A self-contained TOTP authenticator for Garmin watches — with Android & iOS companions, a home-screen widget, Wear OS, and zero-knowledge encrypted cloud backup you fully control.
Add an account once and read your codes wherever you are.
Your keys, under your control — with none of the friction.
RFC 6238 TOTP codes are generated on your Garmin watch itself. No phone required after the first sync.
Back up to your own server (or sentrykey.app). Everything is encrypted in your browser/app — the server only ever stores ciphertext.
Change a code on your phone and it syncs to your watch and your cloud backup automatically — no buttons to remember.
Tap-to-reveal codes right on your Android home screen — hidden by default so a glance never exposes them.
Codes on Galaxy Watch and Pixel Watch too. One vault spans Garmin, Wear OS, phone, and the web.
Import from Google Authenticator and any otpauth:// source. Export anytime. No lock-in.
Three steps. Then it just works.
Add your 2FA accounts by scanning their QR codes in the companion app.
Your vault flows to your watch over Bluetooth and to your cloud backup — encrypted end-to-end.
From your wrist, the widget, or the web dashboard — even with no phone nearby.
Your master password never leaves your device.
Your username + master password derive a login key and a separate encryption key on-device (PBKDF2 + HMAC). The server only sees the login hash.
Vaults are sealed with AES-256-GCM before upload. We literally cannot read your secrets — and neither can anyone who breaches the server.
No accounts needed to use the apps offline. No analytics. Read the privacy policy.
Free and open source. iOS coming soon.