Otter

Your two-factor codes. Your phone. Nothing else.

Otter turns the keys your services give you into six-digit codes, on your device, and keeps them encrypted the rest of the time. No account, no cloud, no telemetry.

Download on theApp StoreGet it onGoogle Play

Free on iOS and Android

See how it works

482 913

Why Otter

Nothing leaves the device

Codes are generated on your phone from keys stored on your phone. There is no account to create and no server to trust, because there is no server.

Encrypted while you are not looking

Every key is encrypted with AES-256-GCM. The key that unlocks them is held by the phone’s own secure hardware, behind your fingerprint, your face or a PIN.

A backup you control

Export a single encrypted file and keep it wherever you like. Otter has no copy and no way to open it without the passphrase you chose.

Standard codes, standard keys

TOTP and HOTP, exactly as specified in RFC 6238 and RFC 4226. Anything you add to Otter works in any other authenticator, and vice versa.

See it work

A demonstration account, generated for this page. Scan it with Otter (or with any other authenticator) and the six digits on your phone should match the ones here, changing together every thirty seconds.

Scan this with Otter

What your phone should show

••• •••

New code in 30s

Or type the key
JBSWY3DPEHPK3PXPJBSWY3DPEHPK3PXP

This key is published on a public web page, so it protects nothing. It is here to be scanned and then deleted.

How it keeps things safe

Otter is small on purpose. Every key is encrypted before it touches the disk, nothing is ever sent anywhere, and the parts that matter are tested against real cryptography. Here is what that means in practice.

Encrypted, and bound to its account

Each key is sealed with AES-256-GCM under a random data key, with a fresh nonce every time. The ciphertext is tied to the account it belongs to, so it cannot be moved or swapped without being noticed.

Unlocked by you, on this phone

The data key is wrapped by the secure hardware of the phone, behind your fingerprint, your face or a PIN. Wrong PIN attempts slow down and the delay survives a restart.

No network, no silent updates

Otter makes no requests. The Android build does not even hold the internet permission, and there is no over-the-air update mechanism: every change ships through store review.

A backup only your passphrase opens

The backup file is encrypted with a key derived from your passphrase using scrypt at 64 MB. The parameters travel inside the file, so they can be raised later without stranding an old backup.

What this does not protect against

An authenticator that overstates its guarantees is worse than one that is honest. Otter cannot help you if:

  • the phone is rooted or jailbroken, or its memory is read while the vault is unlocked;
  • the operating system or the keyboard is compromised;
  • you are coerced into unlocking it;
  • the PIN or the backup passphrase is easy to guess.

Questions that come up

Otter is a personal project maintained by one person, so replies may take a few days.

I lost my phone. Can I get my codes back?

Only from a backup you exported yourself. Otter has no copy of your keys, so there is nothing to restore from on our side. If you have a backup file and its passphrase, install Otter on the new phone and import it.

I forgot my PIN.

If you also set up biometrics, unlock with those and change the PIN in settings. If the PIN was your only unlock method, the keys cannot be recovered, and that is what makes the PIN meaningful. Restore from a backup, or reset two-factor authentication with each service.

Otter stopped accepting my fingerprint after I added a new one.

Android discards keys held behind biometrics when the enrolled set changes. This is the operating system protecting you, not a fault. Unlock with your PIN and set biometrics up again. It is why Otter encourages adding a PIN alongside biometrics.

My codes are being rejected.

Time-based codes depend on your phone’s clock. Check that automatic date and time are enabled in system settings; a clock that is more than thirty seconds out will produce codes the service refuses.

Can I move my accounts from another authenticator?

Yes, if the other app can show you each account’s QR code or key. Otter reads standard otpauth setup codes, so anything another authenticator can export as a QR code can be scanned straight in.

Is there a way to see my keys again after adding them?

No. Otter shows codes, never the underlying keys, so that a glance at your screen cannot give someone permanent access. Use an encrypted backup if you need to move accounts elsewhere.

How do I report a problem?

Write to otter@foohx.com. For a security issue, please report it privately rather than in public. Never include a two-factor key, a backup file or a screenshot showing a code in a message to anyone, including us.

Keep the otter caffeinated

Otter is free, has no ads and will never sell anything. It is built and maintained by one person in the evenings. If it saves you a headache, a coffee is the nicest way to say so.

Buy me a coffee

No account, no subscription. Just a coffee.

Ready when you are

Install Otter, scan your first QR code, and your codes never leave your hand again.

Download on theApp StoreGet it onGoogle Play