Skip to main content

OTPilot

OTPilot is a local-first CLI application for fetching one-time passwords from email accounts.

The first supported provider target is Gmail via IMAP over SSL with Google App Passwords. The architecture is intentionally not Gmail-specific: Gmail is a provider configuration layered on a generic IMAP transport so Outlook, Yahoo, Proton Bridge, and custom IMAP servers can be added without changing the CLI or application services.

OTPilot is available on PyPI:

pip install otpilot

Platform Support

OTPilot supports cross-platform execution on:

  • Windows
  • macOS
  • Linux X11 (Wayland is unsupported)

Product Principles

  • Local only: no server, hosted API, relay, sync service, or cloud dependency.
  • No telemetry: OTPilot does not collect usage, diagnostics, crash reports, or analytics.
  • No OAuth: email access uses IMAP over SSL and provider-specific app passwords.
  • Secure credentials: passwords are stored in the operating system credential vault via keyring (macOS Keychain, Windows Credential Manager, Linux Secret Service), never in config files.
  • Documentation first: public behavior is incomplete unless docs are updated with code.

Current Status

Version 3.0.0 features credential-backed Gmail IMAP fetching, candidate-based OTP extraction, optional clipboard copying via otpilot fetch --copy (which copies the OTP to the clipboard without printing it to terminal output), synchronous polling watch mode, and cross-platform global hotkey support.

CLI

otpilot fetch
otpilot fetch --copy
otpilot watch
otpilot hotkey
otpilot login user@gmail.com
otpilot logout user@gmail.com
otpilot config
otpilot doctor
otpilot version

See docs/cli-reference.md for command behavior and documentation details.

Global Hotkey

otpilot hotkey registers a system-wide hotkey using a cross-platform pynput adapter so it works while another application has focus:

  • Windows & Linux (X11): Ctrl+Shift+O by default.
  • macOS: Cmd+Shift+O or Ctrl+Shift+O by default.

Configure another supported combination in OTPilot's non-secret TOML configuration file, for example:

hotkey = "cmd+shift+o"

Note: On macOS, Accessibility permissions are required for hotkey capturing. On Linux, only X11 display servers are supported (Wayland is unsupported).

Press Ctrl+C to unregister the hotkey and exit. Each invocation copies the OTP to the clipboard; OTPilot never prints it in hotkey mode and does not paste it automatically.

Privacy Guarantee (fetch --copy)

When using otpilot fetch --copy or running in hotkey mode, OTPilot copies the extracted OTP directly to your system clipboard without printing the value to terminal output.

Architecture

OTPilot is layered:

CLI
Application Services
Domain
Providers
Infrastructure

The provider architecture is:

OTP Source
  -> IMAP Provider
      -> Gmail
      -> Outlook
      -> Yahoo
      -> Custom IMAP

See architecture.md for the complete architecture, dependency graph, and design decisions.

Documentation

Development

python -m pip install -e ".[dev]"
pytest
ruff check .
mypy src/otpilot

License

MIT.

Release files for otpilot 3.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for otpilot 3.0.1
File Size Uploaded
otpilot-3.0.1.tar.gz 58.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for otpilot 3.0.1
File Interpreter ABI Platform
otpilot-3.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 118.4 kB

Release files / otpilot-3.0.1.tar.gz

Download URL otpilot-3.0.1.tar.gz
Size 58.0 kB
Tags Source
SHA-256 checksum
How to use checksums
af3af6a5d78fda34b5a3037fefedc019815fdd5f7f4e8855cdfd40bc6e22b347
BLAKE2b-256 checksum
How to use checksums
ff9c3e2005594c1b34f021001faf03c90ec47ff31d802d63a6db4b0277449ee7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / otpilot-3.0.1-py3-none-any.whl

Download URL otpilot-3.0.1-py3-none-any.whl
Size 60.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ebdfb86da1419d1dbb8078ec8e967a8e73f5c6919d25e0e3967c1391c9264e23
BLAKE2b-256 checksum
How to use checksums
d29e15bc6c2bed480cdf9204f48a94469837d22002ab7080a76e883e44b222fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.0.1 This release

2 release files

3.0.0

2 release files

2.3.4

2 release files

2.3.2

2 release files

2.3.1

2 release files

2.3.0

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page