28
submitted 4 months ago* (last edited 4 months ago) by Dirk@lemmy.ml to c/selfhosted@lemmy.world

Hey!

I basically want to replace the Google Authenticator app in style and functionality:

  1. List all TOTP tokens and their validity time (with a name and order I decide).
  2. Allow me to periodically or on change back up the whole thing to some off-site storage, keeping the last N backups.
  3. Have a native app for Android or an actually good PWA.
  4. Don’t do magic bullshit like fetching icons, hide tokens, etc.
  5. Be actually secure (i.e. don’t roll your own auth)
  6. Just be a TOTP manager, and nothing more! No, I’m not interested in a password manager, thank you. I also don’t want any other OTP methods I don’t use.
  7. Don’t be a one-man projects where the availability is not clear in >1 year.

Any experience is welcomed. Thank you!

Edit: Thanks for all the great ideas, I just set up 2FAuth which seems to be the most minimalist and single-feature thing to self-host. I’ll evaluate how it performs but keep a backup in Google Authenticator. It does not match #7 but it seems to be actively used by the author and gets constant updates and fixes, so it’s most likely fine, I guess.

There is a 3rd-party app for it, but this app seems to be pretty much dead (last release in July 2025 and not in any app store) – or at least not released anymore but still worked on but only in the repository.

you are viewing a single comment's thread
view the rest of the comments
[-] eager_eagle@lemmy.world 42 points 4 months ago

Aegis + syncthing for remote backups

[-] Redjard@reddthat.com 9 points 4 months ago

This. Aegis does all of the points except offsite backups. And for good reason.
The Aegis app has no network permissions at all, which is obviously a massive boost for security and privacy. And besides, off-device backuping is a nightmare.

Syncing the Aegis backups made on change to some other server is better handled by a great dedicated app. Syncthing is the best such program (by far), though for the few files involved here nextcloud would work just as well.

[-] bismuthbob@sopuli.xyz 5 points 4 months ago* (last edited 4 months ago)

I second Aegis. You can drag icons and rename tokens. You can also sort by a to z, last used, usage count, etc. Aegis supports automatic backups and can export plaintext or encrypted backup files, after which you can transfer them to other devices however you transfer other files from your phone.

The backup files work with Aegis and with several independent desktop apps depending on your OS of choice. While I haven't looked into it, that suggests that the encryption method isn't something homebrew.

As far as #6 goes Aegis doesn't try to save my passwords, encourage me to use passkeys, or suggest AI solutions. Magic bullshit is a vague qualifier, but I think Aegis is thaumaturgically inert. The 'icons' are just the first letter of the name of the token issuer by default.

The more-than-one-year lifetime is a problem with anything, including plenty of Google projects. There are over 60 contributors on github, so that's something.

[-] LastYearsIrritant@sopuli.xyz 0 points 4 months ago

Print out all the QR codes on a sheet of paper and keep them secure in a fire safe. That's really the best way to keep them backed up and secure.

[-] eager_eagle@lemmy.world 3 points 4 months ago

until you need to update them, or when you need recovery when travelling

[-] LastYearsIrritant@sopuli.xyz 1 points 4 months ago

If you need to update them, you just reprint and replace.

If you need to recover on the road, well that depends on your risk tolerance. I'm never away from home so long that it's a problem, and pretty much every service has a way to bypass 2FA in case of emergency.

this post was submitted on 10 Mar 2026
28 points (88.9% liked)

Selfhosted

60831 readers
945 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS