Features

Everything you expect from an authenticator. And more.

NexKey covers the whole authenticator workflow — provisioning, secure storage, offline generation, and getting your accounts onto a new device safely.

Works with services that support standard authenticator apps

  • Google
  • Microsoft
  • GitHub
  • AWS
  • Cloudflare
  • Dropbox
TOTP / HOTP compatible

Core capabilities

Offline OTP generation

Codes are computed on-device. No network, no server round-trip.

QR code scanning

Add an account by scanning the otpauth QR code a service shows you.

Manual key setup

Paste a Base32 secret and set digits, algorithm, and period yourself.

TOTP and HOTP

Time-based and counter-based codes, per RFC 6238 and RFC 4226.

Touch ID / Face ID

Unlock the vault with biometrics. Fall back to your device passcode.

macOS Menu Bar

Copy the current code from the menu bar without opening the app.

Secure clipboard

Copied codes are cleared from the clipboard after 30 seconds.

Account search

Find an account by issuer or username in a keystroke.

Encrypted backup

Export an encrypted vault file you can restore on a new device.

Encrypted sync

Keep phone and Mac in sync. The backend only ever sees ciphertext.

Trusted devices

A new device must be approved from an existing trusted device.

Device revocation

Lost a device? Revoke it and its key stops working immediately.

In depth

How the pieces fit together.

Offline by design

OTP codes are generated directly on your device. Internet access is not required.

Secure local storage

Secrets are protected using platform security such as Keychain and Android Keystore.

Every device

Use NexKey from your phone and Mac without changing your authentication workflow.

Open standards

Compatible with TOTP, HOTP, and standard otpauth provisioning.

Standards

Open standards, not a proprietary format.

Because NexKey implements the published specifications, your accounts are not locked to it.

RFC 6238 TOTP Time-based one-time passwords, 30-second default period. Read the specification
RFC 4226 HOTP Counter-based one-time passwords. Read the specification
RFC 4648 Base32 Secret encoding used by otpauth provisioning. Read the specification
otpauth:// QR Provisioning Standard URI scheme encoded in setup QR codes. Read the specification
SHA-1 Default digest The digest most services still issue for TOTP secrets.
SHA-256 Extended digest Supported for services that issue stronger digests.
SHA-512 Extended digest Supported for services that issue stronger digests.

Roadmap

More than OTP.

What is shipping today, and what we are building next. Anything not marked available has not shipped yet.

Today
  • TOTP and HOTP Available
  • Encrypted sync Available
  • Trusted devices Available
Next
  • Passkeys Planned
  • Push approval Planned
Later
  • Transaction approval Coming later
  • Enterprise device policy Coming later

One key. Every device.

Secure your accounts with NexKey on mobile and Mac.

  • iPhone · Coming soon
  • Android · Coming soon
  • macOS · Coming soon