AndroidiOS

Where Does FreeOTP Store Tokens?

FreeOTP keeps tokens in Android Keystore-backed storage and iOS Keychain, with encrypted in-app backups. No cloud sync exists.

Last updated

FreeOTP has two eras with a wall between them. Legacy builds kept tokens as JSON in shared prefs that anyone could export. Modern builds moved secrets one-way into Keystore with encrypted prefs, and iOS into Keychain from early on.

No cloud sync bridges phones in any era. Android offers in-app encrypted backup plus system auto-backup when enabled. iOS relies on encrypted Apple backups with Keychain switched on. Legacy converters belong to the old format only.

Where FreeOTP stores this, by platform

Android
/data/data/org.fedorahosted.freeotp

Token storage for the verified Fedora package. Legacy plaintext XML gave way to Keystore-backed encryption with version-varying filenames. Use in-app Backup to a chosen path rather than file copies.

iOS
/var/mobile/Containers/Data/Application/<guid>/Documents

Keychain-backed token store with no files to quote. Recovery needs encrypted Apple backups with Keychain on, excluding biometric-locked secrets. No export feature exists on this platform.

Frequently asked questions

How do I move FreeOTP to a new phone?

Use the toolbar Backup inside the app to a path you choose with a master password, then Restore with the same password on the new phone. Modern secrets live one-way in Keystore, so file copies cannot substitute. Test restores whenever installing, per the project warning.

Do old FreeOTP export tools still work?

They are incompatible by design. Legacy shared-prefs XML held plaintext JSON that community exporters converted to QR codes. Current storage encrypts with Keystore keys, so old converters fail against new backups. Migrate while the old phone still runs.

Where are FreeOTP tokens on iPhone?

It holds nothing portable. iOS keeps tokens in Keychain with order metadata, recoverable only through encrypted Apple backups with Keychain enabled. Biometric-locked secrets stay out of backups entirely by platform rule.

Notice an outdated path? Let us know.