Free Android App — Now on Google Play

Auth Dammit

The two-factor authenticator that doesn't hate you.

Auth Dammit is a free Android application that generates TOTP-based two-factor authentication (2FA) codes for your online accounts — Google, GitHub, Microsoft, Dropbox, and any other service that supports the TOTP standard (RFC 6238). It uses Google Sign-In to securely identify you and sync your encrypted 2FA secrets across all your Android devices, so you never lose access to your accounts if you change or lose your phone.

😤 No more switching apps mid-login 🔐 End-to-end encrypted secrets ☁️ Sync across all your devices ⚡ Works offline, always

What is Auth Dammit?

Let's face it: 2FA is a necessary evil. Auth Dammit is the free Android authenticator app for people who despise authenticators. We took the traditional, isolated nature of TOTP and threw it out the window, prioritizing extreme convenience, seamless cloud syncing, and effortless sharing — while still generating standard time-based one-time passwords (TOTP) for your accounts.

What the app does

  • Generates 6-digit TOTP codes for any 2FA-enabled service
  • Works completely offline — codes generated on-device
  • Syncs encrypted 2FA secrets to the cloud for account recovery
  • Share TOTP codes with friends permanently or temporarily
  • Home screen widgets to get codes without opening the app
  • Group and reorder your codes exactly how you want them
  • Guest Mode: try generating dummy codes without signing in

How we use your Google account

Auth Dammit uses Google Sign-In for one specific purpose: to securely identify you and link your encrypted 2FA vault to your account in our database. This allows you to recover your authenticators on a new device without manual exports or backup codes.

  • We request your basic profile (name, email, user ID) to identify you
  • Your email is used only to associate your vault — we do not send marketing emails
  • We do not access Gmail, Google Drive, Contacts, or Calendar
  • We do not share your Google data with any third party
  • We do not read or store your Google account password

How we use your data

Your TOTP secret keys are encrypted on your device before being sent to our servers. We use Firebase (Google Cloud) as our backend, governed by strict security rules that allow only you to read your own data. Auth Dammit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.

Secure by design.
Convenient by default.

01

Sign in with your Google account

Auth Dammit uses Google Sign-In only to identify you. We access nothing beyond your basic profile — no Gmail, no Drive, no Contacts.

02

Scan a QR code to add an account

Add any TOTP-compatible service by scanning its QR code. Your secret key is encrypted immediately on-device before anything is stored.

03

Get your 2FA code instantly

Codes are displayed on your home screen. Works offline. Copy with one tap. No waiting, no switching apps, no loading screens.

04

Sync to any new device automatically

Got a new phone? Sign in with the same Google account. Your encrypted vault is restored instantly — no backup codes, no manual exports.

Your 2FA codes
Google Account
482 193
GitHub
731 046
0
Plaintext secrets stored
100%
TOTP standard (RFC 6238)
Devices you can sync to
<1s
Time to get your code

We care about security.
Obsessively.

We hate authentication friction — not security. Here's exactly what's protecting your data.

End-to-End Encrypted Secrets

Your TOTP seeds are encrypted on your device before syncing. We have zero knowledge of your secret keys — not even us.

Google Sign-In — Minimal Access

We use Google Sign-In only for identity. We request basic profile only (name + email). We never access Gmail, Drive, Contacts, or Calendar.

Firebase — Rule-Locked Database

Strict Firestore security rules mean only you can read or write your vault. There are no admin backdoors. Your data is yours alone.

Industry-Standard TOTP (RFC 6238)

We use the open TOTP standard — no proprietary crypto. Compatible with every 2FA-enabled service on the planet.

GDPR & DPDPA Compliant

Built for privacy compliance from day one. Request, export, or delete your data at any time. No dark patterns, no hidden data collection.

Fully Offline Code Generation

TOTP codes are computed on-device. No internet connection needed. Your codes always work — even at 35,000 feet.

Stop letting auth ruin your day.

Download Auth Dammit and experience authentication that's actually on your side.

Get it on Google Play