Skip to content

Authenticator Apps Arena

Ente Auth vs 2FAS

Ente Auth wins · 169 (22 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round to 2FAS
    Ente Authfullprobed7/10

    Ente serves a live llms.txt at ente.com/llms.txt confirmed by two independent probes, giving an agent a fair entry point; however, docs-as-markdown and OpenAPI endpoints 404, so agent-oriented documentation beyond the single llms.txt file is thin. missing for 10: markdown-served docs pages, OpenAPI/agent-consumable API spec, broader agent-oriented doc structure beyond one root file.

    • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
    • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
    • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
    • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…

    Direct probe confirms a live llms.txt with an explicit 'For AI agents' section, plus modular per-section llms files, llms-full.txt, per-page .md mirrors, and Accept: text/markdown rendering — strong first-party agent-oriented docs infrastructure verified via runtime probes. Missing for 10: no independent/community corroboration of agents actually consuming these docs in practice.

    • [probe] PROBE llms.txt: HTTP 200 at https://2fas.com/llms.txt # 2FAS — Password Manager and Authenticator > Local-first password manager (2FAS Pass…
    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
    • [probe] PROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... …
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Ente Auth
    Ente Authpartialprobed3/10

    Ente provides an official CLI (ente-cli) that can run headlessly to export/backup Auth codes, which is scriptable and could be used in automation/CI contexts, but evidence only documents it for exporting/decrypting backups, not for generic headless operation, generating TOTP codes on demand, or CI-integrated workflows. Missing for 10: documentation of CLI usage for retrieving/generating codes programmatically, CI-specific examples, and any first-party statement about automation/agentic use beyond backup.

    • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
    • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
    2FASnone0/10

    2FAS is a mobile authenticator/password manager with no CLI, headless mode, or API for CI/automation; the product's own llms.txt explicitly declares 'Public API: None' and is local-first by design, meaning it cannot be run headlessly or scripted in CI.

    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
    • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
  3. ai-native userConnect an agent via an official MCP server

    weight 3 · round drawn
    Ente Authnone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      2FASnone0/10

      2FAS is a password/2FA manager, not an agent, so an MCP server axis could plausibly apply to its ecosystem; however evidence explicitly states 'Public API: None' and no OpenAPI/MCP endpoint exists, with probes confirming no API surface for agents to connect to.

      • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
      • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
    • ai-native userUse an official CLI

      weight 2 · round to Ente Auth
      Ente Authpartialprobed6/10

      Ente ships an official CLI (github.com/ente/ente/tree/main/cli) confirmed to be packaged via Homebrew as 'ente-cli', documented as scriptable tooling to 'automatically backup your Auth codes' and decrypt exports — this is a real, official, automatable interface. However it is scoped narrowly to backup/export/decrypt operations rather than full account/code management or general agentic control. Missing for 10: broader CLI command coverage (add/edit/delete codes, sharing, sync), first-party docs detailing CLI usage beyond export, and independent hands-on reports of using it in automated/agentic workflows.

      • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
      • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
      2FASnone0/10

      2FAS is a mobile/browser 2FA and password-manager app with no evidence of an official CLI; docs explicitly note 'Public API: None' and no CLI tool is mentioned anywhere in the evidence pack.

      • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
    • ai-native userDrive the product through a documented public API

      weight 3 · round to Ente Auth
      Ente Authpartialprobed3/10

      Ente provides a CLI (ente-cli) for exporting/backing up Auth codes and a documented deep-link scheme (enteauth://search), but there is no documented public REST/GraphQL API or SDK for driving the product programmatically — OpenAPI probes returned 404s. missing for 10: a documented public API/SDK covering core operations (add/edit/delete codes, sharing, sync), API authentication docs, and independent developer corroboration of API usage.

      • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
      • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
      • [claimed-docs] Added support for search deep links via enteauth://search.
      • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
      2FASnone0/10

      2FAS explicitly states 'Public API: None' in its own llms.txt, and OpenAPI/swagger probes all return 404, confirming there is no documented public API to drive the product programmatically — it is local-first by design.

      • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
      • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
    • ai-native userIssue scoped/least-privilege API credentials for an agent

      weight 2 · round drawn
      Ente Authnone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        2FASnone0/10

        2FAS is a local-first authenticator/password manager with no public API; its own llms.txt explicitly states 'Public API: None' and no agent-callable endpoint for token generation, so there is no mechanism to issue scoped/least-privilege API credentials for an agent.

        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
        • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
      • ai-native userBuild against official SDKs

        weight 2 · round drawn
        Ente Authnone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          2FASnone0/10

          2FAS explicitly declares 'Public API: None' and has no OpenAPI/SDK endpoints; probes confirm no SDK or API surface exists for developers to build against.

          • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
          • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…

        Agentic features

        1. ai-native userSet up automations that run autonomously in the background

          weight 2 · round drawn
          Ente Authnone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            2FASnone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            • ai-native userOperate the product with natural-language commands

              weight 2 · round drawn
              Ente Authnone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                2FASnone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Api quality

                1. ai-native userExplore an interactive API reference with runnable examples

                  weight 2 · round drawn
                  Ente Authnone0/10

                  No evidence of an interactive API reference or runnable examples; OpenAPI/swagger probes returned 404s and no developer API docs are mentioned anywhere in the pack.

                  • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                  • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
                  2FASnone0/10

                  No evidence of an interactive API reference or runnable examples; openapi probe returned 404s across all candidate paths and llms.txt explicitly states 'Public API: None' since 2FAS is local-first with no agent-callable endpoints.

