# Stratum: a GPL-3.0 two-factor authenticator for Android and Wear OS

> Stratum is a free, offline Android authenticator that supports TOTP, HOTP, mOTP, Steam and Yandex codes, with encrypted backups and a Wear OS companion. It is a good fit if you want a local-only vault and are willing to use the IzzyOnDroid repository.

**stratumauth/app** — 📱 Two-Factor Authentication (2FA) client for Android + Wear OS

- Repository: https://github.com/stratumauth/app
- Website: https://stratumauth.com
- Stars: 4,601 · Forks: 280
- Language: C#
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/stratumauth-app

## What Stratum is for, and who it is not for

Stratum is an Android two-factor authentication client. You add an account, usually by scanning a QR code with the camera, and the app generates the one-time codes that services ask for at login. The README describes it as a free open-source two factor authentication app for Android with encrypted backups, icons, categories and a high level of customisation, plus a Wear OS companion app.

The project targets people who keep their second factor on a phone and want that vault to stay local. The README states that Stratum requires a single permission and does not require Internet access to function. That single permission is the camera, used to add accounts through QR codes. Everything else, including backup, is described as saving to cloud storage or to the device, which means the app itself is not the thing talking to a server.

It is the wrong tool for a few common situations. There is no iOS client in the repository layout, so an iPhone user has nothing to install. There is no browser extension, so a desktop-only workflow gains nothing. And if your organisation requires a shared or centrally administered vault, Stratum has no server component to manage.

The project is written in C#. The solution file Stratum.sln sits alongside Stratum.Core, Stratum.Droid, Stratum.Droid.Shared, Stratum.WearOS and Stratum.Test. That split is worth knowing before you file a bug: a code-generation problem probably lives in Stratum.Core, while anything about the phone UI or the watch app lives in the two Android projects.

## How code generation and storage work in Stratum

The README lists the algorithm surface directly: TOTP (Time Based) and HOTP (Counter Based) authenticators using either SHA1, SHA256 or SHA512 hashing algorithms, and Mobile-Otp (mOTP), Steam and Yandex as additional types. That is a wider set than the plain TOTP-only clients that dominate the category, and the Steam and Yandex entries exist because those services deviate from the RFC 6238 defaults.

The separation between Stratum.Core and the Android projects is the architectural point. Code generation, the account model and the backup serialisation live in a shared core library, and the phone app and the Wear OS app both sit on top of it. The practical consequence is that the watch app is a companion, not an independent vault: the README says plainly that a connection to your Android device is required. Your watch is a display for codes that the phone holds, not a second copy of the secrets.

Backups are the part with the most documentation behind them. The README links a dedicated file, doc/BACKUP_FORMAT.md, which describes the layout of the export. The README describes the feature as backing up your authenticators with strong encryption, and notes you can save to cloud storage or to your device. Because the app has no network access, saving to cloud storage means handing the encrypted file to whatever sync client you already run, not to a Stratum service.

One thing the README does not document is rollback. There is no stated procedure for restoring an older backup over a newer vault, or for downgrading between releases. If you plan to move accounts between devices, treat the backup file as the migration path and test the restore before you need it.

## Installing Stratum and adding your first account

The README gives two download routes: Google Play and F-Droid. The F-Droid route comes with a caveat stated in the README itself: Stratum is currently only available on the F-Droid client through the IzzyOnDroid repo, and you must first add that repository in the F-Droid client. In other words, searching the default F-Droid index will not find it.

If you install the APK directly rather than through a store, the README asks you to verify the certificate signature with apksigner before trusting the file. It publishes three digests to compare against:

```
SHA-256 digest: b975b325e4f39465df1034d6bc2c11a3926f60cc07b820c51fbe1c757555f28a
SHA-1 digest: b6a100cefaf7f4bc7d0879d71ad36c555a8b850e
MD5 digest: bb884532b0ee1b3f04dd9917409d5126
```

A mismatch means the file is not the build the project published, and you should stop there.

Building from source is the other option, and the repository layout gives you the entry point. The solution is C#, so a .NET SDK and the Android workload are the prerequisites implied by Stratum.sln and the Stratum.Droid project. The README does not spell out the build steps beyond the repository contents, so treat the exact SDK version as something you determine from the project files rather than from the documentation.

Once the app is installed, adding an account is the camera flow: you grant the camera permission and scan the QR code your service shows during two-factor setup. The README also links import guides for Google Authenticator, Blizzard Authenticator, Steam and Authy, for the case where you are migrating an existing set of accounts rather than starting fresh.

## Where Stratum's design creates friction

The offline promise is also the constraint. Because Stratum does not request Internet access, it cannot push a code to your watch over a network or sync a vault between two phones. The README states the Wear OS limitation directly: a connection to your Android device is required. If your watch is away from your phone, the watch app has nothing to show.

Backup is manual by design. There is no account, no server and no automatic off-device copy. The README describes encrypted backups saved to cloud storage or to your device, which puts the responsibility for actually running that export on you. Lose the phone without a recent backup and the accounts are gone; the recovery codes from each service become your only way back in.

