Zelf Auth — Decentralized
2FA Protected by HumanAuthn
Store, protect, and recover your 2FA secrets with biometric encryption, decentralized storage, and offline access. No fragile backups. No central point of failure.
Zelf Auth syncs on any device at any time
Most authenticator apps still force users into risky tradeoffs: either you keep your 2FA secrets only on one device and risk losing them forever, or you rely on centralized backup and syncing models that expand your attack surface.
Zelf Auth changes that model.
With HumanAuthn, your 2FA secrets can be biometrically encrypted and decrypted, then stored in a decentralized-first architecture designed to reduce dependence on third-party custodians.

Features
A better way to
secure and recover 2FA
Create or import your 2FA accounts
Add your OTP-based 2FA accounts like you would in a standard authenticator app.
Encrypt them with HumanAuthn
Your 2FA secrets are protected through biometric encryption/decryption, helping bind access to the legitimate user.
Store them in a decentralized-first architecture
Encrypted 2FA data can be stored through IPFS, rather than depending only on centralized third-party storage patterns.
Recover without the usual backup-key anxiety
Secure a Zelf ID and reduce the pain of lost phones, compromised backup flows, and insecure recovery habits.
Compare Zelf Auth vs traditional authenticator apps
Most authenticator apps solve the code-generation problem. Zelf Auth is built to solve the recovery, storage, and resilience problem too.
| Feature | Zelf Auth | 2FAs | Authy | Microsoft | |
|---|---|---|---|---|---|
| Privacy: No phone number or email address required | |||||
| Open-source | |||||
| Decentralized-first: Data stored in Blockchain/IPFS, not sent to third-party servers | |||||
| GDPR / CCPA compliance positioning | |||||
| Biometric encryption / decryption of 2FA secrets | |||||
| Encrypted backup keys designed to reduce loss and compromise risk | |||||
| Protection against Pixnapping-style risk | |||||
| Works offline: Every piece of information on your device, anytime and anywhere |
Footnotes
Google and Microsoft can involve account-linked sync or ecosystem-linked recovery flows depending on setup. Google Authenticator can sync codes to a Google Account, and Microsoft Authenticator supports cloud backup/restore. 2FAS explicitly states it is open-source and anonymous.
Built for the threats other
authenticator apps ignore
Zelf Auth is not just about generating codes. It is about protecting the secrets behind them.

2FA secrets encrypted at rest
If recovery data exists, it should not exist in a fragile or casually exportable form. Zelf Auth keeps 2FA material encrypted at rest and tied to a human-rooted encryption model.

Never lose your backup keys
Traditional 2FA setups often fail at the worst moment: lost phone, broken device, reset app, inaccessible backup, or compromised recovery path. Zelf Auth preserves your recovery keys as encrypted QR codes stored on IPFS, eliminating the tradeoff between convenience and permanent loss.

Positioning against Pixnapping
Researchers have shown that Pixnapping can leak sensitive information displayed on Android screens, including one-time codes from authenticator apps. Zelf Auth positions itself as a stronger model for users who want to reduce exposure around screen-visible secrets, backup leakage, and recovery compromise.
If your 2FA secret can be lost, unrecovered, or stolen via Pixnapping, it is not truly secure.
Upgrade from basic 2FA apps
to decentralized 2FA security
Protect your 2FA with HumanAuthn biometric encryption, encrypted storage, offline access, and decentralized recovery architecture.
