Skip to content

How 2FAS’s scores are calculated

The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.

verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10

PA Score11/100

Agent-ready 10.0 × 0.30 = 3.00

API quality 0.0 × 0.20 = 0.00

Openness 37.6 × 0.20 = 7.52

Built-in AI 0.0 × 0.15 = 0.00

Automation 0.0 × 0.15 = 0.00

(3.00 + 0.00 + 7.52 + 0.00 + 0.00) ÷ (0.30 + 0.20 + 0.20 + 0.15 + 0.15) = 10.52 ÷ 1.00 = 10.5

Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.

Agent-ready10.0/100×0.30 of the PA blend

Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.

Point an agent at llms.txt or agent-oriented docsweight 2

2 (weight) × 9 (quality) × 1.0 (full) = 18.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE llms.txt: HTTP 200 at https://2fas.com/llms.txt # 2FAS — Password Manager and Authenticator > Local-first password manager (2FAS Pass), open-source two-factor authenti
  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/.well-known/pricing.mdPROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... 2FAS Auth — free forever... Price: $0 — no tiers, no premium, no in-app purchases, no advertising, no telemetry.'

Run the product headlessly / in CI for automationweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Plug MCP servers into this product so it can use their toolsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Connect an agent via an official MCP serverweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Use an official CLIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Drive the product through a documented public APIweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Issue scoped/least-privilege API credentials for an agentweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Build against official SDKsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Subscribe to events via webhooksweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Agent-ready = 18.0 ÷ 180 × 100 = 10.0

API quality0.0/100×0.20 of the PA blend

The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.

Explore an interactive API reference with runnable examplesweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)
  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Download a machine-readable API spec (OpenAPI or equivalent)weight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)
  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Test against a sandbox environment without touching production dataweight 1

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Rely on versioned APIs with a documented deprecation policyweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)
  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

API quality = 0.0 ÷ 60 × 100 = 0.0

Openness37.6/100×0.20 of the PA blend

Can you leave, inspect, or self-host — data export, open source, portability.

Do everything through the API that I can do in the UIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [probe] https://2fas.com/openapi.jsonPROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, https://2fas.com/.well-known/openapi.json)

Export all of my data in open formats and leaveweight 3

3 (weight) × 6 (quality) × 0.6 (partial) = 10.8 of 30 max

  • [claimed-docs] https://2fas.com/auth/Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
  • [claimed-docs] https://2fas.com/support/2fas-auth-security-privacy/is-2fas-backup-safe/data can be encrypted with your password, so we encourage you to do that.
  • [claimed-docs] https://2fas.com/.well-known/pricing.mdFreedom to self-host your data
  • [claimed-docs] https://2fas.com/pass/You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
  • [community] https://news.ycombinator.com/item?id=46188858Free tier of 2FAS Pass includes auto-fill, import/export, and standard password generator; paid tier adds multi-device sync, more than 200 vault entries, and unlimited browser extension use.
  • [claimed-docs] https://2fas.com/support/2fas-auth-mobile-app/which-imports-are-supported-in-the-2fas-app/We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.

Read the product's source under an open licenseweight 2

2 (weight) × 8 (quality) × 1.0 (full) = 16.0 of 20 max

  • [claimed-docs] https://2fas.com/auth/browser-extension/You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
  • [claimed-docs] https://2fas.com/pass/browser-extension/Join our GitHub project and contribute to 2FAS by running code review and committing your ideas.
  • [claimed-docs] https://2fas.com/auth/browser-extension/Check out our GitHub repository and delve deep into the intricacies of the browser extension back-end.
  • [claimed-docs] https://2fas.com/.well-known/pricing.mdFreedom to self-host your data
  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Self-host the core productweight 3

3 (weight) × 6 (quality) × 0.6 (partial) = 10.8 of 30 max

  • [claimed-docs] https://2fas.com/pass/You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
  • [claimed-docs] https://2fas.com/.well-known/pricing.mdFreedom to self-host your data
  • [claimed-docs] https://2fas.com/auth/browser-extension/You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
  • [community] https://news.ycombinator.com/item?id=45082327Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's security. Questions how this differs from or improves upon self-hosted Bitwarden.

Openness = 37.6 ÷ 100 × 100 = 37.6

Built-in AI0.0/100×0.15 of the PA blend

Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.

Get AI-generated insights and suggestions from my data inside the productweight 2

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Set up automations that run autonomously in the backgroundweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Delegate tasks to a built-in AI assistant inside the productweight 3

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Operate the product with natural-language commandsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Built-in AI = 0.0 ÷ 40 × 100 = 0.0

Automation0.0/100×0.15 of the PA blend

Depth of automation primitives — rules, scheduling, bulk operations, webhooks.

Perform bulk operations across many items at onceweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.
  • [claimed-docs] https://2fas.com/support/2fas-auth-mobile-app/which-imports-are-supported-in-the-2fas-app/We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.

Define rules that trigger actions automatically on eventsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://2fas.com/llms.txtPROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI agents — when to use 2FAS' section, modular per-section llms files, llms-full.txt, per-page .md mirrors (https://2fas.com/auth.md → '# 2FAS Auth — Free, Open-source 2FA Authenticator App'), Accept: text/markdown rendering, and machine-readable pricing at /.well-known/pricing.md. The same llms.txt honestly declares 'Public API: None' — local-first by design, no agent-callable endpoint for token generation.

Schedule recurring jobs or workflowsweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Version, review, and roll back my automationsweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Automation = 0.0 ÷ 20 × 100 = 0.0