OTP Client is an offline encrypted TOTP/HOTP authenticator for Ubuntu Touch.

It is intended for people who want a small native authenticator with straightforward migration/co-existence from desktop OTPClient. Desktop OTPClient users can export FreeOTP+ -> Key URI and import that text file into this app.

Why another 2FA TOTP app? Other apps in the Open Store save your TOTP secrets in plain text and remember Ubuntu Touch does not have full disk encryption. I have verified this is the case for https://open-store.io/app/tfamanager.cibersheep/ and https://open-store.io/app/authenticator-ng.dobey/

I use a forked OTP Client (https://github.com/paolostivanin/OTPClient) on desktop that is my inspiration for this app.

Offline by design
- No networking AppArmor permission is requested.
- The application contains no Qt Network dependency and no network client code.
- Content Hub permissions are used only to import and export local files.
- No advertising, analytics, tracking, telemetry, or developer-operated cloud service.

Encrypted local vault
- An unlock password is mandatory.
- OTP secrets are encrypted at rest with AES-256-GCM.
- The encryption key is derived from the password with PBKDF2-HMAC-SHA256 and a per-vault random salt.
- The unlock password itself is not stored.
- The encrypted vault is written atomically for every successful token change.
- Background locking is enabled by default.

TOTP and HOTP
- TOTP and HOTP tokens.
- SHA-1, SHA-256, and SHA-512.
- 6 through 10 digits.
- Configurable TOTP period.
- HOTP counter support.
- Tap a generated code to copy it to the clipboard.

FreeOTP+ migration/co-existence
- Import newline-separated standard otpauth:// Key URI files.
- Compatible with desktop OTPClient's FreeOTP+ -> Key URI export path.
- Export back to FreeOTP+ Key URI format when explicitly requested.
- FreeOTP+ export contains OTP secrets in plaintext and the app warns before creating it.

Backup and phone migration
- Backup and restore is available from the top-right hamburger menu.
- Configuration is exported/imported as UTF-8 JSON through Ubuntu Touch Content Hub.
- OTP credentials/secrets are excluded by default.
- Include credentials/secrets is optional and off by default.
- When enabled, OTP secrets are written to the exported JSON in plaintext so the file can restore a usable vault on another phone. Protect and delete that file after migration.
- Without secrets, preferences and token metadata are restored and each token requires its secret to be entered again.
- Temporary export files are deleted from the application cache after Content Hub finishes or cancels the transfer, and stale export files are cleaned on the next launch.

Persistent configuration
- Normal settings are stored in the writable Click package-ID directory for otpclient.barrydegraaff.
- QSettings values are synchronized immediately when changed.
- OTP secrets and token fields are stored in the encrypted vault immediately rather than waiting for application shutdown.
- Token-editor drafts are encrypted and persisted on every field change, including when a secret is typed or pasted. Killing the app without a clean shutdown does not intentionally discard the draft.

Ubuntu Touch integration
- Native Qt/QML application for Ubuntu Touch 24.04 on arm64.
- Square logo.png with no pre-rounded corners or border so Ubuntu Touch/OpenStore can apply the selected corner treatment.
- Light and dark modes.
- Hamburger menu at the top right.
- About dialog includes version 0.1.0.
- Only the common content_exchange and content_exchange_source AppArmor groups are requested. The networking policy group is absent.

Security limits
- An unlocked process necessarily holds the derived vault key and decrypted token data in memory.
- Root access, a compromised operating system, hostile kernel, or memory inspection of the unlocked application is outside the protection offered by the vault.
- Plaintext secret exports must be handled as credentials.

OTP Client for Ubuntu Touch is an independent implementation. It is not affiliated with or endorsed by the desktop OTPClient or FreeOTP+ projects. No desktop OTPClient source code is bundled or copied.

This app was vibe coded using an AI. The source code is published for inspection and improvement.

OTP Client is released under MIT No Attribution, SPDX identifier MIT-0.

MIT No Attribution

Copyright 2026 Barry de Graaff

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
