Skip to content
Hardik Zinzuvadiya
Let's connect

backend

TapToDesk

Send a password or snippet from phone to browser through a QR session, encrypted end to end, nothing stored.

Overview

TapToDesk moves short secrets, a password, a 2FA code, an API key, from your phone to your desktop browser without an account or a copy left anywhere. The Chrome extension makes a fresh RSA-2048 key pair and shows a QR code; the phone scans it, encrypts the text and sends it; the FastAPI relay forwards ciphertext over WebSocket and holds nothing. Open source under the MIT licence.

RSA-2048per-session keys
0data stored on the server

Features

Security

  • RSA-OAEP 2048 key pair generated per session in the extension
  • End to end: the server relays ciphertext and never sees plaintext
  • Sessions locked to the first device
  • Keys in Redis expire on a TTL; HTTPS required

Desktop extension

  • Generates the key pair on demand and shows the QR code
  • Messages arrive over WebSocket and are decrypted locally
  • Configurable session duration and message limit

Mobile

  • Progressive web app with offline support
  • Built-in QR scanner; works with the native camera too
  • Encrypts with the Web Crypto API before sending
  • Redirects automatically when the session expires

Performance

  • No polling: WebSocket delivery
  • Redis-backed sessions with TTL cleanup
  • Multiple messages per session

Technical details

Built with
Python, FastAPI, Redis, WebSockets, Web Crypto API, Chrome Extension API, PWA
Type
backend
Status
In production

Have something slow, manual, or fragile in production?

Tell me what it is. I reply within two working days, with questions.

Let's connect