                  • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                2. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                  weight 2 · round drawn
                  Ente Authnone0/10

                  Probe results explicitly show all candidate OpenAPI/Swagger paths return 404, and there is no documented machine-readable API spec anywhere in the evidence pack; missing for 10: any published OpenAPI/Swagger file, API reference docs, or equivalent machine-readable spec.

                  • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                  2FASnone0/10

                  Direct probes for OpenAPI/swagger specs all returned 404, and the product's own llms.txt explicitly states 'Public API: None,' confirming no machine-readable API spec is offered.

                  • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                3. ai-native userRely on versioned APIs with a documented deprecation policy

                  weight 2 · round drawn
                  Ente Authnone0/10

                  Ente Auth is a 2FA authenticator app; there is no evidence of a public API, API versioning scheme, or documented deprecation policy — OpenAPI probes 404 and no API docs exist in the evidence pack.

                  • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                  • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
                  2FASnone0/10

                  2FAS explicitly declares 'Public API: None' and has no OpenAPI/swagger endpoints (all probes 404), meaning there is no versioned API at all, let alone a documented deprecation policy.

                  • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…

                Automation depth — how much of the product can run unattendedAutomation depth

                How much of the product can run unattended

                1. ai-native userPerform bulk operations across many items at once

                  weight 2 · round to Ente Auth
                  Ente Authpartialprobed4/10

                  Ente Auth documents bulk import from other 2FA apps and a CLI tool for scripted export/backup of all codes, which supports some automation-depth for a bulk operation, but there is no evidence of programmatic bulk editing, deleting, or tagging across many stored codes at once (only single-item edit/delete via long-press is documented). missing for 10: bulk edit/delete/tag API or CLI beyond import/export, evidence of scripted multi-item management, independent hands-on confirmation of bulk workflows.

                  • [claimed-docs] Bulk import from other 2FA apps
                  • [claimed-docs] Ente Auth natively supports imports from many 2FA providers.
                  • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                  • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                  • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.
                  2FASnone0/10

                  2FAS is a local-first authenticator/password manager with no public API (explicitly declared 'Public API: None'), and no evidence of bulk operations across items (e.g., batch import/export beyond single-file import, bulk edit/delete of tokens or vault entries) that an AI agent could invoke. There's no scripting, CLI, or API surface for programmatic bulk actions.

                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                  • [claimed-docs] We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.

                Openness — open source, data portability, and self-hosting storiesOpenness

                Open source, data portability, and self-hosting stories

                1. ai-native userDo everything through the API that I can do in the UI

                  weight 2 · round drawn
                  Ente Authnone0/10

                  Ente Auth exposes only a CLI for exporting/decrypting backups, not a general API covering all UI actions (add/edit/share/organize codes, etc.); probes for OpenAPI/API docs all returned 404, and no documentation describes a comprehensive API surface.

                  • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                  • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                  • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                  2FASnone0/10

                  2FAS's own llms.txt explicitly declares 'Public API: None' and probes confirm no OpenAPI/swagger spec exists at any candidate path, meaning there is no API surface at all through which a user could replicate UI actions.

                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                  • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
                2. ai-native userExport all of my data in open formats and leave

                  weight 3 · round to 2FAS

                  Ente ships an official CLI to export and decrypt Auth data and documents password-encrypted local backups, and some HN commenters confirm easy export/import between apps (comm-6,7,8; probe-rt-1). But a first-hand HN commenter explicitly states 'You cant easily export your codes into a different format using this app, meaning that it is difficult to migrate away' (comm-2), directly contradicting the frictionless open-format export claim. Missing for 10: a documented plain/open (non-proprietary) full export format, resolution of the lock-in complaint, and independent verification that CLI-exported data is usable outside Ente.

                  • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                  • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                  • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                  • [claimed-docs] the data is encrypted using a key derived from the user's password
                  • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                  • [community] I'm waiting for bitwarden or aegis export capability before trying this out. You cant easily export your codes into a different format using…
                  • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …
                  • [community] I think it has its own backup service. But it otherwise lets you export/import your data. I feel like as long as I can do an export in some …

                  2FAS explicitly supports exporting/backing up data (encrypted export files, self-host freedom, import/export in free tier) and even imports from competitor formats, showing some portability. However, there's no evidence the export format itself is documented as an open/standard schema (e.g., JSON spec or standard otpauth migration format), and the backup is typically encrypted for 2FAS's own re-import rather than a documented open format for third-party tools. missing for 10: explicit open/standard export format spec, independent confirmation the exported file is usable outside 2FAS ecosystem, and details on the exact format encoding.

                  • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                  • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                  • [claimed-docs] Freedom to self-host your data
                  • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                  • [community] Free tier of 2FAS Pass includes auto-fill, import/export, and standard password generator; paid tier adds multi-device sync, more than 200 v…
                  • [claimed-docs] We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.
                3. ai-native userRead the product's source under an open license

                  weight 2 · round to 2FAS
                  Ente Authfullprobed7/10

                  Ente's own llms.txt explicitly states 'Ente's apps and server are open source,' and a GitHub repo (ente/ente) is referenced for the CLI/export tooling; independent HN commentary corroborates ('thank you for releasing it open source'). Missing for 10: explicit license name/text and a direct link to the license file are not shown in the evidence pack.

                  • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
                  • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                  • [community] This looks quite nice, thank you for releasing it open source... One note as I signed up for an account is that the email verification went …
                  • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.

                  2FAS explicitly points to its GitHub repositories for both the auth app and browser extension, describing itself as open-source, and the probe confirms 'open-source two-factor authentication' positioning with 'Freedom to self-host your data.' missing for 10: explicit license name (e.g., MIT/GPL) is not stated in evidence, and no independent audit confirming license terms.

