Paste the setup key a site gave you, or scan its QR code. The six digits appear below, worked out in your browser and never sent anywhere.
——————
No accounts here. Add a key and it stays until you close this tab.
Nothing is stored. The key stays in this tab and is gone when you close it. No localStorage, no history list, no third-party script on this page.
On the 2FA screen, choose “authenticator app”, then look for can’t scan the QR code. That reveals the Base32 setup key, usually 16 or 32 characters of A–Z and 2–7.
Spaces and dashes are ignored. Upload the QR image, drop it on the field, or scan it with a camera — the issuer and parameters come straight out of it.
Save the same key in a password manager, and keep the site’s recovery codes offline. A browser tab is a second factor, not a backup plan.
Each guide covers where that service hides the text key, the parameters it issues, and its recovery path.
No account, no cookie banner, no third-party script. Everything ships from this origin under a Content-Security-Policy with connect-src 'none', so the browser blocks any outbound request. Load the page once and it keeps working offline.