A calmer way to handle 2FA

Every code,
visible at a glance.

Spot Auth turns your one-time codes into a clear, living grid. Find the right account, see its remaining time, and copy — in seconds.

Available nowApp Store
Local-firstNo ads or tracking
TOTP · 18s
AES-256
Spot Auth authenticator screen
01Open. Spot. Copy. Done.
01Local-first
02No ads or tracking
03Open OTP standards
Designed for the five-second task

Security that stays out of your way.

A privacy-first authenticator with deliberate motion, fast scanning, and practical migration tools.

01

See time, not a timer

A signature progress ring shows exactly when each TOTP code will refresh.

02

Tap once to copy

Choose an account from the grid and copy the large code from the same screen.

03

Import without friction

Scan QR codes or import from Google Authenticator, Aegis, 2FAS, CSV, JSON, and otpauth links.

04

Encrypted by default

Secrets are encrypted with AES-256-GCM and stored in the device Keychain.

05

Your cloud, your choice

Optional encrypted sync uses your iCloud Drive or your own WebDAV storage.

06

Works offline

Code generation is local. Network icons and cloud sync can be disabled at any time.

TEST AGAINST A KNOWN GOOD

Build, scan, and verify 2FA without leaving the site.

Generate standards-based TOTP and HOTP codes, create an otpauth QR, test clock drift, and export repeatable vectors. Every calculation stays in your browser.

01TOTP + HOTP02QR app check03Regression vectors
Open the 2FA test tool
Spot Auth code grid
30SEC
One clear rhythm

Open. Spot. Copy. Done.

The golden-ratio layout keeps the selected code above and your complete account grid below — no hunting through lists.

  1. 01Unlock with Face ID
  2. 02Spot the service ring
  3. 03Tap to reveal the code
  4. 04Copy and continue
Built for trust

Your secrets do not become our data.

Spot Auth has no official account system and no official data server. Core code generation stays on your device.

Keychain isolation

OTP secrets are kept separate from ordinary app metadata and encrypted at rest.

Biometric lock

Face ID, Touch ID, or the device passcode protects access when the app opens.

Portable by design

Standard OTP formats and exports help you move without being locked into one app.

Privacy
/ DOWNLOAD

One identity. Every platform.

Spot Auth for iPhone is available now. Android and Chrome are being prepared so your secure workflow can follow you everywhere.

Available nowApp Store
/ FAQ

Questions, answered.

No. Core use requires no Spot Auth account and no official server.

On your device, encrypted with AES-256-GCM and stored in Keychain. Optional sync writes an encrypted file to storage you choose.

Check the selected account, confirm the secret was entered correctly, and make sure your phone time is set automatically.

Yes. Create an encrypted backup or enable cloud sync first, then import on the new device.

Spot Auth

Make 2FA feel effortless.

Spot Auth for iPhone is available now on the App Store. Android and Chrome links will appear here when ready.

Available nowApp Store
This download link is reserved and will be enabled at release.