Sign in, or create an account if you were invited to connect.
* Name & phone are optional, but recommended for secure text and text-attachments. By adding a phone number, you agree it can be shared with the people you connect with on AuthCode so they can text you trusted messages, and you consent to receiving those texts. Texts are sent by your connections from their own phones, and standard message & data rates may apply. You can change or remove your number anytime under “Edit phone.”
AuthCode encrypts every message end-to-end, and this browser is missing the encryption it needs (X25519). You won’t be able to send or read messages here until it’s updated.
On iPhone or iPad: update to iOS/iPadOS 18.4 or later, then reopen AuthCode. On a computer, use an up-to-date Chrome, Edge, or Safari.
Find who it's for, write your message, then text, email, or copy the block.
This block is encrypted — only the recipient can read it, and only after they verify it. Send it however you like.
Pick who you expect this from, then paste the full message you received, including the -- verify: line at the bottom.
Invite someone, then give them a one-time code over a call or in person. They enter it to connect — that's what proves it's really them.
Enter a new password for your account.
This is the number the people you've connected with can use to text you trusted messages and attachments. By saving it, you consent to your connections seeing this number and texting you at it — texts are sent from their own phones, and standard message & data rates may apply. It's optional: leave it blank and save to remove it. Saving a valid number, however, updates the number that the people who you're connected to will see and send messages to.
For your security, enter the current 6-digit code from your authenticator app to change your phone number.
Scan this code with an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, 1Password, and similar), then enter the 6-digit code to finish.
Can't scan it? Enter this key manually:
These are the devices that have set up an encryption key on your account. Each can send and read your end-to-end encrypted messages. Revoking a device stops it being used for new messages and removes it from future deliveries — it cannot un-read messages already delivered to it.
Give this device a name so you can recognize it later in “Your devices” (e.g. “Work laptop” or “My phone”).
AuthCode will only send your end-to-end encrypted messages to this person’s devices that you have validated in person or by voice. Compare each device’s number with them on that device’s screen; it must match on both. A device you haven’t validated cannot receive or read your messages.
This is permanent and cannot be undone. Your account and all of your information will be permanently deleted. You'll also be removed from the connections of anyone who connected with you.
Shown here only — nothing is written to this device unless you choose Save unencrypted above, which warns you first. The decrypted file stays in memory for this view and is cleared when you close it. A screenshot or screen recording can still capture what is on screen.
Choose how to save this file. Viewing it in AuthCode (the Open button) never writes anything to your device; downloading does.
Saves an encrypted .authcode copy only you can open with your vault passphrase — unreadable on disk, in backups, and in cloud sync. Reopen it with Open encrypted file (in the menu).
Saves the file in plain, readable form to your device’s Downloads. AuthCode cannot remove or protect it afterward — anyone with access to this device, your backups, or your cloud sync can read it. Use this only if you need the file in another app.
About Download file — encrypted: the copy opens only from inside AuthCode, via Open encrypted file, while signed in — it won’t open by tapping it in a file manager. It’s encrypted under your vault passphrase, which you set the first time you save one. AuthCode and its servers never receive your passphrase and cannot read these files. The flip side: if you forget your passphrase, the files cannot be recovered by anyone, including us.
This signs out every other device on your account — they’ll have to sign in again with your password and authenticator. This device stays signed in. A device that’s currently active can take up to about an hour to be fully locked out.