                  • [claimed-docs] You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
                  • [claimed-docs] Join our GitHub project and contribute to 2FAS by running code review and committing your ideas.
                  • [claimed-docs] Check out our GitHub repository and delve deep into the intricacies of the browser extension back-end.
                  • [claimed-docs] Freedom to self-host your data
                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                4. ai-native userSelf-host the core product

                  weight 3 · round to Ente Auth
                  Ente Authfullprobed8/10

                  Ente explicitly documents self-hosting instructions, pointing users to run Ente Auth at localhost/machine-ip:3003, and the product is described as open source, consistent with independent verification via the llms.txt runtime probe. missing for 10: independent hands-on report of a full self-hosted deployment (beyond docs/probe), and details on self-hosting server setup/requirements beyond the port reference.

                  • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                  • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
                  • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …

                  2FAS explicitly markets 'Freedom to self-host your data' and lets users choose their own cloud/WebDAV/external drive storage for vaults, and the core apps are open-source on GitHub for self-hosting/auditing. However, this is self-hosting of data/storage, not the full core service (no self-hostable server/backend, no API for self-managed infrastructure), and community commentary questions how this differs meaningfully from server-reliant competitors. Missing for 10: a self-hostable backend/server component, documentation of running the whole product on own infrastructure, and independent confirmation that self-hosted storage removes all vendor dependency.

                  • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                  • [claimed-docs] Freedom to self-host your data
                  • [claimed-docs] You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
                  • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…

                Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support

                Passkeys in the vault — storage, sign-in, cross-ecosystem sync

                Storage

                1. everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes

                  weight 3 · round drawn
                  Ente Authnone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    2FASnone0/10

                    2FAS is a TOTP authenticator (2FAS Auth) and separately a password manager (2FAS Pass); evidence covers token/2FA codes, vault items, and password autofill, but nothing describes passkey (WebAuthn/FIDO2) storage or passkey-based sign-in to websites/apps.

                    Sync

                    1. power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

                      weight 2 · round drawn
                      Ente Authnone0/10

                      Ente Auth is a TOTP/2FA code manager; the only passkey mention in evidence (doc-14) refers to passkey login for the separate Ente Photos account, not Ente Auth storing/syncing passkeys as credentials across iOS/Android/Windows/Linux/browsers. No evidence shows Ente Auth itself functions as a cross-platform passkey vault.

                      • [claimed-docs] Ente also offers [Legacy](/help/photos/features/legacy/) (emergency contacts) and support for [Passkeys](/help/photos/features/passkeys).
                      • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                      2FASnone0/10

                      The evidence pack describes 2FAS Auth's 2FA token sync and 2FAS Pass's password vault sync (iCloud, Google Drive, WebDAV, browser extension) but contains no mention of 'passkey' or WebAuthn/FIDO2 credential support or storage anywhere. Since passkey sync is a distinct capability from OTP tokens or password items, there's no evidence this product delivers it.

                      Portability — your secrets stay yours — open export, bulk import, device migrationPortability

                      Your secrets stay yours — open export, bulk import, device migration

                      Export

                      1. power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

                        weight 3 · round to 2FAS

                        Ente Auth does offer local encrypted backups and a CLI ('ente-cli') that can export and decrypt Auth data (docs-8/9/11, probe-rt-1), and Authy-specific tooling explicitly produces a 'plaintext export format' for importing into Ente (docs-5/40) — but this is import-facing, not an open export for leaving Ente. A hands-on community report explicitly states the opposite of the 'no lock-in' claim: 'You cant easily export your codes into a different format using this app, meaning that it is difficult to migrate away once you have already moved your codes over' (comm-2), while other users only describe importing into Ente, not exporting out to a different app's format. Missing for 10: documented open/standard export format usable directly by other authenticator apps, and independent confirmation that migrating away (not just in) is easy.

                        • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                        • [claimed-docs] you should type this for MacOS... This will generate a text file called authy_codes.txt, which contains your Authy codes in Ente's plaintext…
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                        • [community] I'm waiting for bitwarden or aegis export capability before trying this out. You cant easily export your codes into a different format using…
                        • [community] Ente has free backups and it's own encrypted export format, which sounds promissing.

                        2FAS explicitly supports imports from other apps (Aegis, Raivo, Google Authenticator, etc.) and offers 2FAS export files for backup/sync, with optional password-based encryption of backups. However, evidence doesn't confirm the export format is an open/readable standard (e.g., plaintext otpauth URIs or documented JSON schema) rather than a proprietary encrypted blob, and there's no explicit statement about exporting TO other apps' formats for migration away from 2FAS. missing for 10: documented open/standard export format spec, explicit 'export to other apps' migration path, independent confirmation the export file is human-readable/portable.

                        • [claimed-docs] We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.
                        • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.

                      Import

                      1. power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

                        weight 2 · round to Ente Auth
                        Ente Authfullcommunity9/10

                        Ente Auth has a dedicated bulk-import feature and docs listing native support for many 2FA providers (2FAS, Aegis, andOTP, Bitwarden, Google Authenticator, LastPass, Proton, Raivo OTP) plus conversion paths for others like Authy, with community testimony confirming easy export/import migration from Aegis. missing for 10: no independent hands-on walkthrough of the bulk-import UI itself, only docs and one community mention.

