2fa-authenticationCOMP

Aegis vs Google Authenticator (2026): Local Encrypted Vault or Google Account Sync?

Aegis keeps your 2FA codes in an encrypted vault on your Android phone and never needs an account. Google Authenticator runs on Android and iOS and can sync codes to your Google Account. What each one documents about encryption, backups and moving to a new phone, and who should pick which.

By Eric Gerard · Editor · PwdFortress6 min readPhoto via Pexels

Short answer: pick Aegis if you are on Android and want your codes in an encrypted vault that never leaves your control, with backups you manage yourself. Pick Google Authenticator if you want the same codes on Android and iOS, or you would rather have Google restore them when you change phone. Both generate the same standard codes, so every service that accepts one accepts the other. The difference is where the secrets live and who can bring them back.

Everything below about features comes from what each project documents itself: the Aegis README on GitHub and Google's Authenticator help page, both read on 7 October 2026.

At a glance

AegisGoogle Authenticator
PlatformsAndroid onlyAndroid and iOS
Source codeOpen source, GNU GPL v3.0Not published as open source
Account neededNoNo, but sync requires signing in to a Google Account
Where codes liveEncrypted vault on the phone (AES-256-GCM)On the phone, and in your Google Account if you turn sync on
UnlockPassword (scrypt) or biometrics (Android Keystore)Optional Privacy Screen: device PIN, pattern or biometric prompt
BackupAutomatic vault backups to a location you choose; plaintext or encrypted exportSync to Google Account, or manual QR code transfer
Import from other appsYes, a documented list including Google Authenticator, Authy, 2FAS and Microsoft AuthenticatorNot documented on the help page beyond its own QR transfer
Where to get itGoogle Play Store and F-DroidGoogle Play Store and App Store

The real difference: who holds the secrets

A TOTP code is computed from a secret shared once between the service and your app, usually by scanning a QR code. Whoever holds a copy of that secret can generate your codes. So the question behind "Aegis or Google Authenticator" is simple: where are copies of those secrets stored, and what protects them?

Aegis keeps them in one place. The vault sits on the phone, encrypted with AES-256-GCM, and is unlocked with a password derived through scrypt or with biometrics backed by the Android Keystore. The README also lists screen capture prevention and a tap-to-reveal option. Nothing in that model involves an online account: if you want a second copy, you create it, as a backup file.

Google Authenticator can keep them in two. Google's help page says you can synchronize your verification codes across your devices by signing in to your Google Account, and that Google encrypts Authenticator codes in transit and at rest. The page does not describe that sync as end-to-end encrypted. It also says you may choose to use the app without these protections, meaning without signing in, in which case the codes stay on the device only.

Neither design is wrong. They answer different worries.

A fingertip pressing the number 5 on a tablet's passcode keypad, under the words Touch ID or Enter Passcode, with warm out-of-focus light in the background
A fingertip pressing the number 5 on a tablet's passcode keypad, under the words Touch ID or Enter Passcode, with warm out-of-focus light in the background

Where Aegis is ahead

  • You can verify it. The code is public under the GPL v3.0, and the app is also on F-Droid, which builds from source.
  • The vault is encrypted with a key only you hold. A password you choose, not an account someone could take over.
  • Backups are yours. Automatic vault backups go to a location you pick, and an export can be encrypted. You decide whether that file ever touches a cloud service.
  • Leaving is easy. Plaintext or encrypted export, and import from a long list of other authenticators, so you are not locked in either direction.

Where Google Authenticator is ahead

  • It runs on iPhone. Aegis does not. In a household or team with mixed phones, that alone can decide it.
  • Recovery needs no planning. With sync on, a new phone gets the codes back when you sign in. No backup file to keep track of.
  • It is the app most setup guides assume. Any site's 2FA instructions will work as written.
  • Privacy Screen adds a lock. When turned on, the app asks for your device PIN, pattern or a biometric prompt before showing codes.

The cost of that convenience is concentration: with sync enabled, the security of your second factors depends on the security of your Google Account. If you go that way, protect that account with something stronger than a code from the same app, ideally a passkey or a hardware key. Our YubiKey vs passkey comparison covers those options.

How to choose, honestly

  • Android only, and you will keep a backup file: Aegis.
  • iPhone, or both platforms: Google Authenticator, or another cross-platform app from our best authenticator apps guide.
  • You know you will never make a backup: Google Authenticator with sync on. An encrypted vault with no backup is one dropped phone away from a long evening of account recovery.
  • You do not want your codes tied to a cloud account: Aegis, or Google Authenticator without signing in, plus recovery codes stored somewhere safe.

Switching from Google Authenticator to Aegis

  1. Install Aegis from Google Play or F-Droid and set a vault password.
  2. In Google Authenticator, use the transfer option to export your accounts: it displays a QR code.
  3. In Aegis, open the import screen, choose Google Authenticator and scan that QR code.
  4. Test a login with a code from Aegis for each important account.
  5. Set up automatic backups in Aegis, then decide whether to keep or remove the entries in the old app.

Do not skip step 4. A code that looks right but fails at login is something you want to discover while the old app still works. If you are also changing phone, our guide to moving an authenticator app to a new phone walks through the order of operations.

The bottom line

Both apps produce identical codes from identical standards. Aegis gives you an encrypted, open-source vault on Android and leaves backups to you. Google Authenticator trades that control for reach across Android and iOS and for recovery through your Google Account. Choose by how you will handle the day your phone is gone: with a backup file you kept, or with an account you secured.

Frequently asked questions

Is Aegis safer than Google Authenticator?

They protect against different things. Aegis documents an AES-256-GCM encrypted vault unlocked by a password or biometrics, and its code is open source, so the claims can be checked. Google Authenticator can sync codes to your Google Account, which protects you against losing the phone but ties the codes to that account. If your main fear is a lost or broken phone, sync helps. If it is someone getting into a cloud account, a local encrypted vault with your own backups is the stricter model.

Does Aegis work on iPhone?

No. Aegis is an Android app, distributed on the Google Play Store and on F-Droid. On iOS you need another authenticator; Google Authenticator runs on both Android and iOS.

Can I move my codes from Google Authenticator to Aegis?

Yes. Aegis lists Google Authenticator among the apps it can import from. In Google Authenticator you export your accounts as a QR code, then scan it from the import screen in Aegis. Check that every code works in Aegis before deleting anything from the old app.

What happens to my codes if I lose my phone?

With Google Authenticator and sync turned on, signing in to your Google Account on a new device brings the codes back. With Aegis, you restore from a backup file you made earlier: the app can write automatic backups of the vault to a location you choose, and exports can be encrypted. Without sync and without a backup, the codes are gone in both apps, and you fall back on each service's recovery codes.