Skip to content

Self-hosted alternatives to Authy

Authy is an authenticator app from Twilio that generates two-factor codes on a phone or tablet and offers encrypted cloud backup and multi-device use. Two listed apps do its main job and run in your own Cloudflare account.

Each answer comes from the app’s README and source code, compared with the features Authy describes on its own site.

  • 2FA desktop view in Chinese with a search bar above a four-column grid of account cards, each showing its current code

    Self-hosted TOTP and HOTP code manager with imports from other authenticators, cloud backups and browser extensions

    Deploy
    One-click
    License
    MIT
    GitHub stars
    449 stars
    Last commit
  • 2FAuth Worker sign-in screen on the public demo, offering several login providers and passkey sign-in

    Self-hosted TOTP vault with AES-encrypted secrets in D1, whitelist OAuth login and an offline-capable PWA

    Deploy
    Manual
    License
    AGPL-3.0
    GitHub stars
    62 stars
    Last commit

Authy features, app by app

Feature2FA2FAuth Worker
Add accounts by scanning a 2FA QR codeYesYes
Generate one-time codes on the device, including offlineYesYes
Encrypted cloud backup protected by a password you setYesYes
Sync codes across several devicesYesYes
App lock with PIN, password or biometricsPartlyPartly
Device management for removing lost devicesNoNo

Self-hosted TOTP and HOTP code manager with imports from other authenticators, cloud backups and browser extensions

What a Authy user would miss
Per-device approval, a device list and a biometric lock, because one admin password protects the whole instance.
What it adds
It also reads HOTP, imports from Google Authenticator, Aegis, 2FAS and Bitwarden exports, ships Chrome, Edge and Firefox extensions that fill codes, and keeps data in a KV namespace in your own Cloudflare account.
  • Yes Add accounts by scanning a 2FA QR code. Camera scan, QR image upload, pasted screenshot, dragged image or a typed Base32 key.
  • Yes Generate one-time codes on the device, including offline. TOTP and HOTP codes in a PWA with offline access.
  • Yes Encrypted cloud backup protected by a password you set. Automatic backups to WebDAV, S3, OneDrive or Google Drive, encrypted with an ENCRYPTION_KEY secret you set (the key is optional)
  • Yes Sync codes across several devices. One instance used from any browser, with edits routed through a Durable Object so devices do not overwrite each other.
  • Partly App lock with PIN, password or biometrics. One admin password and a session cookie, no PIN or biometric lock.
  • No Device management for removing lost devices. No device list or per-device approval.

Sources:github.com/wuzf/2fa/blob/main/docs/en/README.mdauthy.com/features/

Self-hosted TOTP vault with AES-encrypted secrets in D1, whitelist OAuth login and an offline-capable PWA

What a Authy user would miss
Sign-in needs a configured OAuth provider, and there is no browser extension, device list or PIN lock.
What it adds
Only whitelisted accounts can sign in, a standalone script decrypts a backup file without the deployment, and a Docker image is also available.
  • Yes Add accounts by scanning a 2FA QR code. QR scanner and manual entry in the add-account screen, plus imports from other apps.
  • Yes Generate one-time codes on the device, including offline. Codes generated in the browser by an installable PWA that the README says works offline.
  • Yes Encrypted cloud backup protected by a password you set. Secrets AES-encrypted in D1, daily backups to WebDAV, S3 or Telegram, with backup files encrypted under a backup password.
  • Yes Sync codes across several devices. The same vault opens in any signed-in browser or installed PWA.
  • Partly App lock with PIN, password or biometrics. Sign-in through GitHub, Google, Telegram, Cloudflare Access, Gitee or NodeLoc, with passkey code present; no PIN lock inside the app.
  • No Device management for removing lost devices. No device list or per-device approval.

Sources:github.com/nodeauth/2fauth-worker/blob/main/README_EN.mdgithub.com/nodeauth/2fauth-worker/blob/main/backend/src/features/backup/backupService.tsauthy.com/features/