                        • [claimed-docs] Ente Auth natively supports imports from many 2FA providers.
                        • [claimed-docs] Bulk import from other 2FA apps
                        • [claimed-docs] 2FAS Authenticator * Aegis Authenticator * andOTP (including encrypted backups, except MOTP) * Bitwarden * Google Authenticator * …
                        • [claimed-docs] you might be still able to import from them by first converting the data from your old provider into these plaintext files and then importin…
                        • [claimed-docs] you should type this for MacOS... This will generate a text file called authy_codes.txt, which contains your Authy codes in Ente's plaintext…
                        • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …

                        2FAS docs explicitly list bulk import support from Aegis, Raivo, LastPassAegis, Stratum, and Google Authenticator, directly supporting the power-user portability story. However, the list is limited to a handful of named apps, no evidence of a generic/universal import format (e.g., OTP URI batch, QR export from arbitrary apps), and no independent hands-on verification of the import process working smoothly. Missing for 10: broader import coverage beyond five named apps, independent/community confirmation of successful bulk import, and details on edge cases (e.g., failed imports, partial data loss).

                        • [claimed-docs] We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.

                      Migration

                      1. everyday userMoving to a new phone transfers all my tokens in one guided step

                        weight 2 · round drawn
                        Ente Authfullprobed7/10

                        Ente Auth syncs codes end-to-end encrypted across all devices (docs-27, docs-34), so on a new phone a user simply logs into their existing account and their tokens reappear automatically—effectively a single guided step. Community feedback corroborates that switching devices via export/import was 'very easy' (ente-auth-comm-6), and offline-mode users can restore via password-protected local/CLI backups (docs-7, docs-8, docs-9, docs-11, ente-auth-probe-rt-1). Missing for 10: no explicit first-party step-by-step 'new phone setup/restore' walkthrough, and no independent hands-on account of the exact new-device login-and-sync flow.

                        • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                        • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                        • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                        • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                        • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…

                        2FAS Auth supports iCloud/Google Drive sync and encrypted export/backup files, letting a user restore tokens on a new device by simply enabling sync or importing the backup file, and 2FAS Pass has a dedicated recovery flow for restoring the vault on a different device via iCloud/Google Drive backups. missing for 10: a documented single-tap 'migrate to new phone' wizard UI and independent hands-on confirmation of the transfer experience.

                        • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                        • [claimed-docs] Multi-device sync (encrypted)
                        • [claimed-docs] Learn how to restore access to your 2FAS Pass Vault or run it on a different device.
                        • [claimed-docs] If you have enabled sync with iCloud (on iOS) or Google Drive (on Android), your encrypted 2FAS Pass Vault file is right there.

                      Privacy posture — data-handling and privacy storiesPrivacy posture

                      Data-handling and privacy stories

                      1. ai-native userChoose where my data is stored (region/residency)

                        weight 2 · round to 2FAS
                        Ente Authpartialprobed5/10

                        Ente Auth offers self-hosting instructions (running your own Ente Auth server) and an offline mode that keeps codes only on-device, both of which let a user control where their data lives rather than being forced into a fixed cloud region. However, there's no explicit region/residency selection (e.g., choosing an EU vs US data center) for its hosted cloud service. Missing for 10: explicit multi-region cloud storage options, documented data-residency guarantees for the hosted service.

                        • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                        • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                        • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…

                        2FAS is local-first: users choose to keep data on-device, in their own iCloud/Google Drive, WebDAV, or fully self-hosted, giving strong control over storage location (2fas-docs-5, 2fas-docs-14, 2fas-docs-17). This satisfies the spirit of data residency choice, though it's not a formal 'select region/datacenter' feature and relies on user-configured third-party clouds rather than a first-party regional hosting option. Missing for 10: explicit region/datacenter selection controls, independent verification of self-host setup beyond marketing pages.

                        • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                        • [claimed-docs] Freedom to self-host your data
                        • [claimed-docs] Multi-device sync (encrypted)
                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                        • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…
                      2. ai-native userPrevent my data from being used to train AI models

                        weight 3 · round to Ente Auth
                        Ente Authpartialprobed5/10

                        Ente Auth stores codes with end-to-end encryption, meaning Ente itself cannot access plaintext data, which structurally prevents it from being used to train AI models — but there is no explicit policy statement addressing AI training use of data. Missing for 10: an explicit AI-training data-use policy/statement, and any independent confirmation of this posture beyond the general E2E encryption claim.

                        • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                        • [claimed-docs] the data is encrypted using a key derived from the user's password
                        • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md

                        2FAS is local-first with explicit 'no telemetry' claims and no public API for data collection (2fas-probe-rt-1, 2fas-probe-rt-2), which implies user data isn't centrally harvested and thus couldn't feed AI training pipelines. However, there is no explicit statement addressing AI model training or an opt-out policy specifically. Missing for 10: explicit AI-training data policy/opt-out statement, independent confirmation that no data is ever sent to third-party AI services.

                        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                        • [probe] PROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... …
                      3. ai-native userControl data retention and deletion

                        weight 2 · round to Ente Auth
                        Ente Authpartialprobed7/10

                        Ente Auth lets users delete/trash codes with recovery or permanent deletion (docs-18/33/38), control backup location and encryption (docs-9/10), run fully offline with no cloud retention (doc-7), and export/decrypt all data via the official CLI for full portability (docs-11, probe-rt-1). However there's no explicit documentation on cloud-side account/data deletion policies or retention periods for encrypted server backups. Missing for 10: documented cloud account deletion/retention policy, independent confirmation of full data erasure on request.

                        • [claimed-docs] You can now trash codes that you don't need. ... You can recover codes from here, in case of accidental deletions, or delete them permanentl…
                        • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.
                        • [claimed-docs] You can now trash codes that you don't need. These items will be moved to a separate section within the app, under the "Trash" header.
                        • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                        • [claimed-docs] Custom backup location: Choose where to store your backups on your device.
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…

                        2FAS gives users explicit control over where data is stored (own cloud, external drive, self-hosting) and confirms no telemetry/tracking, which supports retention control (2fas-docs-5, 2fas-docs-14, 2fas-probe-rt-2). However there is no explicit documentation of a deletion/erasure workflow, data-retention policy, or account-deletion mechanism beyond implied local file control. Missing for 10: explicit data deletion/right-to-erasure documentation, retention period policy, and independent confirmation that deleting local/cloud copies fully removes data.

