Skip to content

Auth Token

Published by Mark McAvoy

OATH software tokens

Open sourceGPL-3.0-only

Highlights

  • Generates OATH one-time passcodes as a software replacement for a hardware token.
  • Works with services that publish standard enrolment secrets by QR code or text string.
  • Holds tokens for multiple unrelated accounts in one application.
  • Android only, so tokens stay on the handset where they were enrolled.
  • Licensed GPL-3.0-only, which fixes redistribution to that version of the GPL.

About this application

Auth Token, from Mark McAvoy, produces OATH software tokens on Android. It fills the role a hardware key fob once did: an account is enrolled once, and the application then generates the short numeric codes a login prompt asks for as a second factor. The token lives in software on the handset instead of on a separate physical device.

OATH covers two families of one-time passcode, counter-based (HOTP) and time-based (TOTP). Applications in this category work with any service that hands out a standard enrolment secret, usually as a QR code or a typed string, rather than requiring a vendor-specific companion app. In practice this means one application can hold tokens for several unrelated accounts.

The listing covers Android only, so the tokens are tied to the device where they are enrolled; there is no desktop counterpart in this entry. The licence is GPL-3.0-only, a stricter choice than the "or-later" variant, since redistribution must stay under version 3 of the GPL specifically.

Android

  • App storeF-Droid

    From the publisher

    OpenOpens in a new tab

    Package identifier: uk.co.bitethebullet.android.token

    v3.03.0 MBreleased 05/15/2017

    SHA-256 from the manifest published by F-Droid, compared on 08/04/2026

    e6944295ef12926a1f683a974cd2d7ef95c3d5e4ef7af86dd2a4eee9029c4fe1

We do not host this file, we do not scan it and we do not inspect its contents. Read what the source says, then decide for yourself.