Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Offline 2FA Vault for Android

x2y Authenticator

v1.2.0

Offline by choice. Secure by design. A high-security offline 2FA vault with Stealth Mode, encrypted Panic Backups, and WiFi Companion for seamless desktop access.

ANDROID100% OFFLINESTEALTH MODEZERO TELEMETRY

Free — no account, no cloud sync, no telemetry. Your secrets never leave your device.

At a glance

  • Versionv1.2.0
  • PlatformAndroid · APK
  • ProtocolTOTP (RFC 6238)
  • VaultAndroid Keystore, encrypted
  • PriceFree
  • Network permissionsNone for core use

Codes are generated on-device from locally stored secrets. Nothing syncs, so there is nothing to breach on a server.

Security features

Built for threats that other authenticators ignore

100% offline — no internet required ever

TOTP codes are computed entirely on-device using locally stored secrets and the system clock. The application has no network permissions and makes zero outbound connections. Airplane mode is the recommended operating environment.

Stealth Mode with duress protection

Configure a secondary PIN that opens a decoy vault populated with fake accounts. Under coercion, hand over the duress PIN — your real secrets remain invisible and inaccessible. The attacker sees a convincing but worthless vault.

Encrypted Panic Backup with Master QR

Export your entire vault as an encrypted backup protected by a master recovery key rendered as a QR code. Store the QR physically — in a safe, with a lawyer, split between trusted parties. Restore from it on any device running x2y Authenticator.

PIN + Biometric authentication

Unlock the vault with a numeric PIN, fingerprint, or both. Biometric data never leaves the Android Keystore — x2y Authenticator only receives a yes/no authorisation result from the hardware-backed secure enclave.

Convenience features

Security without the friction

WiFi Companion — stream codes to PC browser

Need a code on your desktop? The WiFi Companion securely streams TOTP codes from your phone to a PC browser over your local network. No cloud relay, no internet hop — the connection stays within your LAN and uses end-to-end encryption.

Smart Folders — Work, Finance, Social

Organise accounts into colour-coded categories. Switch between Work, Finance, Social and custom folders instantly. Each folder can have its own lock timeout and visibility rules.

Restore via Master QR or .x2y file

Two recovery paths: scan the Master QR code generated during Panic Backup setup, or import an encrypted .x2y backup file. Both methods restore the full vault with all accounts, folders and settings intact.

NTP Time Sync for accurate codes

TOTP codes depend on accurate time. x2y Authenticator optionally syncs against NTP servers to correct clock drift — the sync fetches only a timestamp, no personal data is transmitted, and it can be disabled entirely for air-gapped use.

Specifications

Technical details

x2y Authenticator specifications
Productx2y Authenticator
Versionv1.2.0
PlatformAndroid
ProtocolTOTP (RFC 6238)
StorageOn-device encrypted vault (Android Keystore)
SyncNone by design — no cloud, no server
AuthenticationPIN + Biometric (fingerprint via Android Keystore)
Stealth ModeDuress PIN opens decoy vault with fake accounts
BackupEncrypted Panic Backup via Master QR or .x2y file
ImportManual secret entry, otpauth QR scan
WiFi CompanionLAN-only encrypted stream to PC browser
FoldersWork, Finance, Social + custom categories
Time syncOptional NTP (timestamp only, disableable)
Network permissionsNone required for core operation
Telemetry0 bytes — verified continuously
Account requiredNone — ever
PriceFree
Developerx2y Devs Tools Ltd, Nairobi, Kenya

Quick start

From install to first code in four steps

  1. 01

    Install the APK

    Download the signed APK from Uptodown or APKPure. Enable installation from unknown sources if prompted. Verify the SHA-256 checksum before installing.

  2. 02

    Set your PIN and biometric

    Create a vault PIN on first launch. Optionally enable fingerprint unlock. Configure a separate duress PIN for Stealth Mode if desired.

  3. 03

    Add accounts

    Scan an otpauth QR code from any service's 2FA setup page, or enter the secret manually. Assign each account to a Smart Folder (Work, Finance, Social).

  4. 04

    Create a Panic Backup

    Generate your encrypted Master QR recovery key. Store it physically — safe deposit box, sealed envelope, split between trusted parties. This is your lifeline if the device is lost.

WiFi Companion setup. Open the Companion panel in x2y Authenticator, then visit the displayed local URL from any browser on the same network. Codes stream over an encrypted LAN connection — no internet, no cloud, no third party involved.

Downloads

Get x2y Authenticator v1.2.0

Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your downloaded APK before enabling installation.

