixels per image. Use one QR code per image.
- Import of the account name when blank, plus a masked setup URI retaining the secret, algorithm, digits and period. Users review the decoded settings before saving; existing site settings and custom account names are preserved.
- Clear errors for unreadable images, invalid secrets, unsupported settings, ordinary website QR codes, HOTP codes and authenticator migration/export QR codes.
- Cancellation of pending imports when leaving the form, manually editing the secret, cancelling or locking the vault.
Update the existing installation and reload it. Do not uninstall the extension or clear its storage to update.
Existing users see Switch to a PIN once. The old password must be verified before conversion. The re-encrypted vault is saved before replacing the active key; if saving fails, the original vault remains usable with its old password. After a successful conversion, unlocking requires only the PIN.
The previous password-only UI cannot unlock a converted vault. Do not downgrade to 1.1.0 after conversion. Keep backup TOTP keys and the PIN; there is no PIN recovery. Firefox and Chrome continue to have separate vaults.
- AES-256-GCM encryption and PBKDF2-SHA256 with 600,000 iterations remain in use. PINs are not stored in plaintext.
- A four-digit PIN has only 10,000 possibilities and is weaker against offline guessing than a strong password. The failed-attempt delay applies to extension login attempts, not offline attacks against copied vault data.
- Saved vaults now have an
auth: "pin"marker. A localauthAttemptsrecord stores the failure count and retry time. Legacy vaults without the marker require conversion. - No additional permissions or runtime libraries were introduced by this release. QR import, autofill, URL matching, auto-lock choices, password-manager key copying and icon tooltips remain available.
Source code released under MIT License