Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
2FA codes, passkeys, sign-in approvals and passwords in one Android app. Everything stays on your phone — no account, no cloud, no analytics, and no internet permission at all.
WHY WE BUILT IT
The things that prove who you are end up scattered across an authenticator, a password manager and a cloud passkey vault — each with its own account to lose. We put them in one app that holds all of it on your phone, shows each service's codes, passkey and password together, and has no server to trust because it has no server at all.
WHAT IT DOES
TOTP and HOTP two-factor codes. Add accounts by QR code or by hand, import from Google Authenticator, search, favorite and group them. Export as QR or an encrypted backup.
Register as your phone's passkey provider and sign in to apps and websites with your fingerprint or face. Keys are generated in hardware and never leave the phone.
Approve a sign-in on another screen by scanning its QR code and confirming with your fingerprint or face, over a direct Bluetooth link. A short history shows what you approved or denied.
Passwords and secure notes encrypted with a key held in secure hardware. Password generator, search, favorites, and Autofill into other apps and browsers behind a biometric check.
The Identity tab groups a service's 2FA code, passkey and saved password together — your GitHub, your Google, your bank — and searches across all of them at once.
One password-protected file with your Authenticator accounts and Vault. Passkeys are deliberately excluded — their keys can never leave the phone's secure hardware.
SECURITY DESIGN
An app holding your secrets has one job: keep them. Every choice below favours keys that stay in secure hardware and a design that cannot send anything anywhere.
No internet permission means no analytics, no crash reporting and no ads can exist in the app.
Opening the app, filling a password and signing in with a passkey all ask for your fingerprint or face.
We cannot reset a backup password or recover a lost vault, because we never have the keys.
ALREADY USING OUR OTHER APPS?
In the standalone HostSpica Authenticator choose Settings, then Export backup. In HostSpica Identity choose Settings, then Restore from backup, and enter the same password. Duplicates are skipped.
Passkey keys never leave secure hardware, so they cannot be copied between apps. Create a new passkey in HostSpica Identity for each site, then delete the old one once the new one works.
BUILT WITH
QUESTIONS
No. The app declares no network permission at all, so it cannot send anything anywhere. Signing in from another device uses a direct Bluetooth connection, not the internet.
Only on your phone, encrypted with keys held in the Android Keystore. There is no account and no HostSpica server, so there is nothing for us to see or leak.
Yes. Export a backup in the standalone Authenticator app, then restore it in HostSpica Identity under Settings. Passkeys cannot be moved between apps by design — create new ones in Identity and remove the old ones from each site.
Keep an encrypted backup somewhere safe and keep its password separate. Without a backup, accounts stored only in this app cannot be recovered by anyone, including us. Passkeys are never backed up, so keep another way to sign in to each site.
Not yet. It implements the real WebAuthn/FIDO2 protocol with hardware attestation, but formal FIDO Alliance certification is a separate process that has not been completed.
HostSpica Identity is in the final steps before its Google Play release. Watch HostSpica Labs for the store link, or read the privacy policy.
Back to Labs