User Guide
For SSem TouchOTP 1.0.1
1. Install
- Buy and install SSem TouchOTP from the Mac App Store (get the app). The App Store also installs updates for you.
- Open it from Applications or Launchpad. The app lives in the menu bar, not the Dock: look for the lock icon and click it to open the panel.
If you use the DMG version previously downloaded from this website, installing the App Store version replaces the app in Applications. Your vault and accounts stay as they are.
You need macOS 14 or later, Touch ID (built in, or a Magic Keyboard with Touch ID on an Apple silicon Mac), a macOS login password, and at least one enrolled fingerprint.
2. First setup
- Click the menu bar icon and choose Create Vault with Touch ID.
- Touch the sensor once. The vault is created and opens right away.
The vault is the encrypted file that holds your accounts. Its key lives in this Mac’s Secure Enclave and works only with the fingerprints enrolled right now. The Touch ID prompt has no password button: there is deliberately no way to open the vault with a password.
3. Add accounts
Click Add Account at the bottom of the panel. There are three ways to add an account. First open the two-step verification settings of the service (for example GitHub or Google) so its QR code or secret key is on screen.
QR Image
- Paste: press ⌃⇧⌘4 to capture the QR code area to the clipboard, then paste it on the QR Image tab.
- File: Choose File in Window… in the panel lets you pick an image file in a separate window. You can also drop image files onto that window.
- PNG, JPEG, HEIC, TIFF, GIF and BMP images are supported. QR codes are recognized on this Mac only, and the images are not stored.
Check the issuer and account name in the preview, then click Add.
A QR image contains the secret key. Delete screenshot files after adding the account. A pasted image is cleared from this Mac’s clipboard right after it is read, but if you use a clipboard history app, remove it from that history too.
Paste Address
Paste an address that starts with otpauth:// to see a preview that never shows the secret. If the address is still on the clipboard after adding, it is cleared.
Manual
Enter the issuer, account name and secret key (Base32). If needed, change the type (time-based TOTP or counter-based HOTP), algorithm (SHA-1, SHA-256, SHA-512), digits (6–8) and period (15–120 seconds). The secret key field is a secure field that hides what you type.
4. Move from Google Authenticator
- In Google Authenticator on your phone, open the menu › Transfer accounts › Export accounts and select the accounts to move.
- Get the QR code onto your Mac — for example, photograph it with another device and AirDrop the photo, or send a phone screenshot to your Mac (some phones block screenshots of this screen).
- In SSem TouchOTP, paste the image on Add Account › QR Image, or add it as a file in the window.
- If the export has several QR codes, add them all. Progress such as “1 and 2 of 3” is shown.
Afterwards, delete the QR photos on your phone and Mac. The accounts stay in Google Authenticator; decide yourself whether to keep using them on your phone.
5. Use codes
- Click an account row to copy its code. The copied code is cleared automatically after 30 seconds and is marked so it doesn’t go to other devices (Universal Clipboard) or clipboard history apps.
- The ring on the right shows the seconds until the code changes. It turns orange at 10 seconds and red at 5.
- For counter-based (HOTP) accounts, clicking a row that shows no code yet, clicking ↻, or choosing Generate and Copy Next Code from the right-click menu creates a new code and advances the counter by one. Clicking a code that is already shown copies the same code again without changing the counter. Closing the panel hides the code, so the next click creates a new one. Only do this when you need a code.
- Right-click an account for Copy Code and Delete…. A deleted account can’t be recovered.
6. Locking
- The vault locks after the chosen idle time (1 minute by default).
- It locks immediately on screen lock, screen saver, sleep and user switching.
- Lock it any time with the lock button at the top of the panel or Settings › Lock Now.
- Opening the panel while locked shows the Touch ID prompt. If you cancelled it, click Unlock with Touch ID.
- Locking also discards pending QR imports and clears a copied code from the clipboard.
7. Back up and restore
Adding or removing a fingerprint makes the vault impossible to open. Make a new backup whenever you add accounts. If accounts changed since the last backup, a reminder appears above the list.
Make a backup
- Click Settings › Export or Import Backup…. The backup screen opens in a separate window.
- We recommend Generate Random Passphrase. Click the generated passphrase to copy it (cleared after 30 seconds), and write it down on paper or in a password manager. A passphrase you choose must be at least 12 characters, and overly simple ones (repeats, sequences) are rejected.
- Type the same passphrase in the confirmation field, click Confirm with Fingerprint and Export…, and choose where to save it.
The backup file (.touchotp) is encrypted with AES-GCM using a key derived from your passphrase (PBKDF2-SHA256, 600,000 iterations). Keep a copy somewhere safe outside this Mac too, such as an external drive.
Import a backup
- On the same backup screen, choose the file with Choose Backup File… and enter the passphrase.
- Click Import. The backup’s accounts are added to the current vault. Accounts that already exist (same secret key) are skipped, and existing accounts’ settings and counters are never changed.
If you forget the passphrase, there is no way to open the backup. We can’t recover it either.
8. After changing fingerprints
When you add or remove a fingerprint, macOS invalidates the security key and the app shows “The vault can’t be opened”. This screen deletes nothing.
- Click Try Again once to be sure. If you did change fingerprints, it will keep failing.
- Click Reset…. The old vault file is kept aside, not deleted.
- Create a new vault with Create Vault with Touch ID.
- Import your backup file in Settings › Export or Import Backup….
If the screen says the vault file is missing or unreadable but the security key is fine, it isn’t a fingerprint problem. Put the file back and click Try Again, or choose Start an Empty Vault with the Same Key….
If you see “An older copy of the vault file was opened” after unlocking, the vault file was replaced with an earlier copy (for example by a Time Machine restore). If you didn’t do that yourself, someone may have swapped the file, so check your accounts. If everything looks right, click Keep This State.
9. Move to a new Mac
The vault file is bound to the Secure Enclave of the Mac that created it, so a copy won’t open on another Mac. Make a backup on the old Mac, install the app on the new Mac, create a vault, and import the backup.
10. Settings
- Language: choose Use System Setting, 한국어 or English, then click Restart Now to apply it (the app restarts locked).
- Auto-Lock: choose how long to wait when idle (30 seconds, 1, 2 or 5 minutes).
- Backup: shows whether an up-to-date backup exists and opens the backup screen.
Only one copy of SSem TouchOTP runs at a time. If it is already running and you open another copy from a different location, that copy explains and quits. This prevents two copies from overwriting the same vault.
11. Updates
The Mac App Store handles updates. The app itself never connects to the internet, so it doesn’t check for new versions on its own. Updating keeps your vault and accounts.
12. Uninstall
- Make a backup first if you may need your accounts later.
- Quit the app and move SSem TouchOTP from Applications to the Trash.
- To remove the account data too, press ⌘⇧G in Finder and delete the folder
~/Library/Containers/com.levelupsoft.touchotp.
The Secure Enclave key and the wrapped vault key (with a generation number) stay in this Mac’s keychain. Without the vault file they can’t bring back any account information. If you reinstall and create a new vault, the app asks before replacing them.
More questions? See the Support page.