Best European Alternatives to Authy

Looking for an alternative to Authy for two-factor authentication? Authy is owned by Twilio (a US company), requires a phone number to use, and stores your 2FA secrets in their cloud. For privacy-conscious users, open-source alternatives offer better control over your authentication data.

We've curated the best privacy-focused 2FA apps, many of which are open source and store your data locally. These alternatives give you full control over your authentication tokens without relying on US cloud services.

2 Alternatives
100% Open Source
How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy

Why Choose an Alternative to Authy?

Open Source

Audit the code yourself - know exactly how your 2FA secrets are handled.

Local Storage

Your 2FA tokens stay on your device, not in someone else's cloud.

Easy Export

Export and backup your tokens anytime - no vendor lock-in.

No Phone Required

No phone number or personal information needed to get started.

Best Alternatives to Authy

We've curated the best open-source and privacy-focused 2FA apps. Each alternative has been evaluated for security, usability, and privacy features.

Aegis Authenticator

Free, open-source 2FA app for Android with encrypted local storage

#1 for replacing Authy
Open Source
Coming soon Visit website

Proton Pass

Swiss password manager with built-in 2FA support and encryption

#2 for replacing Authy
Switzerland

Feature Comparison: Authy vs Alternatives

Feature Authy Aegis Proton Pass
Open Source No Yes Yes
Cloud Sync Required Optional E2E Encrypted
Phone Required Yes No No
Easy Export No Yes Yes
iOS Support Yes No Yes
Desktop App Yes No Yes
Pricing Free Free Free tier

Key takeaways

  • Authy is free, so price is not a reason to leave; the absence of an export function is, and it compounds with every account you add.
  • Twilio discontinued the Authy desktop apps for Windows, macOS and Linux in August 2024, leaving phones as the only client.
  • In July 2024 an unauthenticated Twilio endpoint exposed the phone numbers behind 33 million Authy accounts.
  • Aegis is not European in any verifiable sense — there is no company and no server, which is the actual argument for it.
  • Proton Authenticator is the only replacement here that restores desktop codes and can also sync them, and it costs nothing.

Why people leave Authy

Authy costs nothing, so the usual comparison — European product, similar features, better price — has no purchase here. Nobody is overpaying for Authy. What they are paying is something else.

In August 2024 Twilio ended the Authy desktop applications for Windows, macOS and Linux. People who generated their codes on a laptop lost the client they had been using, and what remained were the Android and iOS apps. The product did not get worse; a part of it was removed by the company that owns it.

That would be a minor annoyance if you could take your codes elsewhere. You cannot: Authy has never had an export function. Leaving means signing in to every service you protected, turning two-factor authentication off, and turning it back on against a new app, one account at a time. The longer you stay, the more that costs — which is the real price of a free product.

  • There is no export, so the exit gets more expensive every month Every other app on this page will hand you your seeds in a file. Authy will not. That means the switching cost is not a download but an afternoon of disabling and re-enrolling two-factor authentication across thirty or eighty accounts, each with its own settings page and its own recovery codes to write down. Nothing about that is accidental, and nothing about it is going to change.
  • Twilio removed the desktop client The Windows, macOS and Linux apps were discontinued in August 2024, leaving phones as the only place Authy runs. For anyone who signs in to internal systems on a desktop all day, that turned a two-second copy-and-paste into picking up a handset several dozen times a day. It also demonstrates the general point: the client you rely on exists at the vendor's discretion.
  • The account is a phone number, and the phone numbers leaked In July 2024 attackers used an unauthenticated Twilio endpoint to confirm the phone numbers attached to 33 million Authy accounts. No codes or seeds were taken. What was taken is a list of numbers known to belong to people who use two-factor authentication, which is precisely the audience for a SIM-swap or a smishing campaign, and a number is much harder to change than a password.
  • It is a side product of a communications company Twilio Inc. in San Francisco sells messaging and voice APIs to developers; a consumer authenticator app is not the business. That is the context for the desktop shutdown and for an endpoint that went unauthenticated. It is also United States jurisdiction, which matters less here than elsewhere — the seeds are end-to-end encrypted under your backup password — but the phone number, the email address and the list of services you enrolled are not the same category of secret.

