Help Center

Technical Support

How to add accounts, copy codes, back up safely, and get help with Spot Auth.

Last updated: July 18, 2026

What is Spot Auth?

Spot Auth is an iOS authenticator for TOTP and HOTP one-time codes. It is designed to help you find and copy a code in a few seconds, with a large detail panel and a grid of accounts.

The app has no official Spot Auth servers and does not require an account. Your authentication secrets stay on your device by default.

Quick start

  • Unlock with Face ID, Touch ID, or your device passcode.
  • Tap + to add an account by QR scan, photo of a QR code, or manual entry.
  • Select an account in the grid to show the current code in the detail panel.
  • Tap the code (or the detail card) to copy it to the clipboard.

Adding accounts

Spot Auth accepts standard otpauth:// URLs. You can scan a QR code with the camera, pick a screenshot from Photos, paste an otpauth:// link, or enter the Base32 secret manually.

Supported import formats

  • otpauth:// URIs and Google Authenticator migration QR codes
  • Aegis JSON, 2FAS (.2fas), and common CSV/JSON exports
  • Spot Auth encrypted backups (.spotauth.backup)

Codes look wrong

  • Confirm you selected the correct account.
  • If the progress ring is nearly finished, wait for the next code and copy again.
  • Make sure Date & Time is set to automatic on your iPhone.
  • If another authenticator shows a different code, re-check that the secret, algorithm, digits, and period match.

Backup, export, and moving to a new device

Before switching phones, export an encrypted backup or enable cloud sync (Pro), then import or sync on the new device.

Your backup password protects encrypted backups and cloud sync payloads. If you forget it, Spot Auth cannot decrypt that data.

  • Free plan: limited number of accounts and daily single-account exports.
  • Pro (one-time purchase): unlimited accounts, iCloud / WebDAV sync, encrypted backups, and fuller import/export options.
  • Recently deleted accounts can be restored locally for 7 days.

Cloud sync (Pro)

Optional sync uses an encrypted snapshot. Secrets are not uploaded in plain text.

iCloud Documents stores the encrypted file in your iCloud Drive. WebDAV uses a server you choose over HTTPS.

  • Turn on Offline Mode to disable network logo fetching and cloud sync.
  • You can turn sync off at any time in Settings.

Security basics

  • Secrets are encrypted with AES-256-GCM and stored in the iOS Keychain.
  • Metadata such as service name and account label is stored locally with SwiftData.
  • Face ID / Touch ID are used only for local unlock — biometric templates are never sent to us.
  • Copied codes are cleared from the system clipboard by iOS after about two minutes.

Restore purchases

If you already bought Spot Auth Pro, open Settings and choose Restore Purchases. Purchases are handled by Apple through your App Store account.

Try a test code

You can practice scanning with the public demo page: https://2fa.trustdev.org

Contact

Need help or have a privacy question? Email us and we will respond as soon as we can.