Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Release notes · Archive

x2y Authenticator v1.0.5 release notes

v1.0.5

The Security & Usability Release: Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign and diagnostics.

V1.0.5SUPERSEDED BY V1.2.0ARCHIVED NOTESFREE

Free — no account, no cloud sync, no telemetry. These notes are kept exactly as published for the v1.0.5 build.

At a glance

  • Versionv1.0.5
  • ReleaseSecurity & Usability
  • Backup formatBackup v2
  • PIN storageSalted SHA-256
  • Brand registry90+ services
  • Telemetry0 bytes

Superseded by v1.2.0. Every earlier release note remains published and indexable.

Release overview

Every x2y Authenticator release

You are reading the archived v1.0.5 notes. Select another version to read its notes.

x2y Authenticator release overview
v1.2.0The Trust Update. Reliability, security fixes, backup protection, Master QR restore, screenshot protection, and local reminders.
v1.1.0The Powerhouse Update. HOTP, Steam Guard, migration tools, trash, favorites, insights, biometric improvements, and Companion history.
v1.0.5 YOU ARE HERESecurity & Usability Release. Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign, and diagnostics.
v1.0.0Initial Release. Offline TOTP vault, Stealth Mode, encrypted backups, LAN Companion, folders, and NTP synchronization.

v1.0.5

Security & Usability Release

Release focus: align the daily user experience with the application's security model.

Security Center

A centralized security audit was added covering offline vault storage, biometric protection, cloud-sync status, account requirement, backup encryption, backup verification, screenshot protection, clipboard clearing, auto-lock, Stealth Mode configuration and telemetry status. Each condition includes a status, an explanation and a relevant settings shortcut.

Backup v2

Backup envelopes now include a creation timestamp, account count and a SHA-256 integrity checksum. Restore previews include account count, folder count, creation date and format version. Test restore without writing data, merge restore, replace restore, legacy v1.0.0 restore support and timestamped backup filenames such as x2y_vault_YYYYMMDD.x2y were added.

PIN storage

PINs are stored using salted SHA-256 hashes. Existing legacy unsalted hashes remain compatible and are upgraded after a successful unlock.

Auto-lock

Configurable automatic locking was added: immediately, 30 seconds, 1 minute, 5 minutes, 15 minutes or never, plus lock when leaving the foreground and a manual “Lock Now” action.

Clipboard protection

Copied authentication codes can automatically clear after 15 seconds, 30 seconds, 60 seconds or never. A generation guard prevents an older clipboard-clear operation from removing a newer copied value.

Screenshot protection

Screenshot protection became an explicit setting. FLAG_SECURE is enabled by default, applied from the first frame and configurable through Settings.

Biometric settings

Biometric authentication is controlled through an explicit, revocable setting, and the biometric unlock option is hidden when device biometrics are unavailable.

WiFi Companion

Six-character pairing codes, session tokens, per-device revocation, a disconnect-all control, a configurable session timeout, connection history, device identification and client IP reporting were added. Supported session timeouts are 5, 15, 30 and 60 minutes, and locking the vault immediately stops the LAN Companion server.

Privacy and diagnostics

Network policy matrix
Core vaultBlocked
AnalyticsNone
Crash reportingNone
Cloud syncNone
TelemetryNone
CompanionLAN-only
NTPOptional

Android permission explanations and exportable diagnostic reports were also added. Diagnostics are secret-free, key-free and account-name-free.

NTP status

Time synchronization now reports the synchronization result, the measured clock offset and the offset in milliseconds.

Vault redesign

A complete Material 3 vault interface was introduced. Search covers issuer, account and folder; sorting covers A–Z, recently used, recently added and expiring soon; organization adds folder filters, folder suggestions and brand-based organization.

  • Account cards with brand avatars, grouped authentication codes, circular countdown timers, one-tap copy and clipboard-clear confirmation
  • Long-press actions: edit, change folder, copy code, reveal secret, export and delete
  • Account editing for issuer, account, secret, folder, color and advanced parameters
  • Secret masking, secret reveal warnings, explicit deletion confirmation and single-account otpauth:// export
  • Empty-state onboarding, recently-used tracking and duplicate detection

TOTP and QR import

Support was added for RFC 6238 configurations: SHA-1, SHA-256 and SHA-512, 6-digit and 8-digit codes and 10–120 second periods. Strict otpauth:// parsing, friendly parser errors, Base32 validation and normalization, URI export, 3+3 and 4+4 code formatting, QR import confirmation and invalid-code handling were added. Scanner improvements cover torch control, camera switching, single-shot detection and a framing overlay.

Brand recognition

A registry containing 90+ recognized services was added. Brand recognition can provide an application icon, brand color, suggested folder and canonical service name, while unknown issuers receive a safe fallback presentation.

PC Companion dashboard

The PC dashboard was redesigned with the x2y visual identity, inline SVG branding, live search, circular countdowns, session-expiry handling, click-to-copy codes and cache-prevention headers.

Stealth Mode

A guided three-step setup was added: real PIN, stealth PIN and decoy preparation. It includes REAL VAULT and DECOY VAULT indicators, optional decoy-account seeding, sample accounts, PIN management and real-vault biometric resolution.

Settings and documentation

Settings are organized into Security Center, Appearance, Security, Recovery, Companion, Guide and About. An in-app About page, in-app changelog, How-It-Works cards and NTP status information were added.

Engineering

Major internal improvements include database schema v2, non-destructive database migration and rewrites of the backup, OTP, brand, security and biometric services, plus new clipboard, screen-security, companion, companion web and diagnostics services. Dedicated test suites were added for OTP, backups, brands and account models, alongside a native FLAG_SECURE method channel, cross-platform theme portability, an audited icon system and README/CHANGELOG documentation. No new third-party dependencies were introduced.

Compatibility

What v1.0.5 restores

Backup format support is cumulative. The table below is what the current build restores; older release notes describe how each format was introduced.

v1.0.5 compatibility
Backup v2Introduced in v1.0.5 with timestamp, account count and SHA-256 integrity checksum
Legacy v1.0.0 backupRestore supported
Legacy iv:ciphertext backupRestore supported
PIN hashesLegacy unsalted hashes upgraded after a successful unlock
Segmented Master QRNot available in v1.0.5 — added in v1.2.0

Downloads

Install the current build (v1.2.0)

v1.0.5 has been superseded. Keep these notes for reference, and install the latest signed APK for current fixes.

Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your downloaded APK before enabling installation.

Security notice

How to read these release notes

x2y Authenticator is designed for local-first, offline operation. Authentication secrets are not stored in a remote cloud service as part of normal vault operation. Users should maintain a secure physical copy of their recovery material. Stealth Mode and encrypted backups are security mitigations, not guarantees, and no authenticator can completely protect secrets on a fully compromised device.