v2.0 Pinning, Recently Deleted and SHA-256 are here

Two-factor codes that never leave your device.

Autheris is a privacy-first authenticator for iPhone. It generates the one-time passwords that protect your accounts and keeps the secrets behind them in the iOS Keychain — no account, no sign-up, no analytics, no ads.

  • Free, open source (MIT)
  • iOS 16 and later
  • Works entirely offline
Autheris on iPhone showing one-time codes for Google, Discord and GitHub
In the KeychainThis device only
Sync is opt-inEnd-to-end encrypted
  • 0 accountsNothing to sign up for
  • 0 trackersNo analytics, no ads
  • iOS KeychainWhere your secrets live
  • MIT licenceRead every line
Features

Everything an authenticator should do

Codes you can copy in one tap, a list that stays tidy, and the recovery paths you only notice when something goes wrong.

One-tap codes

Tap a code to copy it. Your clipboard is cleared automatically after 60 seconds so the code does not linger.

Pin and reorder

New in 2.0. Pin the codes you use most to the top and drag the rest into whatever order suits you. Pins sync, the manual order stays per device.

Recently Deleted

New in 2.0. A deleted code stays recoverable on your device for 7 days. Restore it, or remove it for good straight away.

QR and setup links

Add an account by scanning its QR code or by picking a screenshot from your photo library. Setup links paste straight in.

SHA-1, SHA-256, SHA-512

New in 2.0. Choose the algorithm per account for the services that need more than the default — the preview code updates live as you change it.

Import from another app

Bring accounts across from Google Authenticator, Aegis, andOTP and 2FAS, or from an Autheris backup.

Setup key access

View, copy or edit a token’s secret when you need to move it somewhere else. It stays masked until you tap to reveal it.

Countdown ring

A clear ring shows how long each code has left, and the colour is yours to set per account.

Search and issuer icons

Find any account instantly however long the list gets, with familiar brand marks so you can spot it at a glance.

Release notes

What’s new in 2.0

A big update to the parts you touch every day, plus a quieter app underneath: tokens, settings and pending deletions moved into the Keychain, so they survive reinstalling the app.

Autheris 2.0

Full changelog on GitHub

New

  • Pin and reorder. Pin the codes you use most to the top, and drag the rest into any order.
  • Recently Deleted. A deleted code is kept on your device for 7 days, so a wrong tap is recoverable.
  • Protected while recording. Codes are covered whenever your screen is being recorded or mirrored — alongside the existing app-switcher and background protection.
  • SHA-256 and SHA-512. Choose the algorithm when adding or editing a code. Some services need something other than the default.
  • Account name is now optional. Add a code without filling in an account.

Improved

  • Redesigned home screen. Add and Edit were rebuilt as native forms, and the code preview updates live as you change a setting.
  • Everything moved into the Keychain. Tokens, settings and pending deletions now survive reinstalling the app — and a deleted code can no longer reappear after a reinstall.
  • Hardening. Fixed a crash that a malformed setup link or backup file could trigger, and the home screen name now reads Autheris, matching the App Store.
How it works

Set up once, then forget about it

  1. Add your accounts

    Scan the QR code a service shows you, paste a setup link, or import an export from the authenticator you already use. Name the account — or leave it blank.

  2. Lock it down

    Turn on Face ID or Touch ID. Autheris locks when it opens and again 30 seconds after it goes to the background, and blurs its content in the app switcher.

  3. Copy codes in a tap

    Open the app, tap the code you need, and paste it. The clipboard clears itself after 60 seconds, and codes are covered while your screen is being recorded.

Security & privacy

Zero-knowledge by architecture, not by promise

There is no Autheris account and no Autheris server holding your tokens. Here is exactly where your data lives, what sync sends, and what the app cannot protect you from.

Secrets live in the iOS Keychain

Tokens are persisted as JSON in the Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly: other apps cannot read them, they do not travel with iCloud Keychain or an encrypted backup, and they are only readable while your device is unlocked.

