Open Source & Offline

Your Codes.
Your Device.
Your Rules.

Military-grade AES-256-GCM encrypted TOTP authenticator that never touches the internet. Biometric unlock, encrypted backups, and zero data collection — by design.

VaultSpec Authenticator screenshot
Vault Encryption
AES-256-GCM
Key Derivation
SCrypt (N=32768)
Preferences
EncryptedSharedPrefs
Biometric Key
Android Keystore TEE
Backup Encryption
AES-256-GCM + SCrypt
Network Access
None (offline)

Security Features

Every feature built with a zero-trust, offline-first architecture. No compromises.

AES-256-GCM Encryption

Every secret is encrypted at rest with AES-256-GCM. Master key derived via SCrypt — brute-force resistant by design.

Biometric Unlock

Fingerprint or face unlock with hardware-backed Keystore. Your master key is sealed in the Trusted Execution Environment.

Fully Offline

Zero network calls. No telemetry, no analytics, no cloud sync. Codes generate entirely on-device using RFC 6238.

Encrypted Backups

One-tap backup to any folder. AES-256-GCM encrypted with a separate password. Auto-backup on every change.

QR Code Scanner

Add accounts instantly by scanning QR codes. ML Kit powered — fast and accurate, processes frames locally.

Dark Mode

Full dark theme support with reactive toggle. OLED-friendly blacks that save battery and look stunning.

How It Works

01

Set Password

Create a master password. A 256-bit key is derived via SCrypt and stored encrypted.

02

Add Accounts

Scan QR codes or enter secrets manually. Each secret is AES-256-GCM encrypted.

03

Generate Codes

TOTP codes are generated offline per RFC 6238. No network ever needed.

04

Stay Protected

Auto-lock, biometric unlock, encrypted backups. Your vault is always secure.

Take Control of Your Security

Open source, free forever. No accounts, no tracking, no compromise. Just military-grade encryption on your device.