KW Authenticator 2FA & OTP

Content rating
Everyone
5+
Downloads
Content rating
Everyone
Learn more
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image
Screenshot image

About this app

KWAuthenticator PRO is an independent fork of privacyIDEA Authenticator, developed and published by KW Krzysztof Wielgosz under the Apache 2.0 License. The app is not affiliated with or officially supported by NetKnights GmbH or the privacyIDEA project.

Protect sign-ins with one-time passwords and complete privacyIDEA Push support.

Key features:
• TOTP and HOTP one-time codes
• approval of privacyIDEA Push requests with your organization's compatible server
• independent integration with the organization's own Firebase project
• secure setup of public Firebase client parameters using an organization-generated QR code — without a Firebase service-account private key
• separate tabs for business and private tokens
• improved handling of token folders and privacyIDEA containers
• improved token visibility, recovery, import, export, and synchronization
• add tokens by QR code or manually
• device biometric access protection
• strict protection of the Push token private key with strong biometrics, optionally bound to the device's current biometric enrollment set
• optional home-screen widget
• redesigned, clearer interface

Strict biometrics for Push tokens:
This mechanism applies only to the privacyIDEA Push token private key. It does not change TOTP/HOTP codes or other token types, and it is separate from the optional lock for access to the whole app.

The mode is enabled during Push enrollment when the server sends app_force_unlock=biometric. If the server omits the two extended parameters, KWAuthenticator PRO uses fail-closed defaults: strong biometrics and key invalidation after a biometric enrollment change. On Android this means class-3 biometrics for every Push signature, with no fallback to the device PIN, pattern, or password.

A cancelled or failed biometric attempt remains retryable and does not invalidate the token. Restarting the app does not reset the protection. Adding a biometric or removing all enrolled biometrics invalidates an enrollment-bound key; Android does not guarantee invalidation when only one of several biometrics is removed. If the key is missing or invalidated, Push approval is blocked and the token must be removed and enrolled again. Removing the token from the app also removes its locally protected key. The platform confirms a biometric match but does not identify a named person, face, or finger.

Without app_force_unlock=biometric, strict Push-key protection is not enforced. For a server administrator to explicitly enforce and control the biometric level and the response to enrollment changes, a compatible privacyIDEA server fork is required to send:
push_app_force_unlock=biometric
push_app_biometric_level=strong
push_app_invalidate_on_biometric_change=true
The last two settings are KW extensions and are not available in standard upstream privacyIDEA.

Token secrets are stored securely on the device. Camera images used for QR scanning are processed locally. The app does not record audio and contains no ads or behavioral analytics.

Push authentication requires a compatible privacyIDEA deployment and Firebase configuration supplied by your organization.

Origin: privacyIDEA Authenticator v4.7.3 by NetKnights GmbH and contributors. KWAuthenticator PRO contains substantial independent modifications by KW Krzysztof Wielgosz.
Secure OTP codes and privacyIDEA push approvals on your Android device
Updated on
Aug 15, 2026

Data safety

Safety starts with understanding how developers collect and share your data. Data privacy and security practices may vary based on your use, region, and age. The developer provided this information and may update it over time.
  • No data shared with third parties
    Learn more about how developers declare sharing
  • This app may collect these data types
    App activity, App info and performance, and Device or other IDs
  • Data is encrypted in transit
  • Data can’t be deleted

What’s new

privacyIDEA Push approvals no longer block work with other tokens, and the store description now explains strict strong-biometric protection for the Push key. Technical: Push operations are serialized per token while preserving biometric-enrollment binding.