Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Release notes · Android

x2y Authenticator release notes

v1.2.0

The Trust Update: reliability, security fixes, backup protection, Master QR restore, screenshot protection and local reminders. Older versions keep their own notes.

LATEST RELEASEV1.2.03 PREVIOUS VERSIONSFREE

Free — no account, no cloud sync, no telemetry. Your authentication secrets stay on your device.

At a glance

  • Current versionv1.2.0
  • ReleaseThe Trust Update
  • PlatformAndroid · APK
  • New packagesNone added
  • Master QRSegmented parts
  • Telemetry0 bytes

Switch versions with the selector below — every earlier release note stays published and indexable.

Release overview

Every x2y Authenticator release

This page documents the current release, v1.2.0. Each earlier version keeps its own published notes, so nothing is withdrawn when a new build ships.

x2y Authenticator release overview
v1.2.0 YOU ARE HEREThe Trust Update. Reliability, security fixes, backup protection, Master QR restore, screenshot protection, and local reminders.
v1.1.0The Powerhouse Update. HOTP, Steam Guard, migration tools, trash, favorites, insights, biometric improvements, and Companion history.
v1.0.5Security & Usability Release. Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign, and diagnostics.
v1.0.0Initial Release. Offline TOTP vault, Stealth Mode, encrypted backups, LAN Companion, folders, and NTP synchronization.

Latest release · v1.2.0

The Trust Update

Release focus: make previously promised security features reliably usable on a real device.

No new packages were added in this release. Everything below is a reliability, correctness or protection change to code that already shipped, followed by two usability additions: optional local security reminders and a clearer unlock screen.

Biometric unlock

  • Fixed an issue where an internal prompt-state flag prevented the biometric plugin from displaying its authentication prompt.
  • The biometric service now manages prompt state and returns explicit results.
  • The login screen can distinguish between a dismissed prompt, a temporary biometric lockout, no enrolled biometrics and no device PIN configured.
Result: Biometric authentication is now reliable and failures are clearly explained.

Large Master QR restore

Large vaults can now be exported as numbered Master QR parts of approximately 700 characters each. Restore supports:

  • Parts scanned in any order
  • Duplicate parts
  • Live progress
  • Checksum validation
  • Invalid or incorrect parts

Small vaults continue to use a single QR code, and the previous single-code Master QR format remains compatible.

Result: Large vaults can be transferred between nearby devices without cloud storage, accounts or cables.

Backup protection

New backups derive the AES-256 encryption key using PBKDF2-HMAC-SHA256, 100,000 iterations and a random 16-byte salt, with a fresh random IV per backup. Existing v2 and v1.0.0 backup packages remain compatible.

Result: Offline password guessing against a stolen backup becomes more expensive.

Screenshot protection

Android FLAG_SECURE is maintained throughout the application lifecycle and re-applied after resume where necessary. Protection covers screenshots, screen recording and recent-app thumbnails.

Result: Vault contents are protected from standard Android screen-capture paths.

Randomized local reminders

Optional local security reminders were added, including three reminder frequencies, quiet hours from 22:00 to 08:00, first-unlock opt-in, settings controls, a Security Center status line and a test notification. No push service, server or additional dependency is required.

Result: Users can receive reminders without introducing a remote notification system.

Unlock screen

The PIN screen was simplified with a compact masked input, PIN progress indicators, reduced instructional text and less visual distraction.

.x2y restore validation

The application now inspects a selected .x2y file before attempting decryption. Selecting an unrelated or invalid file produces a clear validation message instead of a generic decryption error. The About screen was also updated to remove an incorrect third-party licence reference.

Compatibility

What v1.2.0 restores

Backup format support is cumulative. The table below is what the current build restores; older release notes describe how each format was introduced.

v1.2.0 compatibility
New packagesNone added in v1.2.0
v2 backupsContinue to restore
v1.0.0 backupsContinue to restore
Single-code Master QRContinue to restore
Segmented Master QRNew in v1.2.0 — large vaults export numbered parts of roughly 700 characters
PIN storageSalted SHA-256, with legacy unsalted hashes upgraded after a successful unlock

Downloads

Get x2y Authenticator v1.2.0

These notes describe the current release. The download always serves the latest signed build.

Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your downloaded APK before enabling installation.

Security notice

How to read these release notes

x2y Authenticator is designed for local-first, offline operation. Authentication secrets are not stored in a remote cloud service as part of normal vault operation. Users should maintain a secure physical copy of their recovery material. Stealth Mode and encrypted backups are security mitigations, not guarantees, and no authenticator can completely protect secrets on a fully compromised device.