build 3.0.0 · aes-256-gcm / post-quantum · eu/de · ram only

Authenticator apps

Every standard authenticator app works with Paramant. A SHA-256 app gives you the strongest setup.

Why we recommend SHA-256

Paramant's relay accepts both SHA-256 and SHA-1 TOTP codes, so every standard authenticator app works. We recommend SHA-256 because it keeps the MFA layer on the same cryptographic standard as the rest of the transport, which is built around post-quantum key exchange and FIPS 203 primitives. HMAC-SHA1 is not broken and RFC 6238 uses it as the default, so a SHA-1 app is perfectly safe to use. SHA-256 is simply the stronger, more consistent choice.

Recommended apps (SHA-256)

Authy, 1Password, Aegis (Android, open source), Raivo (iOS, open source), Bitwarden, Ente Auth (iOS and Android, open source), and 2FAS all support SHA-256 TOTP. Any of these will work with the QR code shown on the setup page and give you the strongest setup.

Not sure which to pick? Aegis on Android and Raivo on iOS are open source, store codes locally, and have no cloud dependency. 1Password and Bitwarden are good choices if you already use a password manager.

Also works (SHA-1)

Google Authenticator, Microsoft Authenticator, and the authenticator built into iCloud Keychain use SHA-1 TOTP. Paramant accepts SHA-1 codes, so these apps work fine. For the strongest setup we still recommend one of the SHA-256 apps above.

Already using Google Authenticator? It keeps working. Switching to a SHA-256 app such as Raivo or Aegis is a small upgrade, not a requirement.

Upgrading to a SHA-256 app

Google Authenticator works with Paramant. For the strongest setup you can keep it for your other services and add a SHA-256 app (Aegis on Android, Raivo on iOS) specifically for Paramant. Having multiple authenticator apps on one device is supported and common.


Related

Set up authenticator

Scan the QR code and confirm your first code.

Security overview

Full cryptographic posture and protocol details.