AuthWisp watches your own mailboxes for one-time passcodes and magic links, then lets you copy the code, open the link, or jump to the source email. No inbox, no tracking, no hosted backend.
Newest code surfaces in the popover. Copy clears from the clipboard after 90 seconds.
Links never auto-open. You open them explicitly, or jump to the source email instead.
Auth context required. Receipts, shipping, invoices and newsletters are rejected.
Gmail: Google OAuth (read-only) or app password over IMAP.
iCloud: app-specific password over imap.mail.me.com:993.
Outlook: Microsoft Graph (read-only) — rolling out; app passwords over IMAP where tenants allow.
OAuth tokens and app passwords stay in the macOS Keychain. Account metadata lives in ~/Library/Application Support/AuthWisp/. Message bodies and codes are never logged.
https://authwisp.panic.run/ ·
Icon: Wisp Cut mark.authwisp.panic.run.