What you have to replace, not just match

Work out which Authy you are using, because the two versions of it land in different places.

One is Authy as a plain code generator on a single phone. Replacing that is easy and both options here do it better, with an export function attached. The other is Authy as a synchronised service: encrypted cloud backup, the same tokens on a tablet and a second handset, recoverable if the phone goes into a canal. That is the part Authy genuinely does well and the part a local-only app does not do at all.

Aegis is the answer for the first and refuses the second on purpose. Proton Authenticator, the free app from the company behind Proton Pass, is the only option here that covers both, and it is also the only one that puts codes back on a desktop after Twilio took that away.

The alternatives compared

European Authy alternatives, in the order this page ranks them, compared on headquarters, pricing and jurisdiction
PositionToolHeadquartersPricingJurisdiction
#2 Proton Pass Geneva, Switzerland Free tier / from about €1.99/month (Pass Plus) Switzerland (adequacy decision, outside the EEA)

How each alternative compares to Authy

#1

Aegis Authenticator

the one where there is no company at all

Best for: Android users who want their codes in a file they hold

Aegis is published by Beem Development under GPL v3, and the whole of it is an Android app. The vault is encrypted with AES-256-GCM and unlocked with a password or a fingerprint, automatic backups are written to a location you choose, and it imports tokens from most other authenticator apps. There is no account, no sign-up and no server.

That is the argument against Authy in a sentence. Authy can discontinue a desktop client, an endpoint of Authy's can leak the number your account is keyed to, and you cannot take your seeds out of Authy. None of those three things has an equivalent here, because there is no service to change its mind, no identifier to expose and an export in both plain and encrypted form whenever you want one.

Be clear about what is not on offer. It is Android only, so there is no iPhone version and no desktop client, which means it does not restore what Twilio removed in August 2024. It does not sync, so a second device is your own problem, and if you lose the phone without a backup you are working through recovery codes. It also carries no verifiable jurisdiction, and this page is not going to invent one for it.

What Aegis Authenticator does better than Authy

  • Exports your tokens in plain or encrypted form, where Authy offers no export at all
  • No account and no phone number, so there is no identifier of the kind that leaked in July 2024
  • No company that can withdraw the client, as Twilio did with the desktop apps in August 2024
  • GPL v3 source anyone can read, against a closed product owned by a communications company
  • Automatic backups written wherever you choose, rather than to a provider's cloud

Where Aegis Authenticator is a step down from Authy

  • Android only, where Authy also ran on iOS — and it does not bring back a desktop client either
  • No sync between devices, which is the thing Authy genuinely did well
  • Lose the phone without a backup and the tokens are gone; Authy would have restored them
  • No company behind it and no stated jurisdiction, so support is a GitHub issue and goodwill

Standout against Authy. It is the only option here with nothing to leak and nobody to discontinue it, because there is no service — only a file on your phone.

#2

Proton Pass

the one that puts codes back on your desktop

Geneva, SwitzerlandFree tier / from about €1.99/month (Pass Plus)#1 in Password Managers

  • Which law reaches it. Switzerland (adequacy decision, outside the EEA). Authy is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Switzerland, Germany.
  • Source code. Open source, where Authy is not: you can read what it does rather than take the description on trust.

Best for: People who lost the Authy desktop app and still want sync

Proton AG in Geneva makes two things relevant to anyone leaving Authy. Proton Pass includes a built-in authenticator on Pass Plus, so codes sit beside the passwords they belong to. Separately — and not as part of any Pass subscription — Proton Authenticator is a free standalone app on Android, iOS, Windows, macOS and Linux, open source, usable with no account at all, and syncing end to end encrypted across devices when you sign in.

Measured against Authy specifically, that is the one product on this page which replaces what was taken away and keeps what worked.

Desktop codes came back after Twilio removed them in August 2024, multi-device sync still exists, and there is a direct export — the absence of which is the reason leaving Authy is a chore rather than a click. Its importer handles Google Authenticator, 2FAS, Aegis, Bitwarden Authenticator, Ente Auth and LastPass Authenticator; Authy is not in that list because Authy produces nothing to import.

