Scan a setup QR or enter a key once. NexAuth generates standards-based two-factor codes offline and keeps every account secret encrypted on your device.
A focused offline authenticator: import standard TOTP accounts, find the right code instantly, and protect sensitive entries with your device lock.
RFC 6238 codes are calculated on your phone. NexAuth has no authentication server and needs no connection to generate them.
Account secrets stay in platform-protected app storage using Android Keystore or the corresponding protected iOS storage.
Hide individual authenticators and require the same fingerprint, face, PIN, or device passcode before their codes appear.
Your device is the source of truth. Authenticator secrets are stored locally, codes are generated locally, and there is no NexAuth account or mandatory cloud.
NexAuth has no ads or analytics SDKs and does not report which services you protect, which codes you view, or when you sign in.
NexAuth imports standard otpauth:// TOTP accounts. Your two-factor setup is based on an interoperable standard, not a private cloud protocol.
A second factor should reduce trust, not introduce another server you must trust.READ THE PRINCIPLES
NexAuth data is local. Clearing app storage or uninstalling removes the encrypted authenticator list from this device.
Removing the vault also removes the secrets needed to generate your codes. Confirm that every service has another recovery method first; NextEra.One cannot recover local secrets.