For an authenticator you can use on both Android and iPhone, consider Ente Auth, 2FAS, and Proton Authenticator. They differ most in how they handle sync, backups, and open-source coverage. Android users who prefer a locally stored vault and manual backup control should also consider Aegis, but it is not an iPhone option.
Which open-source authenticator works on both Android and iPhone?
Ente Auth, 2FAS, and Proton Authenticator are listed for both iOS and Android in the available product information. The best choice depends less on a single security label than on how you want to recover your codes if a phone is lost, replaced, or reset.
| App | Platforms noted | Sync and backup approach | Open-source scope noted | Best fit |
|---|---|---|---|---|
| Ente Auth | iOS, Android, desktop, and web, according to Ente’s comparison | Ente says it offers end-to-end encrypted sync and import/export. It says local use is possible without an account; an account enables sync. | Ente says both the client and server are open source. | People seeking cross-platform access and optional encrypted sync. |
| 2FAS | iOS, Android, and a browser extension, according to Ente’s comparison | The comparison lists Google Drive/iCloud backup and import/export. Check 2FAS’s current documentation for platform-specific backup and restore details. | Ente’s comparison identifies the client and server as open source. | People who want a mobile authenticator with a browser extension. |
| Proton Authenticator | iOS and Android, according to Proton’s support page | Proton says it can be used without an account, supports import and export, and offers end-to-end encrypted sync with a Proton account. Its support page describes encrypted backups when using an account or on iOS. | Proton describes its apps, including Proton Authenticator, as fully open source. Ente’s comparison describes the client as open source and the server as proprietary. | People who want optional account-based sync and a documented migration path. |
| Aegis | Android only, according to the Aegis project | Manual import/export, encrypted or plaintext export, and automatic vault backups to a location you choose. | The project presents Aegis as open source; Google Play identifies it as GPLv3. | Android users who want local vault control and are prepared to manage backups themselves. |
Ente’s comparison is useful for side-by-side feature claims, but Ente also makes Ente Auth. Treat its descriptions of other products as vendor-reported information, and confirm any feature you rely on with that app’s own documentation. The Proton support page and Aegis project repository provide product-specific details for those apps.
How should you compare sync, backups, and open-source claims?
Choose a recovery model you can actually use
Sync and backups solve different problems. Sync keeps an authenticator’s data available across devices through a service; a backup is a recoverable copy you can use if the app or phone becomes unavailable. Ente and Proton describe end-to-end encrypted sync options. Aegis emphasizes a local vault with manual export and automatic backups to a chosen location. Ente’s comparison lists Google Drive/iCloud backup for 2FAS; check 2FAS’s own current instructions before relying on its restore behavior.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Before choosing, ask whether you want an account-based recovery route or would rather control a backup file yourself. A local-only approach avoids relying on an authenticator account, but it also makes you responsible for storing and protecting backups. Sync is convenient, but you should understand which account and recovery steps you would need if you lost access to a device.
Check what “open source” covers
An open-source mobile app does not necessarily mean its sync server is open source. Ente’s comparison distinguishes projects that publish both client and server code from apps whose client is open but whose server is proprietary. Proton describes its apps as fully open source, while Ente’s comparison characterizes Proton Authenticator’s client as open source and its server as proprietary. Those are differing descriptions, so check the projects’ own current statements if server code availability is decisive for you.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Source availability alone does not establish that a particular app build or server deployment has been independently audited, nor does it guarantee a recovery process will work for your situation. Consider the app’s update and backup practices alongside its licensing and published code.
How do you move authenticator codes to a new app or phone?
Transfer support depends on both the app you are leaving and the one you are installing. Aegis documents imports from several authenticator apps. Proton says it can import from Google Authenticator, 2FAS, Aegis, Bitwarden Authenticator, Ente Auth, and LastPass Authenticator, and can export codes. Consult the current Aegis documentation or Proton instructions for exact steps; the available sources do not establish a universal transfer procedure across every app and operating system.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Check the source app first. Confirm that it supports export or a transfer method compatible with the destination app. Do not assume that every app can export codes in the same format.
- Set up the destination app. Install it on the new phone and follow its current import or device-transfer instructions.
- Verify access before removing anything. Test the imported codes by signing in to the relevant services while the old authenticator is still available. Keep recovery codes or another sign-in method accessible during the change.
- Make and protect a backup. Use the destination app’s supported backup method and store any exported file securely. If an export can be plaintext, treat it as sensitive account data.
- Retire the old setup only after verification. Remove old entries or wipe the old phone once you have confirmed that the new app works and that you can recover its data.
Can you back up authenticator codes without putting them in the cloud?
Yes. Aegis supports exporting its vault in encrypted or plaintext form and making automatic vault backups to a location you choose. That allows an Android user to keep a backup outside an online sync service, but the backup still needs protection: use encrypted export where appropriate, keep the password or key separate from the file, and store a copy somewhere that will survive phone loss.
Proton also documents export to a location chosen by the user, alongside its account-based sync and backup options. The precise backup behavior depends on whether you use an account and, for the documented encrypted backup case, whether you are on iOS. Review Proton’s support instructions before deciding which route fits your devices.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Which app should you choose?
- Choose Ente Auth if you want an option described as working across mobile, desktop, and web, with local use or account-enabled end-to-end encrypted sync.
- Choose 2FAS if a browser extension matters alongside a mobile app; confirm its current backup and restore details before relying on them.
- Choose Proton Authenticator if you want to start without an account, use documented import/export options, and have the option of encrypted sync with a Proton account.
- Choose Aegis if you use Android and prefer a local vault with manual control over backup storage; it does not meet a cross-platform iPhone requirement.
If you already use a password manager’s authenticator feature, Bitwarden Authenticator is another possible option: Ente’s comparison lists it for iOS and Android and describes its client as open source and local. Confirm the precise product scope and migration options before treating it as a dedicated authenticator replacement.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




