Ghost Auth
Private, open-source authenticator
Two-factor codes for every account you protect. Your secrets are encrypted on your device and never leave it. No servers, no accounts, no tracking.
Free and GPL v3. iOS, Android, Chrome, Firefox and more →
Download
Install on the platforms you use. Accounts stay in sync with end-to-end encrypted device sync.
Desktop · coming soon
Features
-
TOTP codes. RFC 6238, with SHA-1, SHA-256, and SHA-512.
-
QR code scanning. Camera on mobile, screen region in the extension.
-
Manual entry. Type the secret, or paste an otpauth:// URI.
-
Encrypted storage. AES-256-GCM, with keys held in the platform keychain.
-
PIN lock with recovery codes. Argon2id-hashed, with escalating rate limiting.
-
Biometric unlock. Face ID, Touch ID, and fingerprint on iOS and Android.
-
Encrypted backups. Argon2id key derivation over AES-256-GCM.
-
Device & extension sync. QR pairing, end-to-end encrypted, mutually authenticated.
-
iCloud sync. An encrypted vault across your Apple devices, zero-knowledge to Apple.
-
Search, reorder & auto-clear. Find codes fast; the clipboard wipes itself after 30 seconds.
Privacy by architecture
Ghost Auth is offline-first. It does not use cloud APIs, collect analytics, or share data with third parties. Network activity happens only when you explicitly start device sync over your local network, or if you opt in to crash reporting.
79 languages
Ghost Auth speaks 79 languages, with full right-to-left support for Arabic, Hebrew, Farsi, and Urdu.
Open source
Ghost Auth is licensed under GPL v3. Read the code, audit the cryptography, or contribute on GitHub.