Open Source Microsoft Authenticator Alternatives

A curated collection of the 2 best open source alternatives to Microsoft Authenticator.

The best open source alternative to Microsoft Authenticator is Aegis Authenticator. If that doesn't suit you, we've compiled a ranked list of other open source Microsoft Authenticator alternatives to help you find a suitable replacement. Other interesting open source alternative to Microsoft Authenticator is 2FAS.

Microsoft Authenticator alternatives are mainly Password & Secret Management. Browse these if you want a narrower list of alternatives or looking for a specific functionality of Microsoft Authenticator.

Share:

A free and open source 2FA app for Android with an encrypted vault, imports from other authenticators, and backups you control.

Screenshot of Aegis Authenticator websiteRead more

Aegis Authenticator is a free, secure and open source two-factor app for Android. It exists to cover what other authenticator apps leave out, namely proper encryption and backups.

The app supports HOTP and TOTP, the industry standard algorithms, which makes it compatible with thousands of services and with anything already enrolled in Google Authenticator. The vault is encrypted with AES-256-GCM and unlocked either by a password stretched with scrypt or by biometrics through the Android Keystore.

The rest is about getting entries in and keeping them findable.

  • Adding entries: scan a QR code or an image of one, type the details manually, or import from apps such as Authy, andOTP, FreeOTP, Microsoft Authenticator and Steam, with root access needed for some.
  • Organization: alphabetic or custom sorting, grouping, advanced entry editing, search by name or issuer, and custom or automatically generated icons.
  • Screen protection: screen capture prevention and tap to reveal keep codes out of screenshots.
  • Backups: the vault exports in plaintext or encrypted form, and automatic backups go to a location of your choosing.
  • Icon packs: no pack is official, but the community maintains several and the format is documented for building your own.

Aegis is available on the Google Play Store and on F-Droid. Releases on Google Play and GitHub are signed with the same key, so an APK can be checked with apksigner against the certificate fingerprints published in the repository. The interface follows Material design with light, dark and AMOLED themes, and the project is licensed under GPL v3.

Read more

Official Android app for the Open Source 2FAS project, generating TOTP and HOTP one-time codes for any compatible service.

Screenshot of 2FAS websiteRead more

Two-factor authentication puts a second check on top of a password, and 2FAS is the free app that supplies it. This repository holds the official Android client for the Open Source 2FAS project, showing the one-time code that proves you hold the phone as well as the password.

It implements the two standard algorithms rather than a proprietary scheme, which is what makes it a drop-in for accounts you already have. Any service supporting TOTP or HOTP works with it, Google, Microsoft and Dropbox among them, and setup is a matter of following the on-screen instructions once the app is installed.

A few things are worth knowing before adopting it.

  • TOTP: time-based one-time passwords, the algorithm most services use.
  • HOTP: counter-based one-time passwords, for services that use those instead.
  • Graphics licensing: the artwork in the app is not part of the open source project and carries separate terms.
  • Security reports: vulnerabilities go to a dedicated security address rather than the public issue tracker.
  • Funding: development and maintenance are supported by donations rather than a paid tier.

Builds are downloaded from the project's releases page and installed on the device. Bug reports go through GitHub issues, where searching for an existing report first is requested, and a contribution guide covers pull requests. The code is licensed under GPL-3.0 by Two Factor Authentication Service, Inc. It suits anyone who wants an authenticator whose source they can read, rather than one tied to an account they do not control.

Read more
back

Discover Open Source alternatives to: