Secure authentication. Every device.

Your keys. Your codes. Your devices.

A secure authenticator for mobile and Mac with offline OTP generation, biometric protection, and encrypted synchronization across trusted devices.

Coming soon for iPhone, Android and macOS

Works with services that support standard authenticator apps

  • Google
  • Microsoft
  • GitHub
  • AWS
  • Cloudflare
  • Dropbox
TOTP / HOTP compatible

Offline by design

OTP codes are generated directly on your device. Internet access is not required.

Secure local storage

Secrets are protected using platform security such as Keychain and Android Keystore.

Every device

Use NexKey from your phone and Mac without changing your authentication workflow.

Open standards

Compatible with TOTP, HOTP, and standard otpauth provisioning.

One authenticator. Multiple ways to use it.

Large, readable codes with a countdown for each account. Codes are generated offline.

A native Mac app with folders, search, and one-click copy. Same vault, same codes.

Get a code without opening the full app.

See every trusted device. Approve new ones or revoke access instantly.

Everything an authenticator should do.

Nothing it shouldn't.

Offline OTP generation

Codes are computed on-device. No network, no server round-trip.

QR code scanning

Add an account by scanning the otpauth QR code a service shows you.

Manual key setup

Paste a Base32 secret and set digits, algorithm, and period yourself.

TOTP and HOTP

Time-based and counter-based codes, per RFC 6238 and RFC 4226.

Touch ID / Face ID

Unlock the vault with biometrics. Fall back to your device passcode.

macOS Menu Bar

Copy the current code from the menu bar without opening the app.

Secure clipboard

Copied codes are cleared from the clipboard after 30 seconds.

Account search

Find an account by issuer or username in a keystroke.

Encrypted backup

Export an encrypted vault file you can restore on a new device.

Encrypted sync

Keep phone and Mac in sync. The backend only ever sees ciphertext.

Trusted devices

A new device must be approved from an existing trusted device.

Device revocation

Lost a device? Revoke it and its key stops working immediately.

Sync without giving up control.

Secrets are encrypted on your device before they leave it. The backend stores ciphertext it cannot read; only a trusted device holding the key can decrypt it.

  1. iPhone Secrets live in the Secure Enclave–backed Keychain.
  2. Encrypt locally Vault is encrypted with a key that never leaves the device.
  3. Encrypted Vault Backend stores ciphertext. It has no key to read it.
  4. Trusted Mac Only devices you approved hold a decryption key.
  5. Decrypt locally Plaintext exists only in memory on the trusted device.
Encrypted on device Ciphertext in cloud Decrypted on trusted device

Security starts on your device.

NexKey is designed so that the most sensitive material — your OTP secrets — never needs to exist in plaintext anywhere except inside platform-secure storage on hardware you control.

  • Local OTP generation

    Codes are computed on-device from the stored secret and the current time or counter.

  • Platform-secure secret storage

    iOS and macOS Keychain, Android Keystore. Secrets are never written to plain files.

  • Touch ID / Face ID protection

    Biometric unlock gates access to the vault; the OS enforces it.

  • End-to-end encrypted sync

    Encryption happens before upload with a device-held key.

  • Trusted device approval

    New devices join only after approval from an existing trusted device.

  • No plaintext OTP secrets in the backend

    The server stores ciphertext and metadata it cannot decrypt.

Read the security model

Built on open standards.

NexKey works with services that already support standard authenticator applications.

RFC 6238 TOTP Time-based one-time passwords, 30-second default period. Read the specification
RFC 4226 HOTP Counter-based one-time passwords. Read the specification
RFC 4648 Base32 Secret encoding used by otpauth provisioning. Read the specification
otpauth:// QR Provisioning Standard URI scheme encoded in setup QR codes. Read the specification

Available where you need it.

iOS

Coming soon
  • Face ID
  • Offline OTP
  • Encrypted sync
Coming soon

Android

Coming soon
  • Android Keystore
  • Biometric lock
  • Offline OTP
Coming soon

macOS

Coming soon
  • Touch ID
  • Menu Bar
  • QR from screen
  • Keychain
Coming soon

Your authentication data should stay private.

  • No ads
  • No OTP analytics
  • No plaintext cloud vault
  • No selling authentication data

Authenticator secrets remain on your devices unless encrypted synchronization is explicitly enabled.

How it works

  1. 01

    Scan

    Scan the QR code provided by a service.

  2. 02

    Store securely

    NexKey saves the authentication secret in platform-secure storage.

  3. 03

    Generate locally

    Codes are generated on the device every 30 seconds.

  4. 04

    Sign in

    Copy or enter the current code into the service.

One key. Every device.

Secure your accounts with NexKey on mobile and Mac.

  • iPhone · Coming soon
  • Android · Coming soon
  • macOS · Coming soon