TOTP & HOTP codes
Standards-based 6-digit codes (RFC 4226 / 6238), generated entirely offline — no network round-trip, ever.
Xirag Authenticator generates TOTP & HOTP codes and push-approvals entirely offline, from a single security-critical core shared and audited once across every platform you use.
Every feature below runs on the same audited Rust core — Android, Apple, Windows, Linux, and Chrome all share one implementation of the cryptography that protects you.
Standards-based 6-digit codes (RFC 4226 / 6238), generated entirely offline — no network round-trip, ever.
Approve sign-ins with a tap. No codes to type, and nothing for a phishing page to intercept.
Every secret is encrypted at rest with Argon2id key derivation and ChaCha20-Poly1305 — memory-hard by design.
Split your recovery key across trusted people or devices. No single backup, and no single point of failure.
Hardware security keys for phishing-resistant sign-in — PRF-verified, and tested on real devices, not just emulators.
Face ID, Touch ID, Windows Hello, or Android Keystore/StrongBox — your vault unlocks the instant you do.
A single Rust core powers every platform. Security-critical logic is written once, reviewed once, trusted everywhere.
Optional cross-device sync built so the backend never sees an unencrypted secret — not even in memory.
Scan a QR code or paste an otpauth:// link — or enter the secret manually.
Read the rotating code, or tap Approve on a push request. Either way, nothing leaves your device.
The vault stays local and encrypted. Sync is optional — and always zero-knowledge.
Syrinx's cryptography — TOTP/HOTP, vault encryption, Shamir recovery, WebAuthn, sync — lives in a single Rust core, bound natively into each app.
Pick your platform — installation takes under a minute.