Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Release notes · Archive

x2y Authenticator v1.1.0 release notes

v1.1.0

The Powerhouse Update: HOTP, Steam Guard, migration tools, trash, favorites, insights, biometric improvements and Companion history.

V1.1.0SUPERSEDED BY V1.2.0ARCHIVED NOTESFREE

Free — no account, no cloud sync, no telemetry. These notes are kept exactly as published for the v1.1.0 build.

At a glance

  • Versionv1.1.0
  • ReleaseThe Powerhouse Update
  • New standardsHOTP · Steam Guard
  • MigrationsGoogle · Aegis · andOTP
  • Trash retention30 days
  • Telemetry0 bytes

Superseded by v1.2.0. Published release notes are never rewritten — switching versions is one click.

Release overview

Every x2y Authenticator release

You are reading the archived v1.1.0 notes. Select another version to read its notes.

x2y Authenticator release overview
v1.2.0The Trust Update. Reliability, security fixes, backup protection, Master QR restore, screenshot protection, and local reminders.
v1.1.0 YOU ARE HEREThe Powerhouse Update. HOTP, Steam Guard, migration tools, trash, favorites, insights, biometric improvements, and Companion history.
v1.0.5Security & Usability Release. Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign, and diagnostics.
v1.0.0Initial Release. Offline TOTP vault, Stealth Mode, encrypted backups, LAN Companion, folders, and NTP synchronization.

v1.1.0

The Powerhouse Update

Release focus: expand supported authentication standards, improve migration, and provide stronger vault-management tools.

Biometric authentication

  • Prevented repeated biometric prompt triggering.
  • Dismissed prompts require a deliberate retry.
  • Disabling biometrics requires the vault PIN.
  • Enabling biometrics performs live verification.
  • Optional device-PIN fallback is supported.
  • Added a test authentication prompt.

Direct .x2y file opening

.x2y backup files can now be opened directly from compatible file managers. The supported flow is file manager → x2y Authenticator → backup password → verified preview → restore. Both cold-start and warm hand-off flows are supported.

HOTP support

Counter-based HOTP accounts were added with live code preview, counter management, ±50 counter resynchronization, otpauth://hotp import and otpauth://hotp export.

Steam Guard support

Native Valve Steam Guard support was added for Base64 shared secrets, with steam:// import and steam:// export.

Migration tools

Migration support was added for Google Authenticator export QR, Aegis JSON and andOTP JSON. Migration includes account selection, duplicate detection, account-level import control and hand-decoded Google Authenticator protobuf support. No additional dependency was required for the protobuf decoder.

Trash and recovery

Deleted accounts are retained for 30 days, with account recovery, batch deletion and undo after deletion.

Favorites and pins

Favorite accounts, pinned accounts, favorite filtering and priority placement for pinned accounts were added.

Batch operations

Long-press selection supports bulk favorite, pin, move and delete.

Vault Insights

On-device vault analysis was added, including a vault hygiene score, weak-key detection, key-reuse detection, an unused-account audit and a parameter inventory. Analysis remains on the device.

Wrong-PIN lockdown

Repeated incorrect PIN attempts now trigger escalating cooldowns from 30 seconds up to 15 minutes. Cooldown state persists across application restarts and the login screen displays the remaining cooldown.

Companion history

Individual event deletion, complete history clearing and a persistent history-cleared marker were added. The marker ensures the visible history remains explicit about being cleared.

Branding

Official x2y artwork is now used consistently across the login screen, application bar, Companion screens and the PC dashboard.

Compatibility

What v1.1.0 restores

Backup format support is cumulative. The table below is what the current build restores; older release notes describe how each format was introduced.

v1.1.0 compatibility
v2 backupsContinue to restore
v1.0.0 backupsContinue to restore
Single-code Master QRContinue to restore
Segmented Master QRNot available in v1.1.0 — added in v1.2.0
Third-party dependenciesNo additional dependency was required for the protobuf decoder

Downloads

Install the current build (v1.2.0)

v1.1.0 has been superseded. Keep these notes for reference, and install the latest signed APK for current fixes.

Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your downloaded APK before enabling installation.

Security notice

How to read these release notes

x2y Authenticator is designed for local-first, offline operation. Authentication secrets are not stored in a remote cloud service as part of normal vault operation. Users should maintain a secure physical copy of their recovery material. Stealth Mode and encrypted backups are security mitigations, not guarantees, and no authenticator can completely protect secrets on a fully compromised device.