Rieck Authenticator generates the 6-digit one-time codes you need when a service asks for two-factor authentication.
Add an account by scanning the QR code the service shows you — or by typing the key in. The code is then ready in the app, even when you have no connection. One tap on the row copies it.
ON THE PHONE, NOT IN THE CLOUD
There is no account to create and no server to sign in to. Your keys are encrypted and stored in your phone's secure storage, and they never leave the device. The app sends no information about you or your accounts anywhere, and it doesn't need an internet connection to generate a code.
LOCKED WITH YOUR PASSCODE
The app unlocks with your fingerprint, your face or your 6-digit passcode. The keys are encrypted behind that code, not merely hidden. Put the app away and it locks again. Its contents are hidden in the app switcher, so your codes never end up as a screenshot on disk.
RECOVERY CODES
The one-time codes a service gives you when you turn on two-factor can be stored alongside the account. They are encrypted the same way — and they are the only way back in if you lose the phone.
STANDARDS, NOT HOMEBREW
Codes follow RFC 6238 (TOTP) and RFC 4226 (HOTP), so the app works with the services you already use. Both 6- and 8-digit codes, and SHA-1, SHA-256 and SHA-512.
FIXES THAT ARRIVE
The app can fetch a fix for itself, so a security issue can be closed the same day. The update is signed, downloads in the background, and is only applied while the app is locked — never while your codes are on screen.
IF YOU LOSE THE PHONE
Your accounts are gone. That is the price of there being no copy anyone else can reach. Keep your services' recovery codes somewhere other than in the app.
Two-factor codes. Your keys stay on the phone, encrypted.