The permission model is narrow, and that is a trade-off rather than a defect. Camera is the only permission the README lists, so anything that would need more, such as reading an image from the gallery to extract a QR code, is not described as supported.

There is also a distribution cost. Because the project is not in the main F-Droid index, the README tells you to add the IzzyOnDroid repository first. That is an extra step for every user, and it means updates arrive through that repository's cadence rather than the default index.

Finally, the licence is GPL-3.0. If you fork Stratum and distribute the result, the README's disclaimer points you at the full GNU General Public License text for the terms. That matters for anyone embedding the code in a closed product, and it is a question for your own legal review rather than something the README answers.

## Stratum compared with Aegis Authenticator

Aegis is the comparison people actually search for, and the two projects occupy the same slot: a free, local, Android-only authenticator. The difference is in what the README of each emphasises, and in the codebase you would be maintaining.

Stratum's stated feature set centres on customisation and breadth of algorithm support: encrypted backups, icons, categories, dark mode, reordering, plus mOTP, Steam and Yandex alongside TOTP and HOTP. The README also calls out a Wear OS companion app, which is a first-class part of the repository rather than an add-on.

Aegis is a Java/Kotlin Android application with its own vault format, and it is distributed through the main F-Droid index as well as Google Play. That distribution difference is concrete: with Stratum you add the IzzyOnDroid repository first, as the README instructs, while Aegis needs no extra repository step.

For a developer choosing which to build on, the language matters more than the feature list. Stratum is C# with a shared core library that both the phone and watch apps consume, which is convenient if your team already writes .NET and wants to reuse the code-generation logic. Aegis is the more conventional Android stack, which is easier to hire for and to patch with standard Android tooling.

Neither is a cloud service, so the choice does not change your threat model much. What changes is the toolchain, the distribution channel, and whether you want a watch app that the upstream project maintains itself.

## Maintenance, releases and upgrade cost

The repository is not archived, and its last push was on 2026-09-22. The most recent release listed is v1.6.2 from 2026-05-08, preceded by v1.6.1 on 2026-03-24 and v1.6.0 on 2026-03-21. The gap between the last release and the last push suggests work continues on master between tagged versions, though the release notes themselves are not part of what the README shows.

Upgrade cost is low for users, because the app is a single Android package and there is no server to migrate. The cost that does exist is the backup format. The README links doc/BACKUP_FORMAT.md, which implies the export has a defined structure that could change between versions. If you maintain tooling that reads Stratum backups, that document is the contract you are tracking, and a format change is the upgrade that would actually break you.

For contributors, the Crowdin badge and crowdin.yml indicate translations are handled outside the repository, so string changes flow through Crowdin rather than pull requests against the source. The README also links a CONTRIBUTING.md and a dedicated icon-request issue template, which tells you the project expects icon additions to arrive as structured requests rather than free-form patches.

The GPL-3.0 licence is the other long-term cost. Redistributing a modified build carries source-disclosure obligations, and the README's disclaimer explicitly disclaims warranty. If you plan to ship Stratum inside another product, that is the constraint to resolve before writing code, not after.

## Conclusion

Adopt Stratum if you want an offline Android authenticator with encrypted backups and a Wear OS companion, and you are comfortable installing from the IzzyOnDroid repository or building the C# solution yourself. Do not adopt it if you need a browser extension, an iOS client, or a cloud-synced vault, none of which the repository provides. Before trusting it with your accounts, verify the APK signature against the three digests published in the README, and read doc/BACKUP_FORMAT.md so you know what your backup file contains.

## FAQ

### Is Stratum available on Google Play?

Yes. The README links a Google Play listing for com.stratumauth.app alongside the F-Droid option. The F-Droid route requires adding the IzzyOnDroid repository first, because the README states Stratum is only available through that repo in the F-Droid client.

### Does Stratum need an Internet connection to work?

No. The README states that Stratum requires a single permission and does not require Internet access to function. That single permission is the camera, used to add accounts through QR codes.

### Which authenticator algorithms does Stratum support?

The README lists TOTP (time based) and HOTP (counter based) with SHA1, SHA256 or SHA512 hashing, plus Mobile-Otp (mOTP), Steam and Yandex. That is broader than a plain TOTP-only client.

### Can I use the Stratum Wear OS app without my phone nearby?

No. The README states that a connection to your Android device is required for the Wear OS companion. The watch shows codes that the phone holds rather than keeping its own copy of the secrets.

### How do I verify a Stratum APK is genuine?

The README asks you to compare certificate signatures using apksigner against three published digests: a SHA-256, a SHA-1 and an MD5 value. A mismatch means the file is not the build the project published.

## Sources

- [License: GPL-3.0](https://github.com/stratumauth/app/blob/master/LICENSE)
- [Project website](https://stratumauth.com)
- [README](https://github.com/stratumauth/app/blob/master/README.md)
- [Releases](https://github.com/stratumauth/app/releases)
- [stratumauth/app on GitHub](https://github.com/stratumauth/app)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/stratumauth-app
