All it requires is the initial setup key and a somewhat accurate (~30s) time source.
Give https://en.wikipedia.org/wiki/Time-based_one-time_password#A... a read, it's extremely simple.
Give https://en.wikipedia.org/wiki/Time-based_one-time_password#A... a read, it's extremely simple.
> TOTP credentials are also based on a shared secret known to both the client and the server
AFAICT this "shared secret" is something that is shared between the service you want to authenticate with (e.g. PyPI) and "you" (your password manager, TOTP client or whatever), right?
In which case i guess this sounds something like it can be done fully locally indeed.
[0] I have a very old Android phone that i always keep offline