Release history

Four releases, every one documented

The current build is v1.2.0. Every earlier version keeps its published notes — switch to v1.0.0 and the original notes open exactly as they shipped in March 2026.

v1.2.0LATEST

The Trust Update. Reliable biometric unlock, segmented Master QR restore for large vaults, PBKDF2-HMAC-SHA256 backup key derivation with 100,000 iterations, FLAG_SECURE screenshot protection across the app lifecycle, optional local security reminders and .x2y restore validation. No new packages. Read the v1.2.0 release notes.

v1.1.02026

The Powerhouse Update. HOTP accounts, native Steam Guard, migration from Google Authenticator, Aegis and andOTP, 30-day trash recovery, favorites and pins, batch operations, Vault Insights, wrong-PIN lockdown and Companion history controls. v1.1.0 release notes.

v1.0.52026

Security & Usability Release. Security Center, Backup v2 with SHA-256 integrity checksums, salted SHA-256 PIN storage, auto-lock, clipboard protection, Companion sessions, the Material 3 vault redesign, diagnostics and brand recognition. v1.0.5 release notes.

v1.0.0MAR 2026

Initial release. Offline TOTP vault with PIN and biometric authentication. Stealth Mode with duress PIN and decoy vault. Encrypted Panic Backup via Master QR and .x2y file. Smart Folders (Work, Finance, Social). WiFi Companion for LAN-only code streaming to PC browsers. NTP time sync (optional, timestamp only). Zero network permissions for core operation. v1.0.0 release notes.

Security model

Your secrets exist in exactly one place: your device

Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Cloud sync: none — by design. Secret storage: Android Keystore (hardware-backed where available). Network permissions: none required for core operation. Backup: encrypted locally, never transmitted. Licence: free.

x2y Authenticator was designed around a single threat model: your secrets are safest when they exist in exactly one physical location that you control. There is no cloud copy to breach, no sync server to subpoena, no analytics pipeline to leak through. The WiFi Companion is the only feature that uses the network, and it operates exclusively within your local area network with end-to-end encryption — no packets leave your router.

Security manifest
Telemetry0 bytes collected
AccountNone required — ever
Cloud syncNone — by design
Secret storageAndroid Keystore (hardware-backed)
Network permsNone for core operation
WiFi CompanionLAN-only, end-to-end encrypted
BackupEncrypted locally, never transmitted
Duress protectionStealth Mode with decoy vault

Design notes

Why an offline authenticator is a different security property

The secret never has to leave the device

x2y Authenticator implements time-based one-time passwords exactly as RFC 6238 defines them: a shared secret plus the current clock, hashed into a six-digit code. That computation needs no network, and adding one would only create an attack surface and a business decision about where your codes live.

So there is no sync service, no recovery mailbox, no vendor database. If an authenticator app offers cloud backup, the honest question is not whether it encrypts the backup but who holds the key and what legal process can reach it. Here the answer is nobody but you.

Sealed by the platform, not by a password

Vault secrets are encrypted at rest using the Android Keystore, and unlock is gated by your PIN or fingerprint through the same hardware-backed path. The app asks for no permissions beyond local storage for the encrypted vault, and none at all for the core operation of producing codes.

A passphrase-only vault is vulnerable while the device is unlocked; a Keystore-backed vault is not readable by another app on the same phone. That distinction is the whole reason this is a native Android app rather than a cross-platform wrapper.

Stealth Mode and the duress scenario

A duress PIN opens a decoy vault containing accounts you chose to expose. It is a real mitigation for a specific, unlucky situation — being forced to unlock your phone — and it is deliberately described as a mitigation, not a guarantee. An attacker who can compel you to give the real PIN still wins; Stealth Mode only removes the free look.

We would rather under-promise here than sell you a magic button. The behaviour, the decoy setup and its limits are documented in the product reference.

Panic Backup that you physically control

Backups are encrypted and exported as a Master QR or a .x2y file. You decide whether that ends up in a safe, a bank deposit box or an encrypted drive. Losing the phone is survivable; losing both the phone and the backup is not — that is the cost of refusing to hold your recovery in our servers, and we think it is the right trade.

WiFi Companion without a relay

Typing six digits on a phone while a desktop login times out is the classic friction point. WiFi Companion streams the current code to a browser on the same local network over an encrypted LAN connection — no relay, no vendor server, and it can be switched off entirely.

Similarly, optional NTP time sync requests a timestamp only, so codes stay accurate after a long flight; disable it and your clock drift is your own business.

How it works

From APK to first code in four moves

01

Install and unlock

Sideload the signed APK from Uptodown or APKPure. Set a PIN and enrol your fingerprint, which arms the Keystore-backed vault.

02

Import an account

Scan the service's standard otpauth:// QR code, or type the secret manually when a QR is unavailable — which is exactly how it should be, since the secret is then never photographed.

03

Generate offline

Codes compute on-device against the local clock. Airplane mode, a dead SIM and a locked-down network all change nothing.

04

Back up deliberately

Create an encrypted Panic Backup, print or store the Master QR, and test a restore on a second device before you ever need it.

Technical summary
Time-step30-second TOTP windows per RFC 6238
Secret storageAndroid Keystore, encrypted at rest
UnlockPIN or fingerprint (biometric via Keystore)
Duress pathStealth Mode opens a decoy vault
BackupEncrypted Master QR or .x2y file
OrganisingWork, Finance, Social plus custom folders
Test the recovery before you need it. Restore your backup onto a second device or a spare phone once. The one unrecoverable failure mode for any offline 2FA app is an encrypted backup nobody has ever successfully opened.