                        • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                        • [claimed-docs] Freedom to self-host your data
                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                        • [probe] PROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... …
                      4. ai-native userOpt out of telemetry and usage tracking

                        weight 2 · round to 2FAS
                        Ente Authnone0/10

                        No evidence pack mentions any telemetry, analytics, or usage-tracking settings, opt-out toggles, or privacy policy statements about data collection in Ente Auth; the evidence covers import/export, backups, and sync features only.

                          2FAS explicitly states in its machine-readable pricing/docs that 2FAS Auth has 'no advertising, no telemetry,' meaning tracking is absent by design rather than requiring opt-out, and the product is positioned as local-first/open-source, reinforcing a privacy-first posture. Missing for 10: no explicit dedicated privacy-settings toggle documentation, and no independent audit confirming zero telemetry across 2FAS Pass as well as Auth.

                          • [probe] PROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... …
                          • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…

                        Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture

                        How it protects itself — app lock, E2EE design, audits, breach alerting

                        App lock

                        1. everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

                          weight 2 · round to Ente Auth
                          Ente Authfullclaimed8/10

                          Docs explicitly confirm FaceID lock (Settings → Security → Lockscreen) and a custom lock screen supporting PINs and passwords, directly matching the story's biometric/PIN app-lock requirement. missing for 10: no independent/hands-on confirmation that the lock actually blocks access on a borrowed device, and no mention of Android biometric or desktop lock parity beyond FaceID/PIN.

                          • [claimed-docs] You can enable FaceID lock under Settings → Security → Lockscreen.
                          • [claimed-docs] You can now further protect your codes with a custom lock screen that supports PINs and passwords.
                          2FASnone0/10

                          The evidence pack describes 2FAS Pass's tiered security and sync options, and confirms access to the browser extension/autofill must be approved in-app, but nowhere states that the 2FAS Auth or Pass app itself can be locked behind biometrics or a PIN to block access if the phone is borrowed. No docs or community evidence mention an app-lock/biometric-gate feature for the authenticator itself.

                          • [claimed-docs] 2FAS Pass supports 3 Security Tiers for protecting your Items.
                          • [claimed-docs] Access through the Browser Extension or using Autofill must be confirmed in 2FAS Pass.

                        Audits

                        1. security engineerThe vendor publishes independent security audits of the app and its sync protocol

                          weight 2 · round drawn
                          Ente Authnone0/10

                          No evidence pack item references any independent security audit of Ente Auth or its sync protocol; documentation focuses on features, encryption claims, and migration, not third-party audit reports.

                            2FASnone0/10

                            Evidence shows only open-source code availability claims and general transparency messaging, with no mention of independent third-party security audits of the app or its sync protocol; community discussion even questions the trust model of cloud-based sync without referencing any audit report.

                            • [claimed-docs] You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
                            • [claimed-docs] Join our GitHub project and contribute to 2FAS by running code review and committing your ideas.
                            • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…

                          Monitoring

                          1. power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

                            weight 2 · round drawn
                            Ente Authnone0/10

                            Ente Auth is a TOTP/HOTP authenticator app; nothing in the evidence pack shows breach-monitoring, weak/reused-credential detection, or exposure alerts — its documented features are around code storage, import/export, sharing, and lockscreen security.

                              2FASnone0/10

                              No evidence of breach monitoring, weak/reused/exposed password detection, or security-posture alerts anywhere in the docs, community reports, or probes; 2FAS's evidence covers sync, tiers, self-hosting, and import/export but nothing about credential health warnings or breach alerts.

                              Push

                              1. it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

                                weight 2 · round drawn
                                Ente Authnone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  2FASnone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting

                                  Running it yourself — self-hosted servers, open-source clients

                                  Server

                                  1. it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter

                                    weight 2 · round to Ente Auth
                                    Ente Authpartialprobed6/10

                                    Ente explicitly documents running the Auth server locally (e.g. at http://localhost:3003) and its server code is confirmed open source, supporting self-hosting for IT admins wanting to keep secrets in-perimeter. However, the evidence pack lacks detailed self-hosting setup docs (Docker/compose instructions, hardware requirements, upgrade/security guidance) and no independent community reports specifically about self-hosting the Auth server (only cloud usage is discussed in community threads). Missing for 10: full self-hosting deployment guide, independent hands-on verification of self-hosted Auth server, and security/perimeter assurances specific to self-hosted mode.

                                    • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                                    • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                                    • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…

                                    2FAS advertises 'freedom to self-host your data' and lets users choose where encrypted vault/token data lives (own cloud, WebDAV, external drive) rather than relying on 2FAS-hosted storage, which partially satisfies the perimeter-control need. However there is no evidence of an actual downloadable/self-hostable 'sync server' component (e.g. a Vaultwarden-style server binary) — it's more bring-your-own-storage for encrypted files/backups, and community commentary explicitly questions whether this differs meaningfully from relying on third-party server infrastructure. Missing for 10: a dedicated self-hosted sync-server artifact/deployment docs, and independent confirmation that all sync traffic stays fully within admin-controlled infra.

                                    • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                                    • [claimed-docs] Freedom to self-host your data
                                    • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…

                                  Source

                                  1. security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed

                                    weight 2 · round to 2FAS
                                    Ente Authfullprobed7/10

                                    Ente's own llms.txt explicitly states 'Ente's apps and server are open source,' and a community poster on HN independently confirms 'thank you for releasing it open source,' corroborating that the client code is publicly available for inspection. Missing for 10: a direct link/reference to the actual auth client source repo, and independent evidence of community security review or audits of the seed-handling code.

