Aegis Authenticator

Open-source, offline two-factor authenticator app for Android

Quick Overview

Company None (open-source community project)
Category Two-Factor Authentication
Headquarters Not applicable — no incorporated entity
Founded 2019 (first public release)
EU Presence Not applicable: local-only app, no company processes any data
Data Location On-device only, by design
Open Source Yes, GNU GPL v3.0
Compliance Not applicable — no data controller exists
Pricing Free
Free Option Fully free, no paywall
Replaces Authy, Google Authenticator

Detailed Review

Authy and Google Authenticator both ask you to trust a US company with the seed codes that generate your two-factor login for every other account you own. Aegis sidesteps the question a different way: there is no company to trust in the first place.

The app is published under the name Beem Development, a pseudonymous open-source collective with a public GitHub organisation, a GPL v3.0 licence, and a Gmail contact address rather than a corporate one. No jurisdiction, no registered office and no privacy policy to read, because there is no data controller: every code is generated and stored locally, encrypted, on the phone.

That also means Aegis has no cloud sync of its own. Backups are the user's responsibility — an encrypted export file you store wherever you choose, including a European cloud drive if that matters to you — rather than an automatic sync to a server operated by the app's maker.

The trade-off is the one every self-hosted or local-only tool makes: there is no customer support line and no company to escalate a bug to, only a GitHub issue tracker maintained by volunteers. For a security-critical app that holds the keys to every other account, plenty of people consider that an acceptable and even preferable trade.

What Aegis Authenticator does well

  • No company, no server, no cloud account: nothing exists for a foreign court order to compel
  • Fully open source under GPL v3.0, auditable by anyone
  • Encrypted local vault with an optional, user-controlled encrypted export for backup
  • Free with no paid tier, no account, no telemetry

Where Aegis Authenticator falls short

  • Android only, no first-party iOS or desktop client
  • No official cloud sync — backup and restore is a manual, user-driven process
  • Support is community-based (GitHub issues), not a vendor helpdesk

Standout feature. The absence of a company is the feature: a 2FA vault that never leaves your device removes the jurisdiction question that every cloud-based authenticator app raises.

Pros and Cons

Pros

  • No company, no server, no cloud account: nothing exists for a foreign court order to compel
  • Fully open source under GPL v3.0, auditable by anyone
  • Encrypted local vault with an optional, user-controlled encrypted export for backup
  • Free with no paid tier, no account, no telemetry

Cons

  • Android only, no first-party iOS or desktop client
  • No official cloud sync — backup and restore is a manual, user-driven process
  • Support is community-based (GitHub issues), not a vendor helpdesk

Frequently Asked Questions

What is Aegis Authenticator?

Aegis Authenticator is a free, open-source two-factor authentication app for Android that stores every TOTP/HOTP code in an encrypted local vault, with no cloud account, no company servers, and no data ever leaving the device unless you choose to back it up yourself.

Where is Aegis Authenticator based?

Aegis has no registered company behind it: it is published under the name "Beem Development," an open-source collective on GitHub, with no incorporated entity, no office, and a Gmail contact address rather than a corporate domain.

What does Aegis Authenticator cost?

Free, GNU GPL v3.0, no paid tier

Who is Aegis Authenticator best for?

Anyone who wants a 2FA app that structurally cannot be a US-jurisdiction data-sovereignty question, because there is no server, no company and no cloud account for a court order to reach.

What are the drawbacks of Aegis Authenticator?

Android only, no first-party iOS or desktop client No official cloud sync — backup and restore is a manual, user-driven process Support is community-based (GitHub issues), not a vendor helpdesk

Is Aegis Authenticator a good alternative to Authy?

Aegis Authenticator is built as a European alternative to Authy: Open-source, offline two-factor authenticator app for Android. It will not be a like-for-like feature match in every respect, so check the review above for where the two genuinely differ before switching.

How does Aegis Authenticator compare to other Two-Factor Authentication tools?

Aegis Authenticator is one of several European Two-Factor Authentication tools we cover. It is most often compared with Authy, Google Authenticator.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Marta Kowalczyk
Written by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Daniel Brandt
Edited by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Sebastiaan Smits
Fact-checked by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to Aegis Authenticator