Who it is for

People who treat a second factor as a secret, not a convenience

Six patterns where on-device TOTP is the correct architecture.

High-value personal accounts

Email, banking and domain registrars, where the attacker's realistic path is a breached cloud backup — a thing this app cannot be part of.

Journalists and researchers

Sources and accounts where a vendor-held vault is an attractive subpoena target. The vault lives on your device and nowhere else.

Freelancers handling client systems

Separate Work, Finance and Social folders keep client credentials organised and easy to remove from at handover time.

Anyone in a coercive environment

Stealth Mode with a duress PIN and decoy accounts, so a forced unlock reveals only what you intended to show.

Travel and border crossings

No account to disable remotely, no sync to suspend, and codes that keep working on a phone with the SIM removed.

Desktop logins from a laptop

WiFi Companion streams the current code to a browser on your LAN, so you are not squinting at a phone across a meeting table.

Prerequisites

What you need before you enrol your first account

x2y Authenticator prerequisites
RequirementMinimumRecommended
DeviceAndroid phone or tabletA second Android device, so you can rehearse a restore
InstallationAllow installation from an unknown source for the sideload, then turn it back offPrefer the signed GitHub release over a mirror
HardwarePIN-capable deviceFingerprint or face unlock backed by the Android Keystore
ClockReasonably accurate system timeEnable optional NTP sync if the device drifts, then disable it again
NetworkNone for code generationA local network only if you choose WiFi Companion
PermissionsLocal storage for the encrypted vaultGrant nothing else — the core flow needs no network permission
BackupAn offline place for the Master QR or .x2y filePrint the QR and keep it physically separate from the phone
Sideload deliberately. Verify the APK's SHA-256 checksum against the value on the GitHub release page before installing. If you would rather not manage signatures yourself, treat the backup — not the install channel — as the thing you must get right.

Context

Offline vault versus cloud-synced authenticator

Both are usable. They fail in different ways, and you should pick knowingly.

Comparison of on-device, cloud-synced and SMS second factors
Propertyx2y AuthenticatorSynced authenticator appSMS or app-push codes
Where secrets liveYour device, Keystore-encryptedVendor cloud, encrypted to a key the vendor's process can reachThe carrier or the sending service
Server-side breach impactNothing to breachDepends entirely on the providerSIM-swap risk sits with the carrier
RecoveryYou hold the only backupProvider account recovery flowCarrier or service support desk
Offline behaviourWorks with the radio offUsually cached, sync-dependentNeeds network or roaming
Duress protectionDecoy vault behind a duress PINNot offeredNone
CostFree, no accountFree or subscriptionFree to you, weak as a factor

Questions

The queries that decide whether to switch

No, and that is intentional. Cloud backup means a third party — and therefore any legal process aimed at that third party — sits between you and your second factor. Instead you get an encrypted export as a Master QR or a .x2y file, which you store the way you would store a hardware key.
You restore from your encrypted backup onto a replacement device using the Master QR or the .x2y file. If that backup is gone too, the services themselves must fall back to their own recovery codes, so keep those when you enrol anywhere. This is the price of a vault we cannot open for you.
Not entirely — nothing is, on an unlocked device. That is why unlock is gated by PIN or fingerprint through the Android Keystore, why the vault is encrypted at rest, and why accounts you consider critical belong in a folder you keep closed rather than on the launcher.
Yes. TOTP is arithmetic on a shared secret and the local clock, so airplane mode changes nothing. The only feature that needs a network is WiFi Companion, which is opt-in and LAN-only.
Because the security model relies on the Android Keystore for hardware-backed secret storage and biometric gating, and we did not want to ship an iOS version that quietly weakens that guarantee. The Android app is the product; we would rather stay honest than be everywhere.
The vault lives exclusively on the Android device. There is no Windows vault; the desktop path is WiFi Companion, which streams the current code to a browser over your local network. The documentation FAQ states this explicitly.
There is no PIN recovery, for the same reason there is no cloud backup. Re-enrol each service with its own recovery path and restore future access from your encrypted backup. Treat the PIN as part of the key material, not as a login convenience.
Add the account manually. Every standards-compliant service shows the base32 secret when you enrol; pasting it into the app is equivalent to scanning the QR, and it avoids photographing a secret.

Documentation

Guides, the APK and the safety checklist

Two rules before you rely on it. First, move one low-stakes account, restore it onto a second device, and only then migrate your email and bank. Second, keep every service's own recovery codes offline — an offline vault and a service's recovery path must not live in the same drawer.

Ready to go offline

Download x2y Authenticator — your secrets, your device, forever

No cloud. No sync. No account. Just a vault that answers to you alone — with Stealth Mode for when the stakes are highest.

Summary
Versionv1.2.0
PlatformAndroid
PriceFree
Telemetry0 bytes