ente Authenticator
Features: End-to-end encrypted cloud backups and multi device synchronization. Offline mode and import & export tokens. It's the only open-source solution that is available for…
Private alternatives to Google Authenticator, Microsoft Authenticator, Authy, vetted against our public criteria.
Grouped by threat level
Features: End-to-end encrypted cloud backups and multi device synchronization. Offline mode and import & export tokens. It's the only open-source solution that is available for…
Aegis Authenticator: Encryption, Organization and Backups for Android
Features: Device synchronization, modern user-interface and backups. The main advantages are the browser extensions that enable one-tap authentication and no need to switch…
Unlisted for now because Raivo was sold, and the new owner wasn't able to clarify concerns listed in the GitHub discussion. The warning will be removed once the situation is…
A TOTP authenticator app that stores one-time password secrets on a YubiKey hardware key rather than on the device, available on Windows, Mac, Linux, and Android.
No matches for those filters.
| Tool | Backup | Cost |
|---|---|---|
| E2EE cloud | Free |
| Local export | Free |
| On hardware key | · |
| Encrypted cloud | Free |
| | None | Free |
| E2EE cloud | Free |
Two-factor authentication adds a second layer of protection on top of your password. Even if someone steals your login, they still need the rotating code from your authenticator app to get in. The open-source apps below keep those codes on your own devices, with encrypted backups and a clear export path, so a leaked password is not enough to take over an account and you are never locked into one platform.
The authenticators baked into the big platforms tie you to an account rather than to an open standard. Google Authenticator long shipped with no backup at all, so a lost phone meant re-enrolling every site by hand, and its newer cloud sync routes your codes through the same account that already tracks the rest of your life. Authy locks your tokens inside a proprietary cloud with no clean export, which is the trap to avoid. The fix is not a hidden setting. It is an app built around the portable TOTP standard, where your codes belong to you and travel with you.
Every app here is measured against our public listing criteria. We require open source so the code generating your codes can be independently inspected, an encrypted backup or a real export path so a lost device never means lost accounts, and offline operation so the app never has to phone home to work. We weigh how easy each one makes day-to-day use, because a second factor people abandon protects nothing. We only list an authenticator we would happily trust with our own logins, and we say plainly where each one compromises.
Four things matter. First, open source, so the security is verifiable rather than a promise. Second, an encrypted backup or token export, so losing your phone is recoverable instead of catastrophic. Third, the platforms you actually use, since an app that runs on your phone but not your laptop forces you to reach for the phone every login. Fourth, offline code generation, so the app works without a network and has no excuse to talk to a server. Aegis Authenticator on Android and Ente Authenticator across platforms are good examples of all four in one place.
Yes, and the gap is wider than it looks. A texted code is a secret in transit, and anything in transit can be intercepted, phished onto a fake page, or stolen outright through a SIM-swap that hands your number to an attacker. A code generated on your device never leaves it until you type it, so there is nothing to intercept. The one weakness apps share with codes is the fake-login-page trick, where you are fooled into typing a real code into an impostor site. If that is your worry, a hardware security key closes it, because the key checks the web address before it responds.
Open the new app, then visit the security settings of your most important accounts, email first, and choose to add an authenticator. Each site shows a QR code during setup. Scan it, confirm the first generated code, and that account is protected. Work through your logins over a week rather than all at once, and turn on the encrypted backup before you go far, so the move is reversible. If you are leaving the platform authenticators specifically, the same step replaces Google Authenticator one site at a time, and pairing your authenticator with a strong, unique password on every account is what makes the second factor count.