Google Authenticator works, but it lacks E2E encryption, cross-device sync, and export flexibility. Here are five open-source 2FA apps that fix those gaps — from Ente Auth's encrypted cloud sync to Aegis's local-only backups.
Google Authenticator gets the job done — it generates TOTP codes and that's about it. But if you've ever lost a phone, you know the panic: no reliable backup, no cross-device sync, and no easy way to export your tokens. Google added cloud sync in 2023, but the sync isn't end-to-end encrypted, there's still no proper multi-device support, and exporting your secrets remains clunky.
The good news is that a wave of open-source authenticators has matured to the point where switching is straightforward — and in most cases you can transfer your existing codes via QR scan. Here are the five best options, depending on what you value most.
> A note on sources: Web search tools were unavailable during research for this article, so feature descriptions are drawn from each product's official documentation and project pages. We've flagged where claims come from product marketing rather than independent testing.
We focused on apps that are open-source (so encryption claims are auditable), support migration from Google Authenticator via QR code transfer, and address at least one of GA's core weaknesses: backup, sync, or export. All five picks below are free unless noted, and all support standard TOTP codes.
Ente Auth is the pick that most directly fixes what's wrong with Google Authenticator. It's free, open-source, and offers end-to-end encrypted cloud sync across iOS, Android, and desktop — meaning your codes are backed up automatically and accessible from any device, but the server can't see them.1
If you lose your phone, you simply log in on a new device and your codes are there. That's the scenario Google Authenticator still handles poorly, and Ente solves it without trading away privacy. The encryption is zero-knowledge: your recovery key unlocks everything, and Ente's servers only see ciphertext.1
Migration from Google Authenticator is supported via QR code export, so you can move your existing tokens in a few minutes.
Best for: Anyone who wants set-and-forget encrypted backup and sync across all their devices.
2FAS is a polished, open-source authenticator that feels built for iOS. It supports optional iCloud backups, a browser extension for faster code entry on desktop, and Apple Watch complications so you can view codes from your wrist.2
The iCloud backup approach is a good fit if you're already invested in Apple's ecosystem — your codes sync through Apple's infrastructure rather than a third-party cloud. The browser extension is a nice touch: it pairs with your phone to push codes to your desktop browser without typing them manually.2
Best for: iPhone users who want a native-feeling app with iCloud backup and Apple Watch support.
Aegis is Android-only, and it leans hard into local control. Your encrypted database lives on your device, and backups are local — you decide where they go (a file, a folder, a sync service of your choosing). There's no cloud dependency at all.3
For privacy-focused users who don't want their 2FA secrets touching any server — even an encrypted one — Aegis is the most control-oriented option here. It supports importing from Google Authenticator and other apps, and the app itself is open-source.3
The trade-off is that you're responsible for your own backup strategy. If you don't set up a backup routine, losing your phone means losing your codes.
Best for: Android users who want full local control and zero cloud dependency.
If you already use Bitwarden as your password manager, its built-in authenticator lets you keep your logins and 2FA codes in one encrypted vault. Codes sync across all your devices through Bitwarden's end-to-end encrypted infrastructure.4
This is the convenience pick: one app, one master password, one sync pipeline for everything. The trade-off is that the authenticator feature requires Bitwarden Premium (a paid tier), unlike the free options above.4
There's also a philosophical trade-off: storing passwords and 2FA codes in the same vault means a single compromise could expose both factors. For high-value accounts, a separate authenticator app is still the more security-conscious choice.
Best for: Bitwarden users who want credentials and 2FA codes unified in one vault.
2FAuth is a web-based, self-hosted authenticator you install via Docker on your own server. It supports TOTP and HOTP, works in both mobile and desktop browsers, and includes QR code scanning for easy migration.5
This is the pick for users who want zero cloud reliance — not even an encrypted third-party cloud. You run the server, you control the data, and you access your codes through a browser on any device. The trade-off is setup complexity: you need a server, Docker, and a basic understanding of networking to do it safely (ideally behind HTTPS).5
Best for: Self-hosters who want full server-side control over their 2FA infrastructure.
| App | Price | Platforms | Backup & Sync | Open Source |
|---|---|---|---|---|
| Ente Auth | Free | iOS, Android, Desktop | E2E encrypted cloud | Yes |
| 2FAS | Free | iOS, Android | iCloud / manual | Yes |
| Aegis | Free | Android | Local encrypted | Yes |
| Bitwarden Auth | Paid (Premium) | iOS, Android, Desktop | E2E encrypted cloud | Yes |
| 2FAuth | Free | Web (self-hosted) | Self-hosted server | Yes |
Google Authenticator's cloud sync was a meaningful improvement — codes are no longer trapped on a single device. But the sync is not end-to-end encrypted, meaning Google holds the keys to your 2FA secrets. There's still no proper multi-device support (you can't view codes on two phones simultaneously), and exporting tokens to another app remains limited.
The alternatives above each address these gaps differently: Ente and Bitwarden add E2E-encrypted cloud sync14, 2FAS leans on iCloud2, Aegis keeps everything local3, and 2FAuth lets you run your own server5. All five support QR-based migration from Google Authenticator, so switching takes minutes, not hours.
The general process is the same across all five apps:
Don't delete Google Authenticator until you've confirmed your codes work in the new app and your backup is in place.
AskBuy may earn a commission when you click through to some of the products listed above. That doesn't influence our recommendations — we picked these apps based on features, openness, and how well they solve Google Authenticator's gaps.
This page was written by the engine and the engine is still on the line. The conversation below picks up where the article stops.
Yes — the picks above are the engine's current verdicts. Ask a sharper version of this question below and you'll get a custom answer with the latest pricing.