Aegis Authenticator: an encrypted, backup-friendly 2FA vault for Android
A free, secure and open source app for Android to manage your 2-step verification tokens.
At a glance
- What is it?
- Aegis Authenticator is a GPL-3.0 Android app that stores HOTP and TOTP tokens in an AES-256-GCM encrypted vault and can import from a dozen other authenticator apps. It is a good fit for Android users who want offline backups and a second unlock factor; it is not a cross-platform or desktop tool.
- Who is it for?
- Adopt Aegis if you are on Android and want your 2FA tokens in a vault you can export and back up yourself, especially if you are migrating away from Authy or Google Authenticator and need an import path. Do not adopt it if you need a desktop client, an iOS app, or a browser extension, because the README describes an Android app only.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 24 days ago.
- What is it written in?
- Mainly Java, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The gap Aegis Authenticator fills for Android 2FA
Most authenticator apps treat the token list as something you cannot see or move. Aegis Authenticator takes the opposite position. The README describes it as a free, secure and open source 2FA app for Android that aims to provide a secure authenticator while also including features missing in existing apps, specifically proper encryption and backups. That sentence is the whole pitch, and it is a narrow one: this is not a general identity platform, it is a vault for one-time passwords.
The audience is Android users who already accept TOTP or HOTP as their second factor but who are uncomfortable that their tokens live inside a closed app with no export. Aegis supports both HOTP and TOTP, so it works with the same services as most other authenticators. The practical difference is that the vault is something you own and can move. Entries can be exported as plaintext or as an encrypted file, and the app can write automatic backups of the vault to a location you choose. If your phone is lost, that backup is the recovery path.
It is also a migration tool. The README lists import from 2FAS Authenticator, Authenticator Plus, Authy, andOTP, FreeOTP, FreeOTP+, Google Authenticator, Microsoft Authenticator, Plain text, Steam, TOTP Authenticator and WinAuth, with a note that root access is required for some of these. If you have tokens stranded in Authy, that list is the reason to look here.
How the encrypted vault and unlock flow work
The README states the vault is encrypted with AES-256-GCM and can be unlocked in two ways: with a password, using scrypt, or with biometrics backed by the Android Keystore. Those are two different trust models sharing one vault. The password path derives a key from something you know, with scrypt as the key derivation function. The biometric path delegates the unlock to hardware-backed key material on the device. The README does not describe what happens if you enable biometrics and then enroll a new fingerprint, or whether the password remains a fallback. The design document at docs/vault.md is where that is meant to be answered.
Around the vault there are smaller defences. Screen capture prevention stops other apps and the system from taking screenshots of your codes, and tap to reveal controls when a code is displayed. Neither stops an attacker who already controls the unlocked device, and the README does not claim otherwise.
Organization is handled locally: alphabetic or custom sorting, groups, search by name or issuer, custom or automatically generated icons, and advanced entry editing. Icon packs are a separate mechanism. Aegis supports third-party icon packs, and the README points to docs/iconpacks.md for how to build one, with aegis-icons, delta-aegis-icons, aegis-simple-icons and aegis-simple-icons-outlined as community examples. The README notes there are no official icon packs. The two simple-icons packs are described as automatically generated, and the README warns that not all of those icons are as high quality as the ones in aegis-icons.
Installing Aegis Authenticator and importing your first tokens
The README does not give build-from-source instructions. It says Aegis is available on the Google Play Store and on F-Droid, and links both. Install it from one of those two stores.
If you download an APK rather than installing from a store, the README describes a verification step. It states that APK releases on Google Play and GitHub are signed using the same key, and that they can be verified with apksigner:
apksigner verify --print-certs --verbose aegis.apkThe README says the output should look like this, with both signature schemes verified:
Verifies
Verified using v1 scheme (JAR signing): true
Verified using v2 scheme (APK Signature Scheme v2): trueThe certificate fingerprints in the output should match the ones the README lists. The SHA-256 fingerprint it publishes is C6:DB:80:A8:E1:4E:52:30:C1:DE:84:15:EF:82:0D:13:DC:90:1D:8F:E3:3C:F3:AC:B5:7B:68:62:D8:58:A8:23, under the owner CN=Beem Development. Compare the full fingerprint, not the first few bytes.
