Thanks for your rating and feedback!
You have already rated.
Offline 2FA codes. No internet permission, no tracking. Open source & secure.
MFA Authenticator generates two-factor authentication codes (TOTP, HOTP and Steam Guard) completely offline. The app does not have — and can never ask for — Android's Internet permission, so your secrets physically cannot leave your device. No ads, no analytics, no trackers, no account. Open source.
WORKS WITH EVERYTHING
• Time-based codes (TOTP, RFC 6238) with SHA-1, SHA-256 and SHA-512, 6–8 digits and custom periods
• Counter-based codes (HOTP, RFC 4226) with tap-to-generate
• Steam Guard's 5-character codes
SWITCHING IS EASY
• Scan any 2FA QR code — including Google Authenticator's "Export accounts" transfer codes
• Import from an image or screenshot, no camera needed
• Import backup files from Aegis (including encrypted vaults), 2FAS (including encrypted backups), andOTP and FreeOTP+
• Type a setup key manually when there is no QR code
• Duplicates are detected on every path, so importing twice is safe
LEAVING IS EASY TOO
Your accounts are yours. Export everything as standard transfer QR codes that Google Authenticator, Aegis, 2FAS and others can scan, or show any single account as a QR code from its detail screen.
SERIOUS ABOUT SECURITY
• Your vault is encrypted with AES-256-GCM using keys stored in your device's secure hardware (StrongBox where available) — the keys never leave the device
• Optional app lock with fingerprint or device PIN; when enabled, the vault key additionally requires your recent screen unlock
• Screenshots and screen recording are blocked by default
• Codes can be hidden until you tap them
• Copied codes are flagged sensitive and the clipboard clears itself
• App data backup and device-to-device transfer are disabled by design
STAY ORGANISED
• Groups with one-tap filtering
• Search, manual drag-to-reorder, alphabetical or most-used sorting
• Encrypted notes per account — keep recovery codes next to the account
• Material You dynamic colors, dark and light themes
PRIVATE BY ARCHITECTURE
The permission list is the privacy policy: camera (optional, only to scan QR codes) and the standard biometric prompt for app lock. Nothing else. The complete source code is public, so you do not have to take our word for any of this.
Note: keep a backup path for your accounts (export QR codes or recovery codes from the services). If your phone is lost, an offline authenticator cannot restore secrets from any cloud — by design.
One-click to install XAPK/APK files on Android!