Your 2FA codes,
on your wrist.

A self-contained TOTP authenticator for Garmin watches — with Android & iOS companions, a home-screen widget, Wear OS, and zero-knowledge encrypted cloud backup you fully control.

Open source Zero-knowledge encryption Self-hostable
SentryKey watch and mobile app sync mockup

One vault, every device

Add an account once and read your codes wherever you are.

⌚ Garmin Connect IQ
🤖 Android Live
🍎 iOS Soon
⌚ Wear OS Galaxy / Pixel
🌐 Web dashboard Live

Built for security & convenience

Your keys, under your control — with none of the friction.

Standalone watch authenticator

RFC 6238 TOTP codes are generated on your Garmin watch itself. No phone required after the first sync.

🔐

Zero-knowledge cloud backup

Back up to your own server (or sentrykey.app). Everything is encrypted in your browser/app — the server only ever stores ciphertext.

🔄

Frictionless auto-sync

Change a code on your phone and it syncs to your watch and your cloud backup automatically — no buttons to remember.

📲

Home-screen widget

Tap-to-reveal codes right on your Android home screen — hidden by default so a glance never exposes them.

🧭

Wear OS & more

Codes on Galaxy Watch and Pixel Watch too. One vault spans Garmin, Wear OS, phone, and the web.

📦

Open standards

Import from Google Authenticator and any otpauth:// source. Export anytime. No lock-in.

How it works

Three steps. Then it just works.

1

Scan on your phone

Add your 2FA accounts by scanning their QR codes in the companion app.

2

It syncs, encrypted

Your vault flows to your watch over Bluetooth and to your cloud backup — encrypted end-to-end.

3

Read codes anywhere

From your wrist, the widget, or the web dashboard — even with no phone nearby.

True zero-knowledge

Your master password never leaves your device.

🧠

Keys derived locally

Your username + master password derive a login key and a separate encryption key on-device (PBKDF2 + HMAC). The server only sees the login hash.

🔒

Encrypted before it leaves

Vaults are sealed with AES-256-GCM before upload. We literally cannot read your secrets — and neither can anyone who breaches the server.

📖

No tracking, no servers required

No accounts needed to use the apps offline. No analytics. Read the privacy policy.

Run your own server 🏠

SentryKey's backup server is open source and ships with a one-command Docker + automatic-HTTPS deploy. Keep your vault entirely on infrastructure you own — self-hosting is free, forever.

Self-host guide

Free forever — powered by you ❤️

SentryKey has no paid tiers, no subscriptions, and no ads. If it keeps your 2FA on your wrist and you'd like to chip in, a one-time or recurring donation funds new features and keeps the cloud running.

💖 GitHub Sponsors ☕ Buy me a Ko-fi

🧪 Become a beta tester

SentryKey is in closed beta on Google Play. Two quick steps — join the testers group, then opt in on Google Play and tap “Become a tester.” It's free, and your feedback shapes the app.

1 · Join the group 2 · Opt in on Play

Get SentryKey

Free and open source. iOS coming soon.