A cross-platform, open-source one-time password (OTP) authenticator app supporting TOTP and HOTP standards.
- TOTP & HOTP support — Generate time-based and counter-based one-time passwords
- QR code scanning — Add accounts by scanning QR codes using the device camera (mobile) or webcam (desktop)
- Cloud backup & restore — Backup and restore your OTP secrets to Dropbox or OneDrive
- Biometric authentication — Secure your OTP secrets with fingerprint/face recognition (Android)
- Cloud account linking — Link cloud storage accounts for seamless backup management
- Dark & light themes — Automatic theme switching with system preference detection
- Search & filter — Quickly find accounts with real-time search
- Drag & drop reordering — Reorganize your accounts with drag and drop
- Multi-platform — Single codebase running on Android, iOS, Windows, macOS, Linux, and the web
| Platform | Status | Details |
|---|---|---|
| 🤖 Android | ✅ Available | Google Play / GitHub Releases |
| 🍎 iOS | ✅ Available | GitHub Releases (IPA) |
| 🖥️ Windows | ✅ Available | GitHub Releases (MSI installer) |
| 🍏 macOS | ✅ Available | GitHub Releases (DMG) |
| 🐧 Linux | ✅ Available | GitHub Releases (DEB package) |
| 🌐 Web | ✅ Available | open-otp.procyk.in (Kotlin/WASM) |
Try the web version directly in your browser: open-otp.procyk.in
Latest Android version is available on Google Play.
You can download compiled versions of the application from GitHub Releases.
Available formats:
- Android: APK (debug/release), AAB (bundle)
- Windows: MSI installer
- macOS: DMG image
- Linux: DEB package
Please note that for running unsigned version of macOS application, you need to temporarily disable Gatekeeper. After installing the application, run:
sudo xattr -dr com.apple.quarantine /Applications/OpenOTP.appYou can learn more about this here.
To install the Linux version, run:
sudo dpkg -i openotp.debThe project is configured with Gradle, and you can find the latest release build commands in the release.yml file.
Example build commands for particular platforms:
- Desktop:
./gradlew desktopApp:packageDistributionForCurrentOS - Android:
./gradlew androidApp:assembleDebug - iOS: Open iosApp/iosApp.xcodeproj in Xcode and run the build
(you may need to configure the
Teamin Signing & Capabilities) - Web:
./gradlew webApp:wasmJsBrowserDistribution
- Kotlin — Primary language
- Kotlin/Wasm — Web target via Kotlin/Wasm JS
- Compose Multiplatform — Shared UI layer
- Material 3 — Modern UI components and theming
- Decompose — Lifecycle-aware business logic components
- Essenty — Instance and state keepers for Decompose
- Koin — Dependency injection
- Kotlin Coroutines — Structured concurrency
- Kotlin Flow — Reactive streams
- Multiplatform Settings — Persistent storage for OTP secrets
- Kotlin Crypto — HMAC-SHA1/SHA2, SHA-2 hashing for OTP generation
- Base32 Encoding — Secret encoding/decoding
- Kotlin Datetime — Time-based OTP calculations
- Kotlin Serialization — JSON and CBOR serialization
- Ktor — HTTP client for cloud backup services
- UUID — Unique identifier generation
- Uri KMP — URI parsing for
otpauth://QR code links
- Android: AndroidX Security (
EncryptedSharedPreferences), Biometric API - Desktop: Webcam Capture + ZXing for QR code scanning
- iOS: Native camera integration via Compose Multiplatform
- Camera Permission — Cross-platform camera permission handling
- Camera QR — Cross-platform QR code scanning UI
- Gradle KTS — Kotlin DSL build scripts
- Gradle Version Catalogs — Centralized dependency management
- GitHub Actions — Automated builds and releases
- GitHub Pages — Web app deployment (CNAME: open-otp.procyk.in)
OpenOTP is designed with privacy in mind. Your OTP secrets are stored locally on your device and are never transmitted to any server, except when you explicitly choose to back them up to your own cloud storage account. See PRIVACY_POLICY.md for details.
This project is licensed under the MIT License — see the LICENSE.md file for details.

