auth v2026.08 — first production release
Highlights
- Import from Google Authenticator, 2FAS, Aegis,
.nexorabackups and plainotpauth://lists, by drag-drop, paste or multi-file QR - Account edit and delete, labels with automatic issuer categorization and grouping
- Real issuer icons plus custom icons, encrypted on your device before upload
- Three-state dark mode, sort/filter/search, drag and keyboard reorder, row context menus with tap-to-reveal
- Clipboard auto-clear, account QR display behind a two-step reveal
- Vault password reset via recovery key, and a
/restorehistory view - Device clock-drift detection and duplicate-account warnings Two deliberate differences from mobile, both stated in the UI rather than silently missing: custom icons require Pro, and HOTP is not supported (a firm decision, not a temporary gap).
Fixes
- Free-tier vaults now persist properly instead of being lost on refresh.
- Deletions now propagate between devices. Previously a deleted account could reappear on the next sync. Deletion records live inside the encrypted snapshot, so the server never learns that a deletion happened.
- A sync that would drop more than half your accounts, or five or more, without matching evidence now routes to a conflict screen instead of committing.
- Cross-device sync data loss for Pro accounts fixed.
- Cloud snapshots now survive a backend restart. Before this they were held in memory only.
- A lapsing Pro account is no longer worse off than a free one — vault data is never paywalled, including recovery, export and restore.