OSS Tanbou

keep two-factor secrets in an encrypted local vault with user-controlled backups

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
13,193
Primary language
Java
License
GPL-3.0
Repository last updated
Sep 6, 2026
On this page

Overview

Aegis Authenticator is an Android HOTP/TOTP authenticator that stores two-factor token secrets in an on-device vault. The vault can use AES-256-GCM encryption, scrypt-derived password credentials, and Android Keystore-backed biometric credentials.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Support HOTP and TOTP across many services

Aegis supports RFC 4226 HOTP and RFC 6238 TOTP and can add entries through QR scanning, manual entry, or imports from other authenticator applications.

Sources: [2]

Encrypt the vault with AES-256-GCM and scrypt

The vault uses a random 256-bit master key with AES-256-GCM. Password credentials are derived through scrypt and biometric credentials can wrap the master key through Android Keystore.

Sources: [3]

Use encrypted exports and automatic backups

Manual exports and automatic backups share the same vault format and can preserve encryption while data is moved off the device.

Sources: [2][4]

Best fit

Fits Android users who want local-first control of 2FA tokens

It is relevant when token secrets should remain under device-level encryption rather than depend on a cloud account managed by the authenticator vendor.

Sources: [2][4]

Before adoption

Plan password recovery and backups because a lost vault password cannot be bypassed

The FAQ warns that forgetting the vault password results in loss of access to the vault and recommends keeping the password reminder enabled.

Sources: [4]

Cloud backups rely on Android Storage Access Framework rather than direct network access

Automatic cloud backup requires a provider app that participates in Android Storage Access Framework. The FAQ states that Aegis itself does not have internet access.

Sources: [4]

v3.4.3 includes a security fix for crafted icon-pack imports

The v3.4.3 release fixes an issue where a malicious icon pack could overwrite internal files, including the vault file. Older installations should be reviewed for upgrade.

Sources: [5]

Official sources

  1. [1]beemdevelopment/Aegis repository(2026-10-01)
  2. [2]Aegis README(2026-10-01)
  3. [3]Aegis vault security design(2026-10-01)
  4. [4]Aegis FAQ(2026-10-01)
  5. [5]Aegis v3.4.3 release(2026-10-01)
  6. [6]Aegis GPL-3.0 license(2026-10-01)
Supplemental curator note

Aegis stores 2FA secrets in an on-device vault protected by a password or Android Keystore-backed biometrics. Automatic cloud backup relies on Android's Storage Access Framework; the FAQ states that Aegis itself does not have internet access.

Try it in 3 steps

  1. 1

    Download the v3.4.3 APK

    Fetch the current stable APK from the official GitHub Release. Google Play or F-Droid can be used instead.

    curl -LO https://github.com/beemdevelopment/Aegis/releases/download/v3.4.3/aegis-v3.4.3.apk
  2. 2

    Verify the APK signature

    Compare the signing certificate fingerprint with the Beem Development fingerprint published in the README before installation.

    apksigner verify --print-certs --verbose aegis-v3.4.3.apk
  3. 3

    Install on the Android device

    This example uses Android Debug Bridge. After launch, set a vault password, add a 2FA QR code, and configure an encrypted backup.

    adb install aegis-v3.4.3.apk
Check the official README

Growth

Growth trends · Last 30 days

13,193 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
4
Open PRs
12

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • otp
  • totp
  • hotp
  • android
  • secure
  • encryption
  • fingerprint
  • 2fa
  • authenticator
Stars
13,193
Forks
598
Watchers
112
Open issues
113
Contributors
62
Owner type
Organization
Primary language
Java
License
GPL-3.0
Repository last updated
Sep 6, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?