Give https://en.wikipedia.org/wiki/Time-based_one-time_password#A... a read, it's extremely simple.
> TOTP credentials are also based on a shared secret known to both the client and the server
AFAICT this "shared secret" is something that is shared between the service you want to authenticate with (e.g. PyPI) and "you" (your password manager, TOTP client or whatever), right?
In which case i guess this sounds something like it can be done fully locally indeed.
[0] I have a very old Android phone that i always keep offline
I had a huge jackie chan meme moment at that point.
Then I realized that, all along, my password manager has a feature to store TOTP, and there is not even a strict need to use all these authenticator apps. (Of course, as someone who strives to exercise some security mindfulness, I reckon it undermines much of the overall point of TOTP to keep it within the same datastore as your account password.)
It's really simple; I once wrote an implementation in Python in 20 lines or so based on just the specification, and I'm not a crypto guy at all. It's probably the simplest crypto systems to implement. Things like "connect your authentication app" make it sound complicated, but all that does is store a short secret in the app.
One clear advantage of this is that a code is only valid for a short period of time (usually a few minutes at the most). I can't re-use the code you used yesterday, and intercepting codes is also much harder as it's much more time-sensitive.