Skip to content

Self-hosted alternatives to Microsoft Authenticator

Microsoft Authenticator is Microsoft's app for verifying sign-ins with one-time codes or approval prompts, including passwordless sign-in to Microsoft accounts. Two listed apps do its main job and run in your own Cloudflare account.

Each answer comes from the app’s README and source code, compared with the features Microsoft Authenticator describes on its own site.

  • 2FAuth Worker sign-in screen on the public demo, offering several login providers and passkey sign-in

    Self-hosted TOTP vault with AES-encrypted secrets in D1, whitelist OAuth login and an offline-capable PWA

    Deploy
    Manual
    License
    AGPL-3.0
    GitHub stars
    62 stars
    Last commit
  • 2FA desktop view in Chinese with a search bar above a four-column grid of account cards, each showing its current code

    Self-hosted TOTP and HOTP code manager with imports from other authenticators, cloud backups and browser extensions

    Deploy
    One-click
    License
    MIT
    GitHub stars
    449 stars
    Last commit

Microsoft Authenticator features, app by app

Feature2FAuth Worker2FA
Generate one-time codes for two-step verificationYesYes
Approve sign-ins with a push notificationNoNo
Passwordless sign-in to Microsoft accounts from the phoneNoNo
Store passkeys for sign-inNoNo
Back up and restore accountsYesYes
Confirm sign-ins with biometrics or a PINPartlyNo

Self-hosted TOTP vault with AES-encrypted secrets in D1, whitelist OAuth login and an offline-capable PWA

What a Microsoft Authenticator user would miss
Push approval and passwordless sign-in, which a TOTP vault does not offer.
What it adds
Codes and backups stay in your own Cloudflare account.
  • Yes Generate one-time codes for two-step verification. TOTP code generation.
  • No Approve sign-ins with a push notification. No push or approval prompts in the source.
  • No Passwordless sign-in to Microsoft accounts from the phone. Not a sign-in provider.
  • No Store passkeys for sign-in. Passkeys are used to sign in to the app itself, not stored for other sites.
  • Yes Back up and restore accounts. Backups to WebDAV, S3 or Telegram with restore.
  • Partly Confirm sign-ins with biometrics or a PIN. OAuth sign-in with passkey code present, no in-app PIN.

Sources:github.com/nodeauth/2fauth-worker/blob/main/README_EN.mdsupport.microsoft.com/en-us/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acclearn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-authenticator-app

Self-hosted TOTP and HOTP code manager with imports from other authenticators, cloud backups and browser extensions

What a Microsoft Authenticator user would miss
Push approval and passwordless sign-in, which a TOTP vault does not offer.
What it adds
Codes and backups stay in your own Cloudflare account, and browser extensions fill codes on approved sites.
  • Yes Generate one-time codes for two-step verification. TOTP and HOTP code generation.
  • No Approve sign-ins with a push notification. No push or approval prompts in the README.
  • No Passwordless sign-in to Microsoft accounts from the phone. Not a sign-in provider.
  • No Store passkeys for sign-in. No passkey storage listed.
  • Yes Back up and restore accounts. Automatic backups with restore to WebDAV, S3, OneDrive or Google Drive.
  • No Confirm sign-ins with biometrics or a PIN. One admin password, no PIN or biometric lock.

Sources:github.com/wuzf/2fa/blob/main/docs/en/README.mdsupport.microsoft.com/en-us/account-billing/about-microsoft-authenticator-9783c865-0308-42fb-a519-8cf666fe0acc