Aegis Authenticator review: open-source 2FA for Android
Review of Aegis Authenticator: free GPL v3 2FA app for Android with an encrypted vault, automatic backups, export, audit log, limits and who should use it.
ReviewsPublished
Provider
Aegis Authenticator
Origin: Open source, Netherlands
Visit website
Aegis Authenticator is a free, open-source app for Android that stores your two-factor codes in a vault you control. It supports the standard HOTP and TOTP algorithms that most services use (see our explanation of TOTP codes), encrypts the vault with a password you set, makes automatic backups to a location of your choice and exports in encrypted or plain form. It is Android-only, which is its biggest limit and also part of its focus. This review is an editorial assessment based on the project’s published information as of October 2026, not a laboratory test.
What Aegis offers
| Feature | Aegis Authenticator |
|---|---|
| Platform | Android 6.0 or newer |
| Licence | GPL v3, open source |
| Algorithms | TOTP and HOTP |
| Vault encryption | With a password you set |
| Backup | Automatic backups to a location you choose; encrypted or plain export |
| Audit log | Yes, a log of important vault events |
| Account or cloud service | None of its own |
| Origin | Open source, Netherlands |
| Cost | Free |
The project is maintained by an independent developer team, listed with a Netherlands origin, and distributed as open source. You can obtain it from common Android sources, including the F-Droid repository, which is a plus for people who avoid proprietary app stores.
Backup and export
Aegis does not run a cloud service. That means no company holds your codes, but it also means the backup is your job. The app can write automatic backups to a folder you choose. If your cloud provider supports Android’s Storage Access Framework, as Nextcloud does, the backup can land in your own cloud storage. You can also export the vault by hand, encrypted or as plain data. Plain export is convenient for migration, but anyone who gets the file can read all your secrets, so delete it afterwards.
A sensible routine looks like this: set a strong vault password, switch on automatic encrypted backups to a cloud folder or another place off the phone, and test a restore on a second device. Store the vault password in your password manager. If you lose both the phone and the password, there is no vendor who can help.
Security and privacy
Because Aegis is open source, anyone can inspect how it handles secrets. It has no account and does not need an internet connection to generate codes. The audit log records important events in the vault, which helps you notice unexpected changes. The app encrypts your vault with strong cryptography once you set a password. If you do not set one, your codes are stored without that protection, so setting it should be your first step.
We have not performed a code audit, and open source does not equal verified security. If a published independent review matters to you, check the project’s documentation for the current state.
Limits
- Android only. There is no iPhone, desktop or browser version. If you ever change to an iPhone, you will have to export and import into another app.
- No live sync. Your codes are on one device plus your backups. If you want the same codes on a phone and a laptop at all times, Ente Auth is the more natural choice.
- Backup is on you. There is no vendor cloud. The control is useful, but it needs discipline.
- Codes remain phishable. A fake website can ask you for a code. A passkey or a hardware key resists that; see the overview of hardware security keys and our guide to two-factor authentication.
Who should use it
Aegis suits Android users who want an authenticator that stays entirely under their control: no account, no vendor cloud, open code and flexible backups. It is a good choice for privacy-minded users, for people who run a Nextcloud or similar service and for anyone who wants to be able to leave without friction. For iPhone users or mixed households, 2FAS is the simpler path, as described in our 2FAS review, and our overview of the best authenticator apps compares all three.
How we assessed it
This review is based on the project’s published description, its open-source licence information, app-store and F-Droid listings and public documentation of its features. We did not run lab tests, audit the code or time anything, and we do not give star ratings. Version numbers and features change with releases, so check the current changelog before you rely on a specific function.
Getting started in five steps
- Install Aegis from a source you trust, such as F-Droid or the official Android store listing.
- Set a strong vault password when the app first asks, and store it in your password manager.
- Add accounts by scanning the QR code each service shows when you enable two-factor authentication.
- Switch on automatic backups to a folder off the phone, for example a synchronised cloud folder, and save each service’s backup codes separately.
- Restore a backup on a second Android device once, so you know the whole chain works.
Verdict
Aegis is a lean, free and transparent authenticator, and for Android users who want control it is one of the strongest options. Its weaknesses are the platform restriction and the lack of automatic sync. Set a vault password, turn on encrypted backups, store the one-time backup codes of your key accounts separately, and you will have a solid setup.
Frequently asked questions
Is Aegis available for iPhone?
No. Aegis is an Android app only and requires Android 6.0 or newer. People with an iPhone can use 2FAS or Ente Auth, which both offer iOS apps.
Is the Aegis vault encrypted automatically?
The vault is encrypted when you set a password, and the app supports strong cryptography for it. If you skip the password, your codes are stored without that protection, so set the password when you first open the app.
How does backup work in Aegis?
Aegis can export the vault in encrypted or plain format and can make automatic backups to a location you choose. If your cloud provider supports Android's Storage Access Framework, such as Nextcloud, the backups can go there. You decide where the file ends up.
Where do I get Aegis?
The app is published as open source under the GPL v3 licence and is available through common Android app sources, including F-Droid. Download it only from sources you trust, and check that it is the app by the Aegis developers.
Can I move my codes from Aegis to another app?
Yes. Aegis exports its vault, and many authenticator apps can import common formats. Test the import in the new app before you delete anything in the old one.
More in Reviews
1Password review 2026: security, features and price
1Password reviewed: Secret Key security, passkeys, EU account region, recovery rules, export and 2026 prices in euros. Who it suits and the alternatives.
Best free password managers in 2026: what you really get
Bitwarden, Proton Pass and KeePassXC offer genuinely usable free password managers, while Dashlane and 1Password no longer do. Limits and trade-offs explained.
Best hardware security keys 2026: YubiKey, Nitrokey, Token2
The best hardware security keys of 2026 compared: YubiKey 5, Security Key Series, Nitrokey 3, Token2 and Google Titan on passkeys, NFC, firmware and price.
Best password managers 2026: compared for European users
Seven password managers compared on encryption, audits, passkeys, EU data options, recovery, export and price, with advice on which one fits whom.
Best password managers for business and teams in 2026
Bitwarden, 1Password, Keeper, NordPass, Dashlane and Proton Pass compared for teams: SSO, SCIM, audit logs, EU hosting, recovery, certificates and per-user price.
Best password managers for families in 2026
Family plans compared: 1Password, Bitwarden, Proton Pass, NordPass, Dashlane and Keeper. Seats, shared vaults, recovery and price for households in Europe.