Secure 2FA code client of 2FAuth server that works offline
About this app
Pocket2FA is a mobile companion for the 2FAuth self-hosted two-factor authentication web application. It generates TOTP and Steam codes locally on your device while synchronizing with your own 2FAuth server.
Features
• Generates TOTP and Steam OTP codes locally — secrets never leave your device
• Encrypted storage using platform security (Android Keystore)
• Optional biometric authentication (fingerprint / face recognition)
• Real-time code refresh with countdown timer
• Privacy mode: hide codes by default, reveal with long-press
• One-tap copy to clipboard
• Group organisation for easy browsing
• Service icon support
• QR code scanning (camera or gallery image)
• Multiple 2FAuth server support
Requirements
A self-hosted instance of 2FAuth is required. This app does not work as a standalone 2FA manager — it is a native client that extends 2FAuth.
Disclaimer: Independent companion app. I am not the author of 2FAuth.
Licensed under AGPL-3.0-only, by Germán Martín.
What's New in v0.9.16
Imported from the F-Droid repository index.
Version history
Jul 5, 2026 · 25 MB · Android API 24–36 · code 273
Imported from the F-Droid repository index.
SHA-256 8dc06da5683aad5d6651db7b46d4e86a9c9980328a8b2596a6a7ab884be7d063
Jul 5, 2026 · 23.5 MB · Android API 24–36 · code 272
Imported from the F-Droid repository index.
SHA-256 3a525a16b0b949c6e8543cdad8a3198b93a4ae8bf390387e660f6489a2e0aad9
Jul 5, 2026 · 21.2 MB · Android API 24–36 · code 271
Imported from the F-Droid repository index.
SHA-256 d1aeb332343dd553a714daa7484842af6e560d04c0462d0912810721dd2ff1a3
Will it run on your device?
92%
- Runs on a broad range of modern Android versions.
- Multiple CPU architectures are covered.
- Aligned with the latest Android target SDK expectations.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be net.gmartin.pocket2fa is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 0.9.16 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Pocket2FA first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Pocket2FA, and a listing is removed when the evidence for it stops holding up.
Get Pocket2FA
Every source we list for net.gmartin.pocket2fa is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
8dc06da5683aad5d6651db7b46d4e86a9c9980328a8b2596a6a7ab884be7d063
Signing certificate
db4737b51964dec5aae1d67b792dddfd774fa02b483e395baa4e3b0eb528c9e3
Permissions Required
What each permission lets Pocket2FA do. A highlighted one is worth a second look — not necessarily wrong, just worth asking whether this app needs it.
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
More Security Privacy apps
More from F-DroidReport a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.