Organize hundreds of TOTP codes in vaults, spaces and nested groups — encrypted on your device, synced zero-knowledge, and never locked in.
Most authenticators are a flat list on a single device. That works — right up until it doesn't.
Codes gone, and every account becomes a recovery ticket.
An unsearchable flat list where nothing has a place.
Client codes next to your bank, one tap apart.
Most apps hold your secrets hostage with no export.
KeyNesta puts all of it in order — organized, encrypted, recoverable, and yours.
One passphrase becomes your encryption key. Everything is sealed on your device with AES-256-GCM.
Scan Google Authenticator's transfer QR or import Aegis, 2FAS, JSON or CSV — with preview and undo.
Face ID on your phone, passphrase on the web. Optional sync restores everything on a new device.
536 194804 227Vaults hold spaces, spaces hold nested groups, groups hold your accounts — and ranked search cuts through all of it in a keystroke.
✓✓✕Every entry is encrypted on your device before it syncs. Sign in on a new phone, enter your passphrase, and your whole vault comes back — spaces, groups, everything.
Scan the transfer QR and every account arrives with a preview — duplicates detected, invalid entries flagged, nothing skipped silently, and the whole batch undoable.
Personal and company vaults on one device — separate passphrases, separate keys, cryptographically independent.
Face ID and fingerprint on mobile, with your master key in the hardware Keychain/Keystore.
Deleted entries wait 30 days for recovery. Archives keep old accounts out of the way without losing them.
Codes hidden until touched, clipboard auto-cleared — per space, so Production can be stricter.
Web, iPhone and Android share one verified core — identical behavior and security everywhere.
RFC 6238/4226 TOTP & HOTP, SHA-1/256/512, 6–8 digits, custom periods. Your codes, the standard way.
Native apps — not web wrappers — sharing one verified engine, so your codes look and behave identically on every device.


Native app with Face ID unlock and camera QR scanning.
App Store — coming soon Notify me at launch

Native app with biometric unlock and camera QR scanning.
Play Store — coming soon Notify me at launchA security product you can't trust for free isn't one you should pay for. The core is free forever — no ads, no data sales, no account required.
Yes. Unlimited TOTP and HOTP accounts, unlimited groups and tags, local encrypted storage, encrypted backups, and import/export are free forever — with no ads. Optional premium features like cross-device sync fund the product instead of your data.
No. Secrets are encrypted on your device with AES-256-GCM under a key derived from your passphrase with scrypt. The sync server only ever stores ciphertext — it cannot decrypt your vault, and neither could anyone who compromised it.
With encrypted sync enabled, sign in on a new device, enter your vault passphrase, and your entire vault — spaces, groups, tags, everything — is restored. Prefer no account? Portable encrypted backup files do the same job offline. A lost phone is not a lost identity.
Open Google Authenticator → Transfer accounts → Export, then scan the QR with KeyNesta. You get a full preview with duplicate detection before anything is saved, and the whole import can be undone with one tap. Aegis, 2FAS, JSON and CSV work too.
Always. Codes are generated on-device using standard TOTP (RFC 6238); no internet connection is ever required to see your codes. Sync and backups are optional additions, never dependencies.
Two ways. Spaces organize accounts inside one vault, each with its own security policy. For hard separation, create multiple vaults — each has its own passphrase, encryption key and optional sync account, and unlocking one reveals nothing about another.
Organize. Encrypt. Sync. Own your two-factor authentication — and leave whenever you want.
Free forever · No account needed · No ads