On this page
Overview
Aegis Authenticator is an Android HOTP/TOTP authenticator that stores two-factor token secrets in an on-device vault. The vault can use AES-256-GCM encryption, scrypt-derived password credentials, and Android Keystore-backed biometric credentials.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Support HOTP and TOTP across many services
Aegis supports RFC 4226 HOTP and RFC 6238 TOTP and can add entries through QR scanning, manual entry, or imports from other authenticator applications.
Sources: [2]
Encrypt the vault with AES-256-GCM and scrypt
The vault uses a random 256-bit master key with AES-256-GCM. Password credentials are derived through scrypt and biometric credentials can wrap the master key through Android Keystore.
Sources: [3]
Best fit
Before adoption
Plan password recovery and backups because a lost vault password cannot be bypassed
The FAQ warns that forgetting the vault password results in loss of access to the vault and recommends keeping the password reminder enabled.
Sources: [4]
Cloud backups rely on Android Storage Access Framework rather than direct network access
Automatic cloud backup requires a provider app that participates in Android Storage Access Framework. The FAQ states that Aegis itself does not have internet access.
Sources: [4]
v3.4.3 includes a security fix for crafted icon-pack imports
The v3.4.3 release fixes an issue where a malicious icon pack could overwrite internal files, including the vault file. Older installations should be reviewed for upgrade.
Sources: [5]
Official sources
- [1]beemdevelopment/Aegis repository(2026-10-01)
- [2]Aegis README(2026-10-01)
- [3]Aegis vault security design(2026-10-01)
- [4]Aegis FAQ(2026-10-01)
- [5]Aegis v3.4.3 release(2026-10-01)
- [6]Aegis GPL-3.0 license(2026-10-01)
Supplemental curator note
Aegis stores 2FA secrets in an on-device vault protected by a password or Android Keystore-backed biometrics. Automatic cloud backup relies on Android's Storage Access Framework; the FAQ states that Aegis itself does not have internet access.
Try it in 3 steps
- 1
Download the v3.4.3 APK
Fetch the current stable APK from the official GitHub Release. Google Play or F-Droid can be used instead.
curl -LO https://github.com/beemdevelopment/Aegis/releases/download/v3.4.3/aegis-v3.4.3.apk - 2
Verify the APK signature
Compare the signing certificate fingerprint with the Beem Development fingerprint published in the README before installation.
apksigner verify --print-certs --verbose aegis-v3.4.3.apk - 3
Install on the Android device
This example uses Android Debug Bridge. After launch, set a vault password, add a 2FA QR code, and configure an encrypted backup.
adb install aegis-v3.4.3.apk
Growth
Growth trends · Last 30 days
13,193 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 4
- Open PRs
- 12
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- otp
- totp
- hotp
- android
- secure
- encryption
- fingerprint
- 2fa
- authenticator
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Tauri111,529 Stars
2 shared tag(s)
Combine a web frontend and Rust native layer into desktop and mobile apps using system WebViews
Rust - Kotlin53,467 Stars
2 shared tag(s)
keep Java interoperability while extending one language from JVM to Android, iOS, desktop, and web
Kotlin - OkHttp47,080 Stars
2 shared tag(s)
centralize HTTP, TLS, connection reuse, caching, and DNS for Android/JVM applications
Kotlin - Tailscale37,060 Stars
2 shared tag(s)
Join devices to a WireGuard mesh with tailscaled/CLI while coordinating identity, NAT traversal, and policy through a managed control plane
Go - HashiCorp Vault36,330 Stars
1 shared tag(s) · 2 shared category(s)
manage secret storage, issuance, encryption, leases, and revocation under one policy model
Go - JumpServer31,707 Stars
1 shared tag(s) · 2 shared category(s)
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python
Report incorrect information
Tell us if any listing information is incorrect or outdated.