Linux

Where Does OTPClient Store Secrets and Config?

OTPClient keeps a small config file pointing at a user-chosen encrypted database on Linux, with only the DB password optionally in Keyring.

Last updated

OTPClient inverts the usual layout. Configuration is tiny and fixed while the database floats wherever first run placed it. The config file records that choice, so backup starts by reading it.

Secrets stay encrypted at rest with modern key derivation, decrypting into locked memory alone. Keyring holds at most the database password when switched on. Exports cover third-party formats through both interface and terminal with size-capped settings JSON.

Where OTPClient stores this, by platform

Linux
~/.config/otpclient/otpclient.cfg

Fixed config recording the user-chosen database path, honoring XDG config home with a Flatpak twin. Database and bak sibling live at the recorded path with strict permissions. Secrets never touch this file.

Frequently asked questions

How do I back up OTPClient?

Copy the config file plus your database file with its bak twin, keeping 0600 permissions. The database path was chosen at first run with no fixed default, so the config tells you where it went. Flatpak builds nest both under the app var tree.

What is the default OTPClient database path?

There is none to quote. First run asks where to create the AES-256 database, current versions using Argon2id key derivation. Secrets decrypt into locked memory only. Anyone documenting a default path is describing their own choice.

Does OTPClient use GNOME Keyring?

Only the database password, and only when enabled since 2.6. Secrets themselves never enter Keyring. Native backup and third-party import/export run through the GUI and CLI with compact JSON settings.

Notice an outdated path? Let us know.