backend
TapToDesk
Send a password or snippet from phone to browser through a QR session, encrypted end to end, nothing stored.
Overview
TapToDesk moves short secrets, a password, a 2FA code, an API key, from your phone to your desktop browser without an account or a copy left anywhere. The Chrome extension makes a fresh RSA-2048 key pair and shows a QR code; the phone scans it, encrypts the text and sends it; the FastAPI relay forwards ciphertext over WebSocket and holds nothing. Open source under the MIT licence.
RSA-2048per-session keys
0data stored on the server
Features
Security
- RSA-OAEP 2048 key pair generated per session in the extension
- End to end: the server relays ciphertext and never sees plaintext
- Sessions locked to the first device
- Keys in Redis expire on a TTL; HTTPS required
Desktop extension
- Generates the key pair on demand and shows the QR code
- Messages arrive over WebSocket and are decrypted locally
- Configurable session duration and message limit
Mobile
- Progressive web app with offline support
- Built-in QR scanner; works with the native camera too
- Encrypts with the Web Crypto API before sending
- Redirects automatically when the session expires
Performance
- No polling: WebSocket delivery
- Redis-backed sessions with TTL cleanup
- Multiple messages per session
Technical details
- Built with
- Python, FastAPI, Redis, WebSockets, Web Crypto API, Chrome Extension API, PWA
- Type
- backend
- Status
- In production
Have something slow, manual, or fragile in production?
Tell me what it is. I reply within two working days, with questions.
Let's connect