Smart 2FA Manager Android
A secure, offline TOTP 2FA manager for Android
AES-256-GCM encryption, QR scanning, offline operation, and Material Design UI.
Smart 2FA Manager Android — a lightweight, offline TOTP (Time-based One-Time Password) manager for Android. Store your 2FA secrets encrypted locally, generate codes without an internet connection, and maintain full control over your authentication data.
Android 8.0 (API level 26) or higher required.
- AES-256-GCM Encryption — industry-standard encryption for your secrets
- SHA-512 Key Derivation — strong password hashing
- QR Code Scanning — quickly add services by scanning QR codes
- Real-time Search — filter services by name instantly
- One-Tap Code Copying — copy TOTP codes with a single tap
- Offline Operation — no internet connection required
- Material Design UI — clean and intuitive interface
- Master Password Protection — all data encrypted with your master password
- Interactive Tooltips — long press any button to see its function
Installation:
- Download the APK from the Releases page
- Enable "Unknown Sources" in your Android settings
- Install the APK and open the app
First Launch:
- Create a master password — this password encrypts all your 2FA secrets
- WARNING — if you lose this password, your secrets are lost forever (no recovery!)
- Add your first service — tap the menu button and select "Add Service"
Option 1: Manual Entry
- Tap the menu button (three dots)
- Select Add Service (+)
- Enter service name and secret key (Base32 format)
- Tap Add
Option 2: QR Code Scan
- Tap the menu button (three dots)
- Select Scan QR (camera icon)
- Scan the TOTP QR code from your service provider
- Service will be added automatically
Using TOTP Codes:
- Copy Code — Tap the "COPY" button to copy the current code
- View Secret — Tap the "SECRET" button to see the secret key
- Delete Service — Tap the "DELETE" button to remove a service
- Search — Tap the "SEARCH" icon to filter services by name
Main Screen:
- Service Cards — List of all your 2FA services
- TOTP Code — Current 6-digit code with countdown timer
- Color Coding — Blue (normal), Orange (10 sec left), Red (3 sec left)
- Service Counter — Shows number of services in toolbar
Toolbar Buttons:
| Button | Action |
|---|---|
| Search | Opens search bar to filter services |
| Show All Tips | Displays tooltips for all buttons |
Menu Buttons:
| Button | Action |
|---|---|
| Scan QR | Add service via QR code |
| Add Service | Add service manually |
| Help | Opens help documentation |
| About | Shows app information and links |
Service Card Buttons:
| Button | Action |
|---|---|
| Copy | Copy current TOTP code to clipboard |
| Secret | View secret key (requires master password) |
| Delete | Remove service |
Encryption:
- Algorithm — AES-256-GCM (Galois/Counter Mode)
- Key Derivation — SHA-512
- IV — Random 12-byte initialization vector per encryption
Data Storage:
- Location —
Documents/.2fa/secrets.enc - Format — Encrypted JSON with service:secret pairs
- No Internet — App never sends data over the network
- Local Only — All secrets remain on your device
Master Password:
- Never stored — Password is only used to derive encryption key
- No recovery — If forgotten, secrets cannot be recovered
- Local only — Password never leaves your device
| Component | Specification |
|---|---|
| Encryption | AES-256-GCM |
| Key Derivation | SHA-512 |
| TOTP Standard | RFC 6238 |
| Time Step | 30 seconds |
| Code Length | 6 digits |
| Hash Algorithm (TOTP) | HMAC-SHA1 |
| Min Android Version | API 26 (Android 8.0) |
By using this software, you agree to the full disclaimer terms.
Software provided "AS IS" without warranty. You assume all risks.
Full legal disclaimer: See DISCLAIMER.md
License: BSD 3-Clause License