                                    • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                                    • [community] This looks quite nice, thank you for releasing it open source... One note as I signed up for an account is that the email verification went …

                                    2FAS explicitly markets itself as open-source and points to a public GitHub repo for code review, including for the browser extension backend ('delve deep into the intricacies'), and invites community contribution/code review. The core apps (2FAS Auth, described as 'Free, Open-source 2FA Authenticator App') are confirmed open-source via probe data. Missing for 10: no independent security audit report or third-party code-review corroboration is cited, and evidence doesn't explicitly confirm the mobile app repos (vs. just extension) are inspectable.

                                    • [claimed-docs] You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository
                                    • [claimed-docs] Join our GitHub project and contribute to 2FAS by running code review and committing your ideas.
                                    • [claimed-docs] Check out our GitHub repository and delve deep into the intricacies of the browser extension back-end.
                                    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…

                                  Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces

                                  Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

                                  Automation

                                  1. ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

                                    weight 2 · round drawn
                                    Ente Authnone0/10

                                    Evidence only shows a CLI for exporting/backing up and decrypting Ente Auth data (ente-auth-docs-11, ente-auth-probe-rt-1), not for programmatically retrieving a live/current TOTP code for use in an automated 2FA login. No API, CLI subcommand, or docs describe generating a real-time code for agent consumption.

                                    • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                    • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                    • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                                    2FASnone0/10

                                    The evidence explicitly states 2FAS has no public API for programmatic TOTP retrieval ('Public API: None — local-first by design, no agent-callable endpoint for token generation'), and no CLI is documented anywhere in the pack; OpenAPI probes all 404. This directly rules out agent-driven fetching of TOTP codes via CLI or API.

                                    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                    • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…
                                  2. ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

                                    weight 1 · round drawn
                                    Ente Authnone0/10

                                    No evidence of any local API, IPC endpoint, or programmatic interface for querying codes; the only related tooling is the export/backup CLI (docs-11, probe-rt-1), which produces files rather than a queryable local endpoint an agent could hit live. No OpenAPI/local server documentation was found (probe-3 confirms no openapi endpoint).

                                    • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                    • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                    • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                                    2FASnone0/10

                                    The product's own llms.txt explicitly states 'Public API: None' and no OpenAPI/local endpoint was found; 2FAS is local-first by design with no agent-callable interface for querying codes or secrets programmatically.

                                    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                    • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…

                                  Browser

                                  1. everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

                                    weight 2 · round to 2FAS
                                    Ente Authnone0/10

                                    No evidence of a browser extension for Ente Auth; the product is described as apps for mobile, desktop and web with manual QR-scan/setup-key entry, not autofill via a browser extension for TOTP or passkeys during login.

                                      2FAS's browser extension is documented to autofill TOTP tokens with confirmation via the mobile app ('You don't have to retype anything'), and the 2FAS Pass extension supports autofill for passwords/passkeys confirmed in the vault app, with the free tier confirmed by community reports to include auto-fill. However, evidence is vendor-documented with only partial independent corroboration and no explicit hands-on confirmation of passkey autofill specifically working smoothly in-browser. Missing for 10: independent hands-on validation of passkey autofill UX, more detail on cross-browser support, and confirmation of friction-free flow beyond vendor claims.

                                      • [claimed-docs] Click the browser extension icon when you need to enter a 2FA token, then confirm in the mobile app. You don't have to retype anything.
                                      • [claimed-docs] Access through the Browser Extension or using Autofill must be confirmed in 2FAS Pass.
                                      • [community] Free tier of 2FAS Pass includes auto-fill, import/export, and standard password generator; paid tier adds multi-device sync, more than 200 v…
                                      • [claimed-docs] You can easily take a look at our code - reflecting our transparent and user-first approach. Check out our GitHub repository

                                    Desktop

                                    1. power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile

                                      weight 2 · round to Ente Auth
                                      Ente Authfullcommunity7/10

                                      Ente Auth explicitly ships native desktop clients (Flathub Linux app, plus 'app for every platform: Mobile, desktop and web' with full sync) and desktop-specific UI features like right-click code editing, matching a first-class desktop experience; a HN user corroborates switching to it specifically for its desktop app after Authy dropped theirs. missing for 10: explicit list/docs of Windows/Mac desktop builds beyond Flathub, and an independent hands-on review confirming full feature parity with mobile.

                                      • [claimed-docs] Auth is now officially available on [Flathub](https://flathub.org/apps/io.ente.auth)!
                                      • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                      • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.
                                      • [community] Ente Auth is awesome - I've been using it ever since Authy discontinued their desktop app.
                                      2FASnone0/10

                                      Evidence only shows mobile apps (iOS/Android) plus a browser extension, and the extension explicitly requires confirmation via the mobile app (2fas-docs-3, 2fas-docs-19) rather than functioning as an independent desktop client. No native desktop app for code generation or vault access is documented anywhere in the pack.

                                      • [claimed-docs] Click the browser extension icon when you need to enter a 2FA token, then confirm in the mobile app. You don't have to retype anything.
                                      • [claimed-docs] Access through the Browser Extension or using Autofill must be confirmed in 2FAS Pass.
                                      • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…

                                    Watch

                                    1. everyday userRead my codes from my smartwatch without pulling out my phone

                                      weight 1 · round to 2FAS
                                      Ente Authnone0/10

                                      The evidence pack covers mobile/desktop/web platform support, import/export, sharing, and lockscreen features, but contains no mention of smartwatch (e.g. Wear OS, watchOS) support or companion app for viewing codes without pulling out a phone.

