One-time sign-in codes, generated on this device
A full TOTP authenticator for the accounts you sign in to everywhere else — GitHub, your bank, your work login. The secrets live encrypted on your phone and are never sent to our servers; the codes are computed locally from the clock. Behind your fingerprint, with an optional backup only your passphrase can open. A Pro & Family tool.
Illustrative preview — a look at the interface.
The problem
Authenticator apps are where people get stranded. The secrets sit on one phone with no way out, so losing the phone means losing every account at once — or they sync to a cloud account that can read them, which quietly turns your second factor into someone else’s database row.
How it works
NexGuard generates codes entirely on the device, from secrets stored in the same encrypted store as your vault. Backup is optional and client-encrypted with a passphrase only you know: the server receives a blob it cannot open, and we can’t recover it for you either. That is the honest trade, and the app says so in those words before you turn it on.
How it works
Authenticator, step by step
Unlock
Open it with the fingerprint, face or device PIN your phone already trusts — the same recent authentication that releases your vault key.
Add an account
Paste a setup key or an otpauth link, or type the service and account name yourself.
Read the code
Six digits, ticking from the wall clock with a progress bar showing the seconds left. Tap to copy.
Back it up (optional)
Choose a passphrase and sync an encrypted copy, so a new phone is a restore rather than a rebuild.
What you’ll get
Built the NexGuard way
Nothing leaves the device
The TOTP secrets are stored encrypted on the phone and the codes are computed there. There is no request in the app that sends a secret to our servers, because there is nowhere in it to put one.
Locked behind your screen lock
Codes are only shown after a biometric or device-credential unlock, and the key relocks with the app. On Android versions where the key is time-bound, NexGuard checks the key really unlocked instead of trusting the prompt.
A backup we genuinely can’t read
Encrypted with a passphrase-derived key before it leaves the phone. Only your passphrase opens it — which also means we can’t recover it if you lose it, and the app tells you that up front.
Standard codes, standard accounts
Ordinary TOTP: any service that works with a standard authenticator works here, and you can move your accounts elsewhere whenever you like.
Privacy first
Designed to protect, never to snoop
Authenticator secrets are encrypted on the device with a hardware-backed key and are never transmitted to NexGuard. Codes are derived locally from the clock. If you turn on backup, your passphrase derives a separate key on the phone and the server stores only opaque ciphertext — we cannot decrypt it, read your account names, or recover your passphrase. Removing the backup deletes that ciphertext.
How NexGuard protects your dataQuestions
Authenticator, explained
How is this different from NexGuard’s two-factor?
What happens if I lose my phone?
Can NexGuard see my codes or my accounts?
Which plans include the Authenticator?
Get early access
Get Authenticator with NexGuard
Authenticator is part of NexGuard — start on the Free plan with no card, and upgrade only if you want higher limits and the advanced engines.