OpenIQ Devices
← Back

WristAuth - Secure TOTP on Your Wrist

· v1.0.0
☆☆☆☆☆ (0) ↓ 10 downloads 2 Free

About

WristAuth is a lightweight and efficient Time-based One-Time Password (TOTP) authenticator for your Garmin watch. It provides a convenient way to access your two-factor authentication (2FA) codes directly from your wrist, following the RFC 6238 standard. ## Key Features - Native Security: Utilizes Garmin's built-in cryptographic functions for high-performance and secure code generation. - Multi-Token Support: Configure up to 20 individual accounts. - Customizable Interface: Choose between different font sizes and personalized colors for each token to make them easy to identify. - Smooth Experience: Optimized for touchscreens with kinetic scrolling and clear, high-contrast displays. - Global Compatibility: Supports both SHA-1 and SHA-256 algorithms and token lengths from 6 to 10 digits. ## Compatibility WristAuth requires a Garmin device with Connect IQ API Level 3.0.0 or higher, as it relies on native cryptographic hardware acceleration. ## How to Configure Tokens are managed via the Connect IQ Store app on your smartphone: 1. Open the Connect IQ app and select WristAuth. 2. Go to Settings. 3. Enable a token slot and enter the Account Name and Secret Key (Base32) provided by your service provider. 4. Optionally customize the color, hashing algorithm, and token length. 5. Save settings; your watch will sync automatically. ## Privacy & Security - READ CAREFULLY - No Data Collection: This application does not collect, store, or transmit any personal data or authentication secrets to external servers. - Credential Storage: Secrets are stored exclusively within the standard Garmin Connect IQ app settings system. This data is synced between your smartphone and your Garmin device. Please be aware that Garmin's system might store these settings on your phone and/or in your Garmin account (e.g., via cloud backups on supported devices). - No App-Level Encryption: Connect IQ app settings are generally stored in plain text on the device. Anyone with physical access to your watch (e.g., via USB) or your unlocked smartphone could potentially extract these secrets. - No App-Level Locking: WristAuth does not provide an additional PIN or biometric lock. Anyone with access to your unlocked watch can open the app and view your active codes. - Lost Device: If you lose your watch, your 2FA protection for all configured accounts is considered **broken**. You must immediately log into your services using backup codes and **deactivate or rotate the secrets** for those accounts. - Backups: Always keep your service-provided backup/recovery codes in a safe, separate place. If your watch or phone is lost, these codes are the only way to regain access to your accounts. ## Disclaimer WristAuth is provided as a free tool. The author provides no warranty, takes no responsibility for any security risks, lost data, or lost access to accounts, and does not offer additional technical support. By using this app, you acknowledge that you are responsible for the security of your device and the backup of your authentication secrets.

What's new

1.0.0 * Initital release

Details

Compatible with 39 devices
Updated Apr 27, 2026
Open on apps.garmin.com ↗