                                        2FAS explicitly markets 'Apple Watch — Improved convenience and accessibility' as a feature, indicating watch support exists, but there's no detail on what functionality is available on the watch (e.g., whether codes are viewable standalone or require phone proximity) and no independent/hands-on confirmation of the experience. missing for 10: details on watch app functionality/UX, confirmation codes can be read without unlocking phone, independent hands-on review of the watch experience.

                                        • [claimed-docs] Apple Watch Improved convenience and accessibility.
                                        • [claimed-docs] Apple WatchImproved convenience and accessibility.

                                      Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup

                                      Not losing your accounts — encrypted backup, multi-device sync, recovery

                                      Backup

                                      1. security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

                                        weight 3 · round to Ente Auth
                                        Ente Authpartialprobed6/10

                                        Ente docs state cloud backups are end-to-end encrypted (docs-27, docs-34) and local backups are encrypted with a password-derived key that Ente cannot recover (docs-9, docs-12), plus open-source apps/server are confirmed (probe-rt-2), supporting a 'vendor never holds key' claim. However there is no detailed cryptographic design doc (key derivation algorithm, protocol specifics, audit report) in the evidence, only high-level marketing/FAQ statements. Missing for 10: a published encryption whitepaper or technical spec, and independent security audit/corroboration of the E2E design.

                                        • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                        • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                        • [claimed-docs] the data is encrypted using a key derived from the user's password
                                        • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …

                                        2FAS documents that backups/sync can be encrypted with a user password (docs-9, docs-17, docs-18) and that vault storage location is user-controlled, but the encryption is presented as optional ('we encourage you to do that') rather than guaranteed end-to-end by default, and there is no detailed technical whitepaper describing key derivation, zero-knowledge architecture, or threat model. Community discussion (2fas-comm-1) explicitly questions whether backups to iCloud/WebDAV truly avoid vendor/server trust, further undercutting a strong E2E claim. missing for 10: a dedicated cryptographic design document (algorithms, key derivation, zero-knowledge proof), confirmation that encryption is mandatory/default rather than opt-in, and independent security audit corroboration.

                                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                                        • [claimed-docs] Multi-device sync (encrypted)
                                        • [claimed-docs] If you have enabled sync with iCloud (on iOS) or Google Drive (on Android), your encrypted 2FAS Pass Vault file is right there.
                                        • [claimed-docs] You decide where to store your Items. You can store it in your own cloud or keep it as an encrypted file on an external drive.
                                        • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…

                                      Multi device

                                      1. everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

                                        weight 2 · round to Ente Auth
                                        Ente Authfullcommunity8/10

                                        Ente Auth explicitly advertises multi-platform apps (mobile, desktop, web) with end-to-end encrypted cloud sync so codes stay in sync across devices, and community evidence corroborates real-world use across app switches without complaint about sync failures. Missing for 10: independent hands-on confirmation of real-time multi-device sync latency/reliability and any edge-case sync bugs reported by users.

                                        • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                        • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                        • [community] Ente Auth is awesome - I've been using it ever since Authy discontinued their desktop app.
                                        • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …

                                        2FAS documents syncing tokens across devices via iCloud/Google Drive and lists 'Multi-device sync (encrypted)' as a feature, and computer access is possible through a browser extension that confirms via the mobile app. However, this cross-device access relies on manual confirmation from the phone rather than tokens being independently and automatically available on a tablet/computer at all times, and multi-device sync appears gated behind a paid tier for the Pass product. Missing for 10: evidence of true simultaneous, always-available token access across phone/tablet/computer without per-use phone confirmation, and confirmation that Auth (not just Pass) multi-device sync is free and automatic.

                                        • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                                        • [claimed-docs] Click the browser extension icon when you need to enter a 2FA token, then confirm in the mobile app. You don't have to retype anything.
                                        • [claimed-docs] Multi-device sync (encrypted)
                                        • [community] Free tier of 2FAS Pass includes auto-fill, import/export, and standard password generator; paid tier adds multi-device sync, more than 200 v…

                                      Recovery

                                      1. everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

                                        weight 3 · round drawn
                                        Ente Authfullprobed8/10

                                        Ente Auth documents end-to-end encrypted cloud sync/backups so codes restore on a new device after login, plus a recovery key to bypass 2FA lockouts, local encrypted backups, and a CLI export tool as additional restore paths. missing for 10: no independent hands-on account of a real device-loss recovery walkthrough, and no detail on exact steps to restore cloud-synced codes on a fresh device beyond general sync claims.

                                        • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                        • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                        • [claimed-docs] We recommend that you ensure you store your recovery key in a safe place (writing it down on a paper is a good idea). This key can be used t…
                                        • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                        • [community] Ente has free backups and it's own encrypted export format, which sounds promissing.

                                        2FAS documents multi-device sync via iCloud/Google Drive/encrypted export files for the Auth app, plus a dedicated recovery page explaining how to restore or run the Pass Vault on a new device using the cloud-synced encrypted vault file, and supports importing from other authenticator apps for migration scenarios. This directly addresses losing a phone and restoring tokens elsewhere, though community commentary raises trust questions about relying on third-party cloud storage rather than disputing that recovery works. Missing for 10: independent hands-on verification of the actual recovery flow succeeding, and clearer detail on recovery when no cloud sync was enabled beforehand.

