---
title: Aegis Authenticator
canonical: https://saasranked.com/software/aegis-authenticator/
category: Authenticator Apps
points: 48
rank: 7 of 12
facts_checked: 2026-10-08
---

# Aegis Authenticator

Free, open-source Android app for two-factor codes, with an encrypted vault and automatic backups.

48 points out of 100. #7 of 12 authenticator apps. Vendor: Beem Development. Website: https://getaegis.app/

- The app is free and runs on Android only, from Google Play and F-Droid [1][2].
- Source code is public under GPL-3.0 [2].
- The vault is encrypted with AES-256-GCM, unlocked by a password or biometrics [2][3].
- Automatic backups go to a location you choose, including cloud storage that Android can reach, such as Nextcloud [2][4].
- It imports from 11 other authenticator apps, including Google Authenticator, Authy and 2FAS [2].

Verdict: Aegis suits Android users who want free, open-source code and control over their backups [1][2]. Backups can go to cloud storage you choose, and the vault is locked with a password you hold [3][4]. The catch: it runs only on Android, and its pages publish no outside audit, bug bounty or multi-device sync [1][2][6]. Best for: Android users who want an open-source app and control over where backups go.

## Points

| Criterion | Line | Value | Points | Note |
|---|---|---|---|---|
| Security and trust | End-to-end encrypted backup | Not published | 0/12 | Automatic backups are copies of the vault, which is encrypted only if you set a password; pages do not say backups are encrypted [2][3][4]. |
| Security and trust | Independent audit, 2023 or later | Not published | 0/10 | Not published on the project's site or README [1][2]. |
| Security and trust | Open-source apps | Yes | 6/6 | Licensed under GNU GPL v3.0 on GitHub [2]. |
| Security and trust | Public bug bounty | Not published | 0/3 | Not published; the repository's security page shows no security policy and mentions no bounty [6]. |
| Security and trust | App lock | Yes | 6/6 | The vault unlocks with a password or Android biometrics [2][3]. |
| Backup and recovery | Cloud backup or sync | Yes | 10/10 | Automatic backups can go to any cloud provider that supports Android storage access, such as Nextcloud, with no sync built in [4]. |
| Backup and recovery | Same codes on several devices | Not published | 0/7 | Not published on the project's site or README [1][2]. |
| Backup and recovery | Export all accounts | Yes | 7/7 | README lists export as plaintext or encrypted [2]. |
| Backup and recovery | Import from other apps | Yes | 6/6 | README lists 11 authenticator apps to import from, including Google Authenticator, Authy and 2FAS [2]. |
| Backup and recovery | Works without an account | Yes | 5/5 | Privacy policy says the app collects no data from your device; no sign-up or account is described [5]. |
| Systems | Apps | Android | 2/12 | Distributed on Google Play and F-Droid; the README says Android only [1][2][4]. |
| Features | Stores passkeys | Not published | 0/3 | Not published on the project's site or README [1][2]. |
| Features | Sign-in approval prompts | Not published | 0/3 | Not published on the project's site or README [1][2]. |
| Features | Counter-based (HOTP) codes | Yes | 3/3 | README says it supports HOTP and TOTP [2]. |
| Features | Folders, tags or search | Yes | 3/3 | README lists grouping entries and searching by name or issuer [2]. |
| Price | Cost with backup on two devices | Not published | 0/4 | Free, but no page documents the same codes on two devices, so the condition is not met [1][2]. |

## Plans

| Plan | Price | Per month (USD) |
|---|---|---|
| Free | Free [1] | $0 |

## Strengths

- Free, with source code public under GPL-3.0 [2].
- Vault master key is wrapped by a key derived from your password with scrypt [3].
- Handles both time-based and counter-based (HOTP) codes [2].
- Imports from many apps and exports in plaintext or encrypted form [1][2].

## Limits

- Android only; there is no iOS, desktop or web app [1][2].
- No outside audit is published on the project's pages [1][2].
- No documented way to use the same codes on two devices at once [1][2].
- No push approval prompts or passkey storage are listed [1][2].

## Concerns

- Aegis's own GitHub advisory (Sept 6, 2026, rated High) says a crafted icon pack could overwrite internal files, including the vault, if imported; fixed in 3.4.3 [7].

## Sources

1. [Aegis Authenticator](https://getaegis.app/), Beem Development, accessed 2026-10-08
2. [beemdevelopment/Aegis](https://github.com/beemdevelopment/Aegis), GitHub, accessed 2026-10-08
3. [Aegis vault format and security design (docs/vault.md)](https://github.com/beemdevelopment/Aegis/blob/master/docs/vault.md), GitHub, accessed 2026-10-08
4. [Aegis Authenticator on F-Droid](https://f-droid.org/packages/com.beemdevelopment.aegis), F-Droid, accessed 2026-10-08
5. [Aegis privacy policy](https://getaegis.app/privacy), Beem Development, accessed 2026-10-08
6. [Aegis security page](https://github.com/beemdevelopment/Aegis/security), GitHub, accessed 2026-10-08
7. [Arbitrary file overwrite via maliciously crafted icon pack (GHSA-fw8c-jmjv-q6xf)](https://github.com/beemdevelopment/Aegis/security/advisories/GHSA-fw8c-jmjv-q6xf), GitHub, accessed 2026-10-08