After install, the first real task is getting your existing tokens in. The README lists the import sources, including Google Authenticator, Authy, andOTP, FreeOTP, Microsoft Authenticator and Steam, and notes that root access is required for some of them. The other route is adding entries one at a time: scan a QR code, scan an image of a QR code, or enter the details manually. Once entries exist, open the export or backup settings and write an encrypted export to a location you control. That file, not the phone, is your recovery plan.
What Aegis Authenticator does not do
The README describes an Android app and nothing else. There is no desktop client, no iOS version, no browser extension and no command-line tool mentioned anywhere. If your workflow assumes you can read a code from a laptop, Aegis is the wrong tool, and no amount of configuration changes that.
The import list is also a reminder of a boundary. Some importers need root access, which means a stock, unrooted phone cannot pull tokens out of every app on that list. The README does not say which ones require root, so you have to check before assuming a clean migration.
Screen capture prevention and tap to reveal are protections against casual exposure, not against a compromised device. The README does not describe any protection against a malicious app with accessibility permissions, and it does not describe a remote wipe or a server-side component, because there is no server. Everything depends on the vault file and the backup you made.
Finally, Aegis is a TOTP and HOTP client. The README names those two algorithms and no others. Services that have moved to push-based approval or hardware security keys are outside its scope.
Aegis Authenticator compared with andOTP
andOTP is the closest comparison, and it is not a hypothetical one: it appears in Aegis's own import list, which means Aegis treats it as a source of users rather than only as a rival. Both are Android authenticator apps with encrypted vaults and both handle TOTP and HOTP. The difference is in what the README emphasizes. Aegis leads with the vault design, documents the format in docs/vault.md, and publishes APK signing certificates so a downloaded build can be checked. It also supports third-party icon packs through a documented format, with several community packs listed.
If you are already on andOTP and it works, the README gives no reason to move beyond the import path. If you are choosing fresh, the deciding question is whether the vault documentation and the published signing certificate matter to you. They are the parts of Aegis that a reader can verify independently, and that is a reasonable thing to weight.
Maintenance, licensing and upgrade cost
The repository is not archived, and the last push was on 2026-09-06, the same day as the v3.4.3 release. Before that, v3.4.2 landed on 2026-02-24 and v3.4.1 on 2025-08-03. That is a release cadence measured in months, not weeks, which is normal for an app whose protocol surface (RFC 4226 and RFC 6238) is stable. The README also links a Crowdin project, so translations arrive on their own schedule.
Upgrade cost is low in the ordinary case: install the new version from the same store and the vault opens as before. The cost that matters is the one you pay if you forget the password and have no export. The README does not document a recovery mechanism for a forgotten vault password, and it does not document rollback to an older release. Treat the encrypted export as the thing that makes upgrades safe.
Aegis is licensed GPL-3.0. If you are an end user installing from Play or F-Droid, the licence mostly means the source is available and derivatives must stay under the same terms. If you plan to fork it, bundle it, or ship a modified build inside another product, read the LICENSE file in the repository and get proper advice; the README does not discuss redistribution.
Editorial conclusion
Adopt Aegis if you are on Android and want your 2FA tokens in a vault you can export and back up yourself, especially if you are migrating away from Authy or Google Authenticator and need an import path. Do not adopt it if you need a desktop client, an iOS app, or a browser extension, because the README describes an Android app only. Before trusting it with your accounts, verify the APK signature with apksigner against the certificate fingerprints published in the README, and read docs/vault.md to understand what the scrypt password and the Android Keystore biometric unlock actually protect.
Frequently asked questions
How do I set up Aegis Authenticator?
Install it from the Google Play Store or F-Droid, then add entries by scanning a QR code, scanning an image of one, or entering the details manually. You can also import from another authenticator app, though the README notes root access is required for some import sources.
How do I install Aegis Authenticator?
The README says Aegis is available on the Google Play Store and on F-Droid, and links both stores. It does not provide build-from-source instructions.
How do I use Aegis Authenticator?
Add your services as entries, either by scanning a QR code or entering the details manually, and the app generates HOTP or TOTP codes for them. The README also describes groups, search by name or issuer, custom icons, and exporting the vault as plaintext or encrypted.
What is Aegis Authenticator?
It is a free, secure and open source 2-step verification app for Android, licensed GPL-3.0. It stores HOTP and TOTP tokens in an AES-256-GCM encrypted vault that can be unlocked with a password (scrypt) or biometrics via the Android Keystore.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/beemdevelopment-aegis)