5 items
Store 2FA secrets and fill one-time codes with a right click. Imports directly from Google Authenticator exports. Sesame fills your two-factor codes for you. Right-click any verification box and choose "Use OTP code". The submenu lists only the codes saved for the site you are on — pick one and it goes straight in. BRING YOUR CODES OVER Already using Google Authenticator? Open it, go to Transfer accounts → Export accounts, and paste the text it encodes into Sesame's import screen. Or drop the QR screenshots straight in. Everything is parsed on your own machine. You get a preview of what was found, with codes you already have marked as duplicates, before anything is saved. Setup keys from sites that show you a string instead of a QR code work too, as do otpauth:// URIs from other authenticator apps. FOUR WAYS TO FILL • Right-click → Use OTP code • A chip that appears when you click into a 2FA box, with the code ready to fill • Alt+Shift+O to fill the best match from the keyboard • The toolbar popup, with every code and a live countdown — click one to copy Filling handles ordinary text boxes, contenteditable fields, and the split six-little-boxes widgets that defeat most autofill. CODES GO WHERE THEY BELONG Every account carries a list of the sites it may be used on, filled in on import and editable at any time. If an account has domains, only those domains match it. A saved GitHub code is offered on github.com and its subdomains — never on githubb.com, github-login.com, or github.com.evil.example. Resemblance to a site's name is never enough to pull a code onto it. Several logins on one site? All of them are offered, so you can pick the right one. NOTHING LEAVES YOUR BROWSER Sesame makes no network requests at all. No account, no sync service, no analytics, no telemetry, no third-party code. Codes are computed locally with the browser's own WebCrypto. Add a passphrase and your secrets are encrypted with AES-256-GCM behind a PBKDF2-derived key. You enter it once per browser session, not once per use. Optional auto-lock after 5, 15 or 60 minutes. YOUR DATA STAYS YOURS Export whenever you like: back to Google Authenticator format, as otpauth:// URIs, or as a JSON backup you can restore from. Source code: https://github.com/joseserro/sesame-2fa-autofill
Aug 30, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.