EasyAuth

EasyAuth

Open-source 2FA authenticator — works offline, data under your control, safe and reliable

Website · GitHub · Gitee · GitCode

简体中文 · 繁體中文 · 한국어

License

GitHub Download Gitee Download GitCode Download

Introduction

EasyAuth is an open-source, local two-factor authentication (2FA) app that supports WebDAV and S3 cloud backup (Nutstore, Qiniu Cloud, AWS S3, etc.), balancing data control with multi-device sync.

Built with Flutter. Official packages are currently Android only; the iOS and Windows / macOS / Linux project directories are kept in the repository so you can build them yourself. Biometric unlock and screenshot protection rely on system APIs and are available on Android / iOS only.

Screenshots

EasyAuth EasyAuth

Features

  • Data stored locally: 2FA secrets are kept in the device's encrypted storage (Android Keystore / iOS Keychain)
  • Encrypted cloud backup: WebDAV and S3-compatible storage with AES-256-GCM end-to-end encryption
  • Google Authenticator compatible: supports the otpauth:// protocol and migration QR import/export
  • Biometric protection: fingerprint / face unlock with automatic lock when backgrounded
  • Screenshot protection: optionally enable a secure window to block screenshots and screen recording
  • Multi-language: supports 简体中文 / 繁體中文 / English / 한국어 / 日本語

Download & Install

  • Android: download from GitHub Releases, Gitee Releases or GitCode Releases
    • easyauth-<version>-release.apk: universal package, works on any device
    • easyauth-<version>-arm64-v8a-release.apk, armeabi-v7a, x86_64: split by CPU architecture, smaller downloads
    • Every APK ships with a matching .sha1 file so you can verify your download
  • Other platforms: iOS, Windows, macOS and Linux must be compiled from source — see "Build & Run"

Tech Stack

  • Framework: Flutter / Dart 3
  • State management: Provider
  • Local storage: flutter_secure_storage
  • Encryption: encrypt (AES-256-GCM), PBKDF2-HMAC-SHA256 key derivation
  • Biometrics: local_auth
  • Screenshot protection: flutter_windowmanager_plus
  • QR code: mobile_scanner (scanning), qr (generation), otpauth-migration protobuf
  • Cloud backup: http, xml (WebDAV), aws_signature_v4 (S3)
  • Backup packaging: archive, path_provider
  • Localization: flutter_localizations, intl (ARB resources, 5 languages)

See third-party dependencies: https://easyauth.easydebug.net/third-party

Project Structure

EasyAuth/
├── lib/
│   ├── main.dart                    # app entry point
│   ├── models/                      # data models: setting, two_factor_account
│   ├── providers/                   # state management: locale_provider
│   ├── screens/                     # pages: home, add/edit, import/export, settings, about
│   ├── services/                    # services: backup, otp, security, storage
│   ├── utils/                       # helpers: exceptions, qr, s3, style, webdav
│   └── l10n/                        # ARB resources and generated localization code
├── assets/icon/                     # app icon
├── docs/                            # images used by this README
├── android/ ios/ linux/ macos/ windows/   # platform projects
├── test/                            # tests
├── decryption.py                    # backup decryption script (Python)
├── pubspec.yaml                     # dependency manifest
└── l10n.yaml                        # localization config

Build & Run

Requirements

  • Flutter 3.x (Dart 3.12+)
  • Android: Android SDK (Android Studio)
  • iOS / macOS: Xcode
  • Windows / Linux: the matching desktop toolchain

Run

flutter pub get
flutter run

Build

flutter build apk        # Android
flutter build appbundle  # Android (AAB, for Google Play)
flutter build ios        # iOS
flutter build windows    # Windows
flutter build macos      # macOS
flutter build linux      # Linux

Backup & Decryption

A cloud backup is named backup_<timestamp>.zip and contains two entries, salt and data:

  1. A 256-bit key is derived from your backup password and the salt with PBKDF2-HMAC-SHA256 (600,000 iterations, the OWASP recommendation for SHA-256)
  2. data is decrypted with AES-256-GCM (format: 12-byte nonce + ciphertext + 16-byte GCM tag)

You can decrypt your own backups offline, without the app — decryption.py in the repository root uses the same scheme and prints an otpauth:// URI for every account:

pip install pycryptodomex
python decryption.py backup_20260731_120000.zip
python decryption.py backup_20260731_120000.zip -p your-password -o uris.txt

License

This project is licensed under the Apache License 2.0.