A calmer way to handle 2FA

Every code,
visible at a glance.

Spot Auth turns your one-time codes into a clear, living grid. Find the right account, see its remaining time, and copy — in seconds.

Local-firstNo ads or tracking
TOTP · 18s
AES-256
Spot Auth authenticator screen
01Open. Spot. Copy. Done.
01Local-first
02No ads or tracking
03Open OTP standards
Designed for the five-second task

Security that stays out of your way.

A privacy-first authenticator with deliberate motion, fast scanning, and practical migration tools.

01

See time, not a timer

A signature progress ring shows exactly when each TOTP code will refresh.

02

Tap once to copy

Choose an account from the grid and copy the large code from the same screen.

03

Import without friction

Scan QR codes or import from Google Authenticator, Aegis, 2FAS, CSV, JSON, and otpauth links.

04

Encrypted by default

Secrets are encrypted with AES-256-GCM and stored in the device Keychain.

05

Your cloud, your choice

Optional encrypted sync uses your iCloud Drive or your own WebDAV storage.

06

Works offline

Code generation is local. Network icons and cloud sync can be disabled at any time.

Spot Auth code grid
30SEC
One clear rhythm

Open. Spot. Copy. Done.

The golden-ratio layout keeps the selected code above and your complete account grid below — no hunting through lists.

  1. 01Unlock with Face ID
  2. 02Spot the service ring
  3. 03Tap to reveal the code
  4. 04Copy and continue
Built for trust

Your secrets do not become our data.

Spot Auth has no official account system and no official data server. Core code generation stays on your device.

Keychain isolation

OTP secrets are kept separate from ordinary app metadata and encrypted at rest.

Biometric lock

Face ID, Touch ID, or the device passcode protects access when the app opens.

Portable by design

Standard OTP formats and exports help you move without being locked into one app.

Privacy
/ DOWNLOAD

One identity. Every platform.

The iOS app is first. Android and Chrome are being prepared so your secure workflow can follow you everywhere.

/ FAQ

Questions, answered.

No. Core use requires no Spot Auth account and no official server.

On your device, encrypted with AES-256-GCM and stored in Keychain. Optional sync writes an encrypted file to storage you choose.

Check the selected account, confirm the secret was entered correctly, and make sure your phone time is set automatically.

Yes. Create an encrypted backup or enable cloud sync first, then import on the new device.

Spot Auth

Make 2FA feel effortless.

Spot Auth for iPhone is coming soon. Store links will appear here when each release is ready.

This download link is reserved and will be enabled at release.