Privacy-first · Zero-knowledge

Your keys.
Your device.
Zero knowledge.

2FA codes, passwords, secure notes and passkeys — in one end-to-end encrypted vault. Generated on your device, synced without ever being read.

  • No ads
  • No tracking
  • Open-source crypto
  • Works offline
Authenticator
GitHub@alexdev 552 190
Amazonwork 746 038
CloudflarePasskey · no password
Dropboxpersonal 319 704
AES-256 · on-device Real-time sync

Protects your logins across the services you already use

Google Apple GitHub Microsoft Amazon Cloudflare Dropbox Facebook PayPal Discord X
3-in-12FA · passwords · passkeys
AES-256GCM encryption at rest
600,000PBKDF2 key-hardening rounds
0 bytesof your data we can read
35languages, RTL included

Everything, in one vault

More than an authenticator.

2FA is free and unlimited. Premium adds a full password manager, advanced security and multi-device sync — all encrypted the same way.

Two-factor authenticator

TOTP, HOTP and Steam Guard codes, generated entirely on-device. Add by scanning a QR code or import from Google Authenticator, 2FAS, Aegis and Authy in seconds.

081 423552 190746 038

Passkeys

Create and sign in with passkeys (WebAuthn) straight from AutoFill. Passwordless and phishing-resistant.

Password manager

Strong generator, autofill on iOS & macOS, breach monitoring and a live security score.

Secure notes & backup codes

Keep recovery codes and sensitive notes encrypted right next to your 2FA — never in plain text, never on a server that can read them.

Widgets, Watch & Live Activity

Read codes from your Home Screen, Lock Screen, Apple Watch and Dynamic Island.

Decoy vault & Travel Mode

A second hidden vault under a different passcode, plus location lock and border-crossing Travel Mode.

Real-time sync, no risk

Optional sync over iCloud, Google Drive, WebDAV or our private server. Push-driven — the server only ever sees ciphertext.

Up and running in a minute

How it works.

  1. 1

    Scan or import

    Point at a QR code, or import your existing accounts from Google Authenticator, 2FAS, Aegis or Authy.

  2. 2

    Codes on your device

    Every code is generated locally and encrypted at rest with AES-256. Nothing leaves the phone to make a code.

  3. 3

    Sync, still sealed

    Turn on optional sync and your vault travels as an opaque blob — encrypted before it ever leaves the device.

  4. 4

    Autofill everywhere

    Fill codes, passwords and passkeys across Safari and apps on iPhone, iPad and Mac.

The part that matters

Security you can actually verify.

Most apps ask you to trust them. We publish the cryptographic core so you don't have to — clone it, read it, run the tests.

  • AES-256-GCM encryption at rest — keys never leave your device.
  • PBKDF2-HMAC-SHA256, 600,000 rounds for passphrase-wrapped backups.
  • X25519 ephemeral-static ECDH for per-device sharing — the server never holds the key.
  • Zero-knowledge sync — your vault is an opaque blob to us.
  • Face ID / Touch ID unlock, with a decoy vault for coercion.
Your deviceDEK · Secure Enclave
9f2c…a7fbciphertext
Our serverstores blob · can't read

Encryption happens before anything leaves your device.

No trackingZero analytics SDKs, no advertising identifiers.
No ads, everYou're not the product. Never will be.
Works offlineCodes generate on-device, no network needed.
35 languagesNative localization, right-to-left included.

Where it stands

One app instead of three.

Most people juggle an authenticator, a password manager and a notes app. Authenticator Pro does all three, encrypted the same way.

CapabilityAuthenticator ProTypical authenticatorTypical password manager
Unlimited 2FA (TOTP/HOTP/Steam)
Passkeys (WebAuthn)Some
Password manager + autofill
Encrypted secure notes
Zero-knowledge syncRareVaries
Open-source, testable cryptoSome
Works fully offlinePartial
Decoy vault & Travel Mode
No ads · no trackingVariesVaries

Comparison reflects common feature sets in the category and is not a claim about any specific product.

Built for your whole setup

One vault, every device.

iPhone & iPad

Home Screen & Lock Screen widgets, Live Activities, Dynamic Island, Face ID and system AutoFill.

Mac

Menu-bar codes, a global Quick-Search hotkey, Safari AutoFill and on-screen OCR to grab any code.

Apple Watch

Your codes on the wrist — glanceable, offline, always a tap away.

Android Soon

The same zero-knowledge vault is coming to Android, with Credential Manager passkeys.

Simple & fair

2FA is free. Forever.

Unlimited two-factor codes cost nothing. Premium unlocks the password manager, advanced security and sync.

Free

$0/ forever

  • Unlimited TOTP / HOTP / Steam codes
  • Import from other authenticators
  • Widgets, Watch & Live Activity
  • Face ID unlock, works offline
Download free
Most complete

Premium

from $2.49/ month

  • Everything in Free, plus:
  • Password manager & autofill
  • Passkeys & secure notes
  • Zero-knowledge multi-device sync
  • Decoy vault, Travel Mode, breach monitor
Get Premium

Final pricing is shown in the App Store for your region. Subscriptions verified server-side.

Good questions

Frequently asked.

Is it really free?

Yes. Unlimited 2FA codes are free forever with no ads and no tracking. Premium is optional and only unlocks the password manager, advanced security and multi-device sync.

Can you read my data?

No. Your vault is encrypted with AES-256 on your device before anything syncs. Our server only ever stores an opaque blob — it never holds your keys, so it physically cannot read your accounts, passwords or notes.

What if I lose my phone?

If you enabled sync, restore on a new device and unlock with your passphrase. You can also export an encrypted, passphrase-wrapped backup (PBKDF2, 600,000 rounds) and keep it anywhere safe.

Does it work offline?

Completely. Codes are generated on-device using the standard TOTP/HOTP algorithms, so you never need a network connection to sign in.

Which apps can I import from?

Google Authenticator, 2FAS, Aegis and Authy exports, plus standard otpauth:// QR codes and migration URIs.

Is the cryptography auditable?

The cryptographic core is published as a standalone, dependency-free package with a full test suite (TOTP/HOTP RFC vectors, AES-GCM tamper rejection, WebAuthn assertion verification). You can clone it and run swift test yourself.

Take back control of your keys.

Free, unlimited 2FA. Encrypted the same way whether you pay or not.

iOS 16+ · macOS 14+ · Face ID / Touch ID · 35 languages