Thanks, i took a look in the page and it looks quite simple. One question i have would be that it mentions:
> TOTP credentials are also based on a shared secret known to both the client and the server
AFAICT this "shared secret" is something that is shared between the service you want to authenticate with (e.g. PyPI) and "you" (your password manager, TOTP client or whatever), right?
In which case i guess this sounds something like it can be done fully locally indeed.