In final testing

NexGuard isn’t on Google Play yet. Join early access and we’ll send the install link the day it opens.

Home Features Authenticator
AvailablePro · Family

One-time sign-in codes, generated on this device

A full TOTP authenticator for the accounts you sign in to everywhere else — GitHub, your bank, your work login. The secrets live encrypted on your phone and are never sent to our servers; the codes are computed locally from the clock. Behind your fingerprint, with an optional backup only your passphrase can open. A Pro & Family tool.

Illustrative preview — a look at the interface.

NexGuard AuthenticatorPreview
GitHub
you@example.com
481 206
Refreshes in 22s
Cloudflare
you@example.com
905 447
AWS root
ops@example.com
336 178
Encrypted backup
Your passphrase only — we can’t read it
ON
Why it matters

The problem

Authenticator apps are where people get stranded. The secrets sit on one phone with no way out, so losing the phone means losing every account at once — or they sync to a cloud account that can read them, which quietly turns your second factor into someone else’s database row.

The NexGuard approach

How it works

NexGuard generates codes entirely on the device, from secrets stored in the same encrypted store as your vault. Backup is optional and client-encrypted with a passphrase only you know: the server receives a blob it cannot open, and we can’t recover it for you either. That is the honest trade, and the app says so in those words before you turn it on.

How it works

Authenticator, step by step

01

Unlock

Open it with the fingerprint, face or device PIN your phone already trusts — the same recent authentication that releases your vault key.

02

Add an account

Paste a setup key or an otpauth link, or type the service and account name yourself.

03

Read the code

Six digits, ticking from the wall clock with a progress bar showing the seconds left. Tap to copy.

04

Back it up (optional)

Choose a passphrase and sync an encrypted copy, so a new phone is a restore rather than a rebuild.

What you’ll get

Built the NexGuard way

Nothing leaves the device

The TOTP secrets are stored encrypted on the phone and the codes are computed there. There is no request in the app that sends a secret to our servers, because there is nowhere in it to put one.

Locked behind your screen lock

Codes are only shown after a biometric or device-credential unlock, and the key relocks with the app. On Android versions where the key is time-bound, NexGuard checks the key really unlocked instead of trusting the prompt.

A backup we genuinely can’t read

Encrypted with a passphrase-derived key before it leaves the phone. Only your passphrase opens it — which also means we can’t recover it if you lose it, and the app tells you that up front.

Standard codes, standard accounts

Ordinary TOTP: any service that works with a standard authenticator works here, and you can move your accounts elsewhere whenever you like.

Privacy first

Designed to protect, never to snoop

Authenticator secrets are encrypted on the device with a hardware-backed key and are never transmitted to NexGuard. Codes are derived locally from the clock. If you turn on backup, your passphrase derives a separate key on the phone and the server stores only opaque ciphertext — we cannot decrypt it, read your account names, or recover your passphrase. Removing the backup deletes that ciphertext.

How NexGuard protects your data

Questions

Authenticator, explained

How is this different from NexGuard’s two-factor?
Two-factor protects your NexGuard account — you sign in to us with a code. The Authenticator is for every other service: it generates the codes you use to sign in to GitHub, your bank, your work login.
What happens if I lose my phone?
If you turned on the encrypted backup, install NexGuard on the new phone, restore with your passphrase and your accounts come back. If you didn’t, the secrets were only ever on the old device — use each service’s own recovery codes. We can’t recover them for you, by design.
Can NexGuard see my codes or my accounts?
No. Secrets are encrypted on the device and codes are computed there. A backup is encrypted before it leaves the phone with a key derived from your passphrase, which we never receive.
Which plans include the Authenticator?
The Authenticator is a Pro and Family tool. Two-factor on your NexGuard account, including one-time recovery codes, is free on every plan.

Get early access

Get Authenticator with NexGuard

Authenticator is part of NexGuard — start on the Free plan with no card, and upgrade only if you want higher limits and the advanced engines.