Free, open-source 2FA for iPhone. Your secrets stay on your device — no account, no cloud, no tracking. Ever.
Keya Authenticator generates TOTP and HOTP codes for any service that supports standard two-factor authentication.
All secrets are stored in the iOS Keychain with the strongest protection class — locked to your device and unavailable when the screen is locked.
Unlock your tokens instantly with biometrics. A 6-digit PIN fallback is always available, with automatic lockout after repeated wrong attempts.
Add any account in seconds by scanning a standard otpauth:// QR code. Works with Google, GitHub, Dropbox, Amazon, Microsoft, and hundreds more.
Import from Google Authenticator, Aegis, 2FAS, and Raivo. Export as QR codes, plaintext, or AES-256-GCM encrypted backup files.
Star your most-used accounts so they float to the top. Drag to rearrange the rest — your order is remembered across launches.
Before the current code expires, the next one appears early — so you never have to race the countdown timer.
Available in English, French, Japanese, Korean, Brazilian Portuguese, and Latin American Spanish.
Fill one-time codes directly from the iOS keyboard in Safari and any other app — no need to switch away from what you're doing. Enable in Settings → Passwords.
Tap any otpauth:// link in Mail, Safari, or another app and Keya Authenticator opens with the Add Token form pre-filled — ready to save in one tap.
Keya Authenticator was designed from the ground up to collect nothing. There is no server, no account, and no analytics SDK.
No advertising network, no targeting, no third-party SDKs.
The app has no network entitlements. It cannot connect to the internet.
Your secrets never leave your device. No iCloud sync, no backup to any server.
Zero tracking. No crash reporters, no usage analytics, no telemetry.