Skip to content

Flauth

F-Droid

Open source

Privacy-first, open-source TOTP authenticator for 2FA token management.

Version
1.1.0
Size
21.6 MB
Updated
May 17, 2026
Get from Download APK (v1.1.0)
Signing certificate on record

About this app

Flauth is a privacy-first, fully open-source TOTP authenticator for Android, macOS, Windows, and Linux. It provides a simple and lightweight solution for managing your 2FA (Two-Factor Authentication) tokens.

Features:

• 100% Open Source: Transparent and trustworthy code.

• Flexible Backups: Local text file export/import and WebDAV sync.

• Privacy & Security: Secrets are encrypted and stored in the device's secure element (Android Keystore).

• Modern UI: Built with Material 3, supporting adaptive light and dark modes.

Licensed under MIT, by Jiacai Liu.

OfficialSignature VerifiedOpen Source

What's New in v1.1.0

Imported from the F-Droid repository index.

  • * Add manual account entry
  • You can now add TOTP accounts by manually entering the issuer, account name, and secret key. Tap the + button on the home screen to choose between scanning a QR code or manual entry.

Version history

v1.1.0Latest
Signature continuous

May 17, 2026 · 21.6 MB · Android API 2836 · code 2002

Imported from the F-Droid repository index.

  • * Add manual account entry
  • You can now add TOTP accounts by manually entering the issuer, account name, and secret key. Tap the + button on the home screen to choose between scanning a QR code or manual entry.
USE_BIOMETRICINTERNETCAMERAUSE_FINGERPRINTnet.liujiacai.flauth.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 8e6fcaef781f4617de69701cd0b0abfc33c14cd21d4c142370e150570bcab71b

v1.0.0
Signature continuous

Jan 16, 2026 · 21.1 MB · Android API 2836 · code 2001

Imported from the F-Droid repository index.

  • * Added bottom padding to the account list on the Home screen.
  • This ensures that the last few items are no longer obscured by the Floating Action Button (FAB) or SnackBars when the list is scrolled to the bottom.
  • * Replace mobile_scanner with barcode_scan2
  • Mobile scanner is a non-free package, it's prohibited in F-Droid repository. Replaced it with barcode_scan2 which is free and open source.
USE_BIOMETRICINTERNETCAMERAUSE_FINGERPRINTnet.liujiacai.flauth.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 a8973cf98eba07f09b74f9d5f034b9eabb2c5002569574039811e0274ce946ed

Will it run on your device?

CompatibilityCheck the requirements

60%

  • Targets newer Android builds, so legacy devices may be excluded.
  • ABI coverage is focused on newer 64-bit devices.
  • Aligned with the latest Android target SDK expectations.
What changed in this release
Size delta
+0.5 MB
Added permissions
None
Removed permissions
None

Installation Guide

1

Open Settings on your Android device

2

Go to Security → Unknown sources (or Install unknown apps)

3

Enable "Allow from this source" for your browser or file manager

4

Open the downloaded APK file from your Downloads folder

5

Tap "Install" and wait for installation to complete

6

Launch the app from your home screen

Make sure to re-enable Unknown Sources restrictions after installation for security.

How to install this safely

How to verify the file you downloaded

Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.

What the signing certificate proves

Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be net.liujiacai.flauth is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.

How to roll back to an earlier version

If the current release misbehaves, 1.0.0 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Flauth first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.

Why we list sources instead of hosting everything

The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Flauth, and a listing is removed when the evidence for it stops holding up.

Get Flauth

Every source we list for net.liujiacai.flauth is legality-reviewed. Pirated or cracked builds are never offered.

Other sources

F-Droid listing

official

F-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.

Source code

verified publisher

The upstream repository this build is compiled from.

We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.

App Information

Developer
F-Droid
Category
Security Privacy
Android
9.0+
Architectures
arm64-v8a
Version
1.1.0 (code 2002)
Size
21.6 MB
Updated
May 17, 2026
Package name
net.liujiacai.flauth

Security Verification

File integrity
SHA-256 recorded
Signing certificate
Fingerprint on record
Official source
Download APK (v1.1.0)

We record provenance; we do not run malware scans. Verify the hash yourself before installing.

SHA-256 Hash

8e6fcaef781f4617de69701cd0b0abfc33c14cd21d4c142370e150570bcab71b

Signing certificate

6f089f1171a04315ff4905956c345e7fcb82a5232387e648c1c6e2af5344b22f

Permissions Required

USE_BIOMETRIC
INTERNET
CAMERA
USE_FINGERPRINT
net.liujiacai.flauth.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Previous Versions

Signature verified

The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.

Report a problem with this listing

A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.

Report a problem