A library terminal, a hotel business center, a friend's laptop, a work kiosk — scan a QR code with your phone and sign in without ever typing your password or leaving a session behind. The exchange is end-to-end encrypted; the relay server never sees your credentials.
Free forever · MIT License · No account required
Add AuthRelay to Chrome. It watches for Google sign-in pages automatically — nothing to configure.
When a sign-in is detected, a QR code appears on the desktop. Scan it with the AuthRelay app on your phone.
Sign in with Google on your phone, where you already trust the device. The desktop browser completes sign-in the moment you approve.
Your phone and desktop negotiate a fresh encryption key for every session and encrypt the OAuth callback before it ever leaves the device. The relay server only forwards ciphertext it cannot read — even if it were compromised, there's nothing usable to steal.
Sessions are ephemeral by design: they expire five minutes after creation, and nothing is persisted once a sign-in completes. The full protocol, extension, and server are MIT-licensed and open for anyone to audit on GitHub.
Install the extension on desktop, then the app on your phone.
AuthRelay is free and open source. If you find it useful, consider supporting development.