FAQs
Table of Contents
- Is 2fa compatible with alternate Android operating systems?
- How does 2fa's security compare to other popular apps?
- How do I verify that my install is genuine?
- Does 2fa have reproducible builds?
- Has 2fa had a security audit?
- Are added accounts encrypted by default?
- What happens if I forget my passphrase?
- What else does the app do to protect my privacy?
- Can I import my accounts from another app?
- Are there plans to implement cross-device sync?
- Will there ever be an iOS version of 2fa?
- How do I report a bug or security issue?
- How do I request an icon for a service?
- In what ways can I contribute to the project?
Is 2fa compatible with alternate Android operating systems?
Yes. The app was specifically designed with this in mind. It has been developed and thoroughly tested on GrapheneOS and functions fully without Google Play Services.
How does 2fa's security compare to other popular apps?
The following table compares each app, assuming the user is using a passphrase and biometrics, and is based on the source code of the latest downloadable build of each project, including any alpha, beta or release candidate versions. It was last updated in September 2026.
| Property \ Android App | 2fa by 979 | Aegis | Ente Auth | Proton Auth | 2FAS |
|---|---|---|---|---|---|
| Network Access | No | No | Yes | Yes | Yes |
| Programming Language | Rust & Kotlin | Java | Dart | Rust & Kotlin | Kotlin |
| Memory Tagging Extensions | Yes | No | No | No | No |
| Memory Zeroization | Yes | No | No | No | No |
| Hardware-Backed Biometrics | SE with TEE fallback | TEE | TEE | TEE | TEE |
| Passphrase Strength Enforcement | zxcvbn | zxcvbn | entropy | None | None |
| Key Derivation | Argon2id | scrypt | Argon2id | Argon2id | PBKDF2-HMAC-SHA256 |
| Encryption | AEGIS-256 | AES-256-GCM | XChaCha20-Poly1305 | AES-256-GCM | AES-256-GCM |
2fa by 979 requests no network permission, so it has no way to reach the internet on its own. This can be verified by checking the app's permissions or manifest.
The core is written in Rust, with the UI in Kotlin. Rust lets us clear key material from memory as soon as it is no longer needed, which most other languages cannot guarantee. The app also enables Memory Tagging Extension, which allows supported hardware to detect memory corruption bugs before they can be exploited.
When you unlock with biometrics, the key is held in the device's Secure Element, or the Trusted Execution Environment as a fallback. It cannot be used while the device is locked, every use requires you to authenticate again, and enrolling new biometrics invalidates the key entirely.
Passphrases are checked using zxcvbn and must meet a minimum strength threshold. From there, your passphrase becomes a key using Argon2id, which is costly enough to make guessing impractical. Each export uses a fresh random salt, so the same passphrase never produces the same key twice, and that key is expanded with HKDF into the key and nonce used by AEGIS-256, which encrypts your accounts.
Whatever is left is padded to a multiple of 4 KiB, so the file size gives nothing away about how many accounts you have, or whether you have any. This applies to stored accounts and exports alike.
How do I verify that my install is genuine?
If you installed 2fa from Accrescent, Google Play Store, or IzzyOnDroid, you don't need to do anything. All three verify the app's signature at install time and on every update, so anything not signed with our key is rejected.
In case you want to install the app from a mirror, you should use a tool such as AppVerifier to compare the certificate hash against the one below before installing. If it matches, the app is genuine.
E5:B2:8E:A1:E0:51:C2:32:DE:A9:4C:27:C0:59:2E:2C:00:2D:17:C5:CA:81:78:8B:51:30:6D:60:8A:FE:52:C5Does 2fa have reproducible builds?
Yes. All releases are built on Archlinux LTS and are fully reproducible. We have also tested compilation on Ubuntu LTS and Debian Stable, which yielded the same result.
Has 2fa had a security audit?
2fa has not undergone an independent security audit. However, the source code is public and the builds are reproducible, allowing anyone to review the code independently. While we would like to arrange a third-party audit, we currently lack the funding to do so.
Are added accounts encrypted by default?
Android encrypts the app's private storage by default, which prevents accounts from being read. However, if your device is seized or stolen, forensic tools can expose saved accounts. If this is a concern, you can set a passphrase. Your accounts will then be encrypted with a key only you know and will remain inaccessible until you enter it.
What happens if I forget my passphrase?
You permanently lose access to the app and the accounts stored inside. When adding an account, you are usually asked to save recovery codes. If you did not save them, you most likely won't ever get those accounts back. However, if the account is with a service that can verify your identity, such as a bank, you may be able to recover it through their support process.
What else does the app do to protect my privacy?
There are a few features to keep your information from leaking in ways you might not expect.
- Incognito Keyboard: Your keyboard normally remembers what you type to improve its predictions, which means anything you enter, including account names, issuers, or notes, could end up in its dictionary. This is why the feature is enabled by default and cannot be turned off.
- Secure Clipboard: When you copy a code, your system may display it in clipboard previews and suggestions, or even sync it to other devices. Copied codes are marked as extra sensitive so the system knows to hide them. This feature can be enabled in Settings.
- Lock on Exit: When the app goes into the background, sensitive information is securely wiped from memory, so once the app is opened again you will be required to re-authenticate. This feature is only available if you have set a passphrase, and can be enabled in Settings.
- Block Intents: Other apps can send data to yours, such as when sharing an image or a link. We use this to let you add accounts by sharing QR codes or otpauth links from other apps. Anything sent this way is data from outside the app that must be read and parsed, which creates an attack surface. Enabling this feature blocks all incoming data from other apps, closing that surface at the cost of not being able to share directly into the app.
Can I import my accounts from another app?
Yes, but as of right now only Aegis Authenticator is supported. We have attempted to implement other apps with selective account import, but it did not work the way we wanted. Still, it is something we intend to add in the future.
Are there plans to implement cross-device sync?
Yes, but it will come after the iOS version is released.
Will there ever be an iOS version of 2fa?
Yes. We plan to start iOS development later this year, with a release expected in 2027.
How do I report a bug or security issue?
Most of the time you will report issues through the 2fa Codeberg repository, but you can also report them via our Discord server. If it is a security issue, you should email us directly, following the instructions on our security page.
How do I request an icon for a service?
You can request an icon through the 2fa Codeberg repository. Create an issue naming the service you want, and include the issuer along with any relevant information, such as the service's website or media kit. This helps us represent their icon more accurately. We may not be able to include textured monochrome icons, so please specify a color if possible.
In what ways can I contribute to the project?
You can contribute in three major ways. The first is becoming a translator for the 2fa project, which directly helps us expand our reach. The second is writing a review or telling people about 2fa. The third, and most valuable, is donating to us through Monero or Ko-fi.

Address43YaGjafqvwTZKqiE22MwQ1kVKYnG679pUXQnAzkos3WK2uoqJSeu9jRpko4VzKL9tHvFYRWbTUebcDDqkKiwJAL83arU6X