Two honest caveats. If you sync, a Swiss company again holds encrypted material on your behalf, which is a better jurisdiction than California but is not the same as holding nothing. And if you take the Pass Plus route rather than the standalone app, both of your factors end up behind one master password, which for a bank or a registrar is not what you want.

What Proton Pass does better than Authy

  • Runs on Windows, macOS and Linux as well as phones, which Authy stopped doing in August 2024
  • Direct export of your codes, where Authy has never offered one
  • Open source and independently audited, against a closed product from a communications vendor
  • No phone number required, so the identifier exposed in the 2024 Twilio leak is not collected
  • Swiss company and Swiss or German storage, rather than a San Francisco entity under the CLOUD Act

Where Proton Pass is a step down from Authy

  • Syncing means a provider holds your encrypted tokens, where Authy's replacement on this page above holds nothing
  • Keeping codes in Pass Plus puts both factors behind one master password
  • Newer than Authy, and fewer services name it in their own setup instructions
  • The vault product it belongs to only became available in 2023, so the surrounding features are still filling in

Standout against Authy. It is the only replacement here that gives you back the desktop client Twilio deleted, syncs across devices, and still lets you export and walk away.

proton.me/pass Visit Proton Pass

What actually breaks when you switch

The migration is manual and there is no shortcut, so treat it as an inventory exercise first. Open Authy, list every token in it, and work down that list rather than relying on memory — the accounts people forget are the ones they enrolled once and never signed out of, which are also the ones with the slowest recovery process.

Collect recovery codes as you go. Most services offer a set of one-time codes at the moment you enrol a new authenticator, and that is the only point at which they are easy to get. Printed and kept somewhere physical, they are what saves you when a phone is stolen on the third day of a migration.

And do not delete Authy on the day you finish. Leave it installed for a fortnight with the tokens intact, because the accounts you missed announce themselves the next time you sign in to them, and until then Authy is the only thing that still has their seeds.

How do I actually get my codes out of Authy?

By hand, service by service, and there is no trick that avoids it. Authy publishes no export, so the procedure is: install the new app, then for each account open its security settings, remove the existing authenticator, scan the new QR code, confirm with a fresh code, and save the recovery codes the service offers you.

Do it in an order and do not do it all in one sitting. Start with email, because it is the recovery path for the rest. Then anything with money in it. Then work accounts, where an administrator can usually reset you if it goes wrong. Leave the long tail of forums and shopping sites for whenever you next sign in to them.

Keep Authy installed until the last account is confirmed working on the new app. The failure people actually hit is deleting Authy after a successful-looking migration and then discovering one account was never re-enrolled, on a service whose account recovery takes five working days.

Is Authy unsafe after the 2024 phone number exposure?

The tokens themselves were not affected. What attackers obtained through the unauthenticated endpoint was confirmation of which phone numbers were registered, not seeds, not codes and not backups.

The harm is indirect and durable. A verified list of people who use two-factor authentication is a good target list: convincing smishing that claims to be from Authy or from a service you use, and SIM-swap attempts against numbers now known to be worth swapping. Authy accounts are keyed to a phone number, so this is the identifier the account is built on rather than an incidental field.

Treat it as a reason to review how your mobile operator authenticates a SIM change, which is worth doing regardless, rather than as evidence your codes are compromised. They are not.

Do I lose multi-device sync if I leave?

Only if you choose Aegis, and that is deliberate rather than a gap. Aegis keeps an encrypted vault on the device and writes automatic backups to a location you pick, which might be a folder your own sync tool handles. There is no account, no server and therefore no sync in the sense Authy means it.

Proton Authenticator does sync, end to end encrypted, across Android, iOS, Windows, macOS and Linux, and it will also run with no account at all if you would rather keep it local. That combination — optional account, every platform, free — is not something Authy offered even before the desktop apps were withdrawn.

Whichever you choose, write down or print the recovery codes each service gives you when you enrol. They are the real backup, and they work when every app on this page has failed you.

Should my two-factor codes live in my password manager?

It is a genuine trade rather than a rule. Proton Pass includes a built-in authenticator on Pass Plus, and putting codes beside the passwords makes signing in one step instead of two, which is why people who do it stop losing accounts to abandoned second factors.

The objection is that both factors then sit behind one master password, which turns two factors into one with extra steps. For a bank, a domain registrar or anything holding client data, keep the second factor in a separate app.

A reasonable split is the one most careful people settle on anyway: codes for high-value accounts in a dedicated authenticator, codes for the forty sites that forced two-factor on you in the password manager. That is not a compromise so much as an accurate reading of how much each account is worth.

Which one to pick

If you are on Android and what you want is your codes in a file with nobody in between, Aegis is the answer and the lack of a company behind it is the feature rather than the risk. Set up the automatic backup on the first day, not the day after you drop the phone.

If you used Authy on a computer and lost that in August 2024, or you need the same tokens on two devices, Proton Authenticator is the only option here that covers it, and it costs nothing.

If you want the codes beside the passwords, Proton Pass does that on Pass Plus — but keep your bank, your email and your domain registrar in a separate app, because two factors behind one master password is one factor wearing a hat.

Whichever you pick, the reason to move now rather than later is arithmetic. Authy has no export, so the migration is priced per account, and that price only goes up.

Frequently Asked Questions

Aegis if you are on Android and want your codes in a file you control, with no account and no service behind them. Proton Authenticator if you need the codes on more than one device, or on a desktop again, since it runs on Android, iOS, Windows, macOS and Linux and syncs end to end encrypted when you want it to. Both are free and both, unlike Authy, will export.

No. Authy has never shipped an export function, so tokens cannot be moved to another app. Migrating means disabling two-factor authentication on each service and enrolling again with the new app. Proton Authenticator's import list covers Google Authenticator, 2FAS, Aegis, Bitwarden Authenticator, Ente Auth and LastPass Authenticator, and Authy is absent from it for exactly this reason.

No. Twilio discontinued the Windows, macOS and Linux applications in August 2024, and Authy now runs on Android and iOS only. If you enter codes on a computer all day, that is the change that most likely brought you to this page, and Proton Authenticator is the option here that puts a desktop client back.

In July 2024 the ShinyHunters group used an unauthenticated Twilio API endpoint to confirm the phone numbers associated with 33 million Authy accounts. Seeds, codes and encrypted backups were not involved. The result is a verified list of two-factor users, which is useful for targeted phishing by text message and for SIM-swap attempts, and a phone number is far harder to rotate than a password.

There is no verifiable answer, and it is more honest to say so than to assume. Aegis is published by Beem Development under GPL v3 and names no country on its site or in its repository. It also does not matter much here: there is no company holding your data and no server to send an order to, because the vault is a file on your own Android device.

Authy is free for consumers, and so are both replacements on this page. Aegis is free and open source with no paid tier. Proton Authenticator is free, open source and works without a Proton account. Cost is not what separates these, which is unusual on this site and worth saying plainly.

Two things. Its encrypted cloud backup and multi-device model have worked reliably for years and are the reason many people never looked further. And it has the recognition: support pages at hundreds of services name Authy by name in their setup instructions, which quietly makes it the default. Neither is a technical advantage, and neither survives a company deciding to withdraw a client.

It can, and the way it happens is predictable. Because there is no export you must re-enrol each service individually, and any account you miss is still pointing at an Authy install you have deleted. Keep Authy on the phone until every service is confirmed working elsewhere, and collect the recovery codes as you go — they are what gets you back in when both apps have failed.

Both, for now. Passkeys are phishing-resistant in a way that a six-digit code is not, and where a service supports them they are the better second factor. In practice most services still do not, and the ones that do usually keep a code-based fallback enabled anyway. An authenticator app you control, with an export function, remains the sensible floor.

Who worked on this review

Three people touch every comparison page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Marta Kowalczyk
Written by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Sebastiaan Smits
Edited by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Ingrid Halvorsen
Fact-checked by

Ingrid Halvorsen

Managing Editor · Oslo, Norway

Runs the review process and decides when a page is ready to publish or needs another pass.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Explore More European Alternatives

Discover privacy-focused European alternatives to other popular US tech services.

1Password Alternatives Okta Alternatives ExpressVPN Alternatives Browse All Categories