SecureAuth: Offline 2FA

Content rating
Everyone
5+
Downloads
Content rating
Everyone
Learn more
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image

About this app

SecureAuth is a privacy-first, fully offline two-factor authentication (2FA) app and password vault. No cloud. No accounts. No telemetry. No ads. Every secret stays on your device — the app doesn't even request internet permission.

TWO-FACTOR AUTHENTICATION
• TOTP (RFC 6238), HOTP (RFC 4226) and Steam Guard tokens
• SHA-1 / SHA-256 / SHA-512, 4–8 digits, 15–60s periods
• Add accounts by QR scan, from an image, or manually
• Show any account as a QR code to move it to another device
• Live search, drag-to-reorder, next-code preview

PASSWORD VAULT & AUTOFILL
• Store passwords and passkeys in an encrypted local vault
• System-wide autofill via Android Credential Manager
• Biometric-gated access to your credentials

SERIOUS SECURITY
• Argon2id password hashing (Password Hashing Competition winner)
• AES-256 encrypted local database
• Brute-force protection with exponential-backoff lockout
• Optional data wipe after repeated failed attempts
• Auto-lock on inactivity, clipboard auto-clear
• Screenshot blocking & app-switcher privacy
• Clock-tamper detection and a security audit log

BACKUPS YOU CONTROL
• AES-256-GCM + Argon2id encrypted backup files
• Plain JSON export for interoperability
• Import from encrypted or plain backups — all offline

13 LANGUAGES
English, Türkçe, Deutsch, Español, Français, Português, Русский, العربية, Azərbaycanca, 日本語, 한국어, 中文 and more.

100% open source. Your secrets belong to you — SecureAuth just keeps them safe.
Updated on
Jul 7, 2026

Data safety

Safety starts with understanding how developers collect and share your data. Data privacy and security practices may vary based on your use, region, and age. The developer provided this information and may update it over time.
No data shared with third parties
Learn more about how developers declare sharing
No data collected
Learn more about how developers declare collection