A full compromise of your device — including a forensic extraction — should still be treated as a compromise of your tokens. Autheris is honest about that rather than pretending otherwise.

iCloud Sync is opt-in and encrypted

Sync is off by default and only ever uses the private CloudKit database tied to your own Apple ID. Labels, account names, secrets, ring colours and pin flags are written through CloudKit’s encrypted fields, so they are not readable by the developer or visible in the CloudKit dashboard.

Only non-secret metadata is stored as plain fields: timestamps, algorithm, digits, period, and a one-way fingerprint used to detect changes.

Unlock, blur, and recording protection

Face ID or Touch ID locks the app when it opens and again 30 seconds after it is backgrounded. Content blurs when you switch apps, codes are hidden in the app switcher, and they are covered whenever the screen is being recorded or mirrored.

All three protections default to on and can be tuned in Settings.

Deletes stay deleted

Deleting a code writes a tombstone immediately, so it disappears from your other devices at once — the 7-day Recently Deleted bin never delays that. Tombstones are stored in the Keychain, which is why a reinstall can no longer resurrect codes you asked to delete.

Tombstones are kept for 30 days. A device that stays offline longer than that and still holds a live copy can reintroduce a token — the deliberate trade-off for not carrying deletion bookkeeping forever.

What Autheris cannot protect you from. iOS gives apps no notice when a screenshot is taken, so the privacy screen cannot cover one — Autheris does not claim it does. Backups you export are protected by the password you set and by wherever you choose to keep the file. If you never enable iCloud Sync and never export a backup, your codes exist only on the device they were added to.

FAQ

Questions people actually ask

More answers, including troubleshooting steps, are on the support page.

Is Autheris free?

Yes — Autheris is free on the App Store, with no ads. The source code is published under the MIT licence, so you can audit exactly what it does with your secrets.

Do I need an account?

No. There is nothing to sign up for, no email address to hand over, and no Autheris server in the middle. An iCloud account is only relevant if you choose to turn iCloud Sync on.

Where exactly are my secrets stored?

In the iOS Keychain, as JSON, using kSecAttrAccessibleWhenUnlockedThisDeviceOnly. That keeps them off other apps, out of iCloud Keychain, out of encrypted device backups, and unreadable while your iPhone is locked.

If you export a backup, that file is protected by the password you choose (AES-256-GCM) and by wherever you decide to keep it.

Does it sync to iCloud?

Only when you turn it on — the setting is off by default and it is a per-device choice.

  • Sync uses your private CloudKit database, scoped to your Apple ID.
  • Labels, account names, secrets, ring colours and pin flags are written as CloudKit encrypted fields. The developer cannot read them.
  • Turning sync off asks what to do: keep the codes on this device, or delete the iCloud copy first — which removes them from your other devices too.
What happens if I lose my phone?

If iCloud Sync was on, your codes come back on a new iPhone signed in to the same Apple ID. If it was off and you have no backup export, the codes only ever existed on that device — which is the point of the design, and the risk to plan around.

Export an encrypted backup from Settings → Backup, or turn on sync, before the day you need it.

Can I import from Google Authenticator?

Yes. Autheris imports from Google Authenticator, Aegis, andOTP and 2FAS export files, and it scans QR codes or accepts setup links one account at a time.

Why can’t it hide my codes from a screenshot?

Because iOS does not tell apps when a screenshot is taken, and the capture protection only applies to screen recording and mirroring. Autheris covers your codes in the app switcher and during recording, but a screenshot is a single frame taken without the app’s involvement. It does not pretend to block them.

Is it open source?

Yes — Swift/SwiftUI, MIT licensed, at github.com/nerdykidtech/Autheris. The security-relevant logic (sync merge rules, tombstones, ordering, privacy shield, backup crypto) lives in small pure types with unit tests.

Autheris app icon

Keep your second factor under your own control

Free on the App Store for iPhone. No account, no tracking, nothing to cancel later.

iOS 16.0 or later · iPhone · Version 2.0 · Free