Privacy-first authenticator

The authenticator built for people with more than 10 accounts.

Organize hundreds of TOTP codes in vaults, spaces and nested groups — encrypted on your device, synced zero-knowledge, and never locked in.

AES-256GCM encryption
0trackers & ads
100%offline codes
Freecore, forever
— The 2FA mess

Still trusting one phone with every login you own?

Most authenticators are a flat list on a single device. That works — right up until it doesn't.

Phone lost?

Codes gone, and every account becomes a recovery ticket.

20+ accounts?

An unsearchable flat list where nothing has a place.

Work & personal?

Client codes next to your bank, one tap apart.

Want to leave?

Most apps hold your secrets hostage with no export.

KeyNesta puts all of it in order — organized, encrypted, recoverable, and yours.

— How it works

Set up once. Covered everywhere.

1

Create your vault

One passphrase becomes your encryption key. Everything is sealed on your device with AES-256-GCM.

2

Bring your codes

Scan Google Authenticator's transfer QR or import Aegis, 2FAS, JSON or CSV — with preview and undo.

3

Unlock anywhere

Face ID on your phone, passphrase on the web. Optional sync restores everything on a new device.

CreateEncryptSyncRestore
Spaces
Work34
Personal18
Clients52
Groups
▾ Infrastructure12
▸ AWS6
▾ Production3
▸ Cloudflare4
AWAWS Root
Work › Infrastructure › AWS › Production
536 194
AWAWS Prod Deploy
Clients › Acme › AWS › Production
804 227
— Organization at scale

A place for every code. A path to every place.

Vaults hold spaces, spaces hold nested groups, groups hold your accounts — and ranked search cuts through all of it in a keystroke.

  • Unlimited nested groups with breadcrumb paths
  • Tags, favorites and recently-used surfacing
  • Search across names, accounts, tags and full paths
  • Per-space security policies — strict for Production, easy for Personal
Server stores: ciphertext only — it cannot decrypt your vault
This MacBook
synced just now
iPhone 16
Face ID · synced 2 min ago
Old phone
revoked — can no longer sync
passphrase ─scrypt→ key ─wraps→ master key ─AES-256-GCM→ every object
— Zero-knowledge sync

We can't read your codes. Neither can anyone who breaches us.

Every entry is encrypted on your device before it syncs. Sign in on a new phone, enter your passphrase, and your whole vault comes back — spaces, groups, everything.

  • AES-256-GCM under a random 256-bit master key
  • Passphrase stretched with memory-hard scrypt
  • Device list with one-tap revocation
  • Portable encrypted backups that work without any account
Google Authenticator detected · 24 accounts
GitHub · dev@company.comnew
AWS · root@company.comnew
Dropbox · me@mail.comduplicate — skipped
??? · corrupted entryinvalid — flagged
18 new · 4 duplicates · 2 invalidImport 18 ↩ Undo
— Switching is the easy part

Import from Google Authenticator in minutes.

Scan the transfer QR and every account arrives with a preview — duplicates detected, invalid entries flagged, nothing skipped silently, and the whole batch undoable.

  • Google Authenticator transfer QR, Aegis, 2FAS, JSON, CSV
  • Preview before anything is saved
  • One-tap undo for the entire import
  • And the door stays open: encrypted backups + standard exports
ScanPreviewImportUndo
— And everything around it

The details that make it dependable.

Multiple vaults

Personal and company vaults on one device — separate passphrases, separate keys, cryptographically independent.

Biometric unlock

Face ID and fingerprint on mobile, with your master key in the hardware Keychain/Keystore.

Trash, not terror

Deleted entries wait 30 days for recovery. Archives keep old accounts out of the way without losing them.

Tap-to-reveal & clipboard control

Codes hidden until touched, clipboard auto-cleared — per space, so Production can be stricter.

Native apps, one engine

Web, iPhone and Android share one verified core — identical behavior and security everywhere.

Standards, not lock-in

RFC 6238/4226 TOTP & HOTP, SHA-1/256/512, 6–8 digits, custom periods. Your codes, the standard way.

— Everywhere you work

One vault. Three screens. Zero drift.

Native apps — not web wrappers — sharing one verified engine, so your codes look and behave identically on every device.

KeyNesta

Web

Full vault in any browser — nothing to install.

Available now Open the web app →
KeyNesta

iPhone

Native app with Face ID unlock and camera QR scanning.

App Store — coming soon Notify me at launch
KeyNesta

Android

Native app with biometric unlock and camera QR scanning.

Play Store — coming soon Notify me at launch
— Pricing

Free where it matters. Honest where it doesn't.

A security product you can't trust for free isn't one you should pay for. The core is free forever — no ads, no data sales, no account required.

Free

$0 forever
  • Unlimited codes, groups, tags & vaults
  • Local encryption & biometric unlock
  • Encrypted backups, import & export
  • All apps — web, iPhone, Android
Start now — no account

Premium

Coming soon
  • Zero-knowledge sync across devices
  • Automatic encrypted cloud backups
  • Smart groups & advanced policies
  • Early access to new platforms
Get notified
— Questions

Frequently asked questions

Is KeyNesta free?

Yes. Unlimited TOTP and HOTP accounts, unlimited groups and tags, local encrypted storage, encrypted backups, and import/export are free forever — with no ads. Optional premium features like cross-device sync fund the product instead of your data.

Can KeyNesta see my 2FA codes?

No. Secrets are encrypted on your device with AES-256-GCM under a key derived from your passphrase with scrypt. The sync server only ever stores ciphertext — it cannot decrypt your vault, and neither could anyone who compromised it.

What happens if I lose my phone?

With encrypted sync enabled, sign in on a new device, enter your vault passphrase, and your entire vault — spaces, groups, tags, everything — is restored. Prefer no account? Portable encrypted backup files do the same job offline. A lost phone is not a lost identity.

How do I switch from Google Authenticator?

Open Google Authenticator → Transfer accounts → Export, then scan the QR with KeyNesta. You get a full preview with duplicate detection before anything is saved, and the whole import can be undone with one tap. Aegis, 2FAS, JSON and CSV work too.

Does it work offline?

Always. Codes are generated on-device using standard TOTP (RFC 6238); no internet connection is ever required to see your codes. Sync and backups are optional additions, never dependencies.

Can I keep work and personal codes separate?

Two ways. Spaces organize accounts inside one vault, each with its own security policy. For hard separation, create multiple vaults — each has its own passphrase, encryption key and optional sync account, and unlocking one reveals nothing about another.

Your authentication, organized.

Organize. Encrypt. Sync. Own your two-factor authentication — and leave whenever you want.

Free forever · No account needed · No ads