                                        • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                                        • [claimed-docs] Learn how to restore access to your 2FAS Pass Vault or run it on a different device.
                                        • [claimed-docs] If you have enabled sync with iCloud (on iOS) or Google Drive (on Android), your encrypted 2FAS Pass Vault file is right there.
                                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.
                                        • [claimed-docs] We support imports from Aegis, Raivo, LastPassAegis, Stratum (formerly Authenticator Pro) and Google Authenticator.
                                        • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…

                                      Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin

                                      Shared and managed use — shared vaults, org policies, programmatic provisioning

                                      Automation

                                      1. ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

                                        weight 2 · round drawn
                                        Ente Authnone0/10

                                        Evidence shows only manual QR-scan/setup-key entry, GUI import/export, and a CLI limited to exporting and decrypting backups—no documented API, SDK, or CLI subcommand for programmatically creating or updating vault entries. No OpenAPI/API surface was found (ente-auth-probe-3 confirms no openapi.json), so an agent has no documented programmatic surface to seed or update TOTP secrets.

                                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                        • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                                        • [claimed-docs] Scan the QR code shown by the service.
                                        • [claimed-docs] Enter the account name, issuer, and secret (setup key).
                                        2FASnone0/10

                                        No programmatic API exists for creating/updating vault entries or seeding TOTP secrets; the product's own llms.txt explicitly states 'Public API: None' and openapi probes all 404, confirming no agent-callable surface for this workflow.

                                        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                        • [probe] PROBE openapi: all candidate paths 404 (https://2fas.com/openapi.json, https://2fas.com/swagger.json, https://2fas.com/api/openapi.json, htt…

                                      Policy

                                      1. it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

                                        weight 1 · round drawn
                                        Ente Authnone0/10

                                        No evidence of any org-wide admin console, centralized policy enforcement, mandated master password strength, or app lock/export restrictions applied across members — Ente Auth is a personal/individual authenticator with local lock screen (per-device) and personal backup/export options, not a managed enterprise policy tool.

                                        • [claimed-docs] You can now further protect your codes with a custom lock screen that supports PINs and passwords.
                                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                        2FASnone0/10

                                        2FAS is a consumer-focused authenticator/password manager with no evidence of centralized org policy management, admin dashboards, enforced app-lock policies, export restrictions, or credential strength mandates across users; it is explicitly local-first with no public API for such control (2fas-probe-rt-1). No IT-admin console or MDM/policy feature is documented anywhere in the pack.

                                        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                        • [claimed-docs] Freedom to self-host your data
                                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.

                                      Sharing

                                      1. it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control

                                        weight 2 · round to Ente Auth
                                        Ente Authpartialclaimed4/10

                                        Ente Auth documents sharing individual TOTP codes via temporary, end-to-end encrypted links with teammates (docs-16, docs-35), and explicitly restricts sharing to TOTP (not HOTP) entries (docs-30), which covers the core 'share TOTP logins with team' idea. However there is no evidence of a vault/collection construct or per-member access control (e.g., role-based permissions, group vaults, admin-managed membership) — sharing appears to be per-code link generation rather than an admin-managed shared vault. Missing for 10: evidence of collection/vault-based sharing, per-member access control or roles, and admin management console for team access.

                                        • [claimed-docs] You can now easily share specific codes with your team, with temporary links that are end-to-end encrypted.
                                        • [claimed-docs] Share codes with your team securely
                                        • [claimed-docs] Sharing is now limited to TOTP codes; the share option is hidden for HOTP entries.
                                        2FASnone0/10

                                        2FAS is positioned as a personal, local-first authenticator/password manager with individual sync (iCloud/Google Drive/self-host) and multi-device sync for a single user, not team/organization features. No evidence of shared vaults, collections, or per-member access control for an IT-admin-managed team; the HN community discussion even questions its single-user 'local-only' security model, but nothing addresses team sharing at all.

                                        • [claimed-docs] Synchronize your Tokens with 2FAS export files, iCloud or Google Drive.
                                        • [claimed-docs] Multi-device sync (encrypted)
                                        • [community] Skeptical about 'local-only' claim: 2FAS Pass supports backups to iCloud, WebDAV and local file, meaning passwords rely on a server's securi…
                                        • [community] Free tier of 2FAS Pass includes auto-fill, import/export, and standard password generator; paid tier adds multi-device sync, more than 200 v…

                                      Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core

                                      The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

                                      Enrollment

                                      1. everyday userScan a QR code and immediately start generating TOTP codes for a new account

                                        weight 3 · round to Ente Auth
                                        Ente Authfullclaimed8/10

                                        Docs explicitly describe scanning a QR code shown by a service to add a new account, both generally (docs-1) and for specific migration flows (docs-6/41), which immediately generates TOTP codes in the app. This core flow is directly and simply documented as the primary onboarding method. Missing for 10: independent hands-on confirmation of the exact scan-to-code-generation moment and any UX friction reports.

                                        • [claimed-docs] Scan the QR code shown by the service.
                                        • [claimed-docs] Enter the account name, issuer, and secret (setup key).
                                        • [claimed-docs] Tap the add button and scan the QR code shown by the service.
                                        • [claimed-docs] Open Ente Auth. Tap the add button and scan the QR code shown by the service.

                                        2FAS Auth is a well-known TOTP app and docs reference connecting accounts via video tutorials, but the evidence pack lacks any direct documentation or hands-on confirmation of the core QR-scan-to-code-generation flow. missing for 10: explicit documentation/screenshots of QR scanning UX, confirmation that codes generate immediately post-scan, independent/hands-on corroboration of the onboarding flow.

                                        • [claimed-docs] use our quick and easy-to-follow video tutorials to connect your online accounts.
                                        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…

                                      Offline

                                      1. power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes

                                        weight 2 · round drawn
                                        Ente Authfullclaimed8/10

                                        Docs explicitly confirm offline mode with no account required, codes stored only on-device, and no network dependency for viewing codes. Missing for 10: independent hands-on verification (e.g. airplane-mode test) beyond vendor docs, and no detail on how backups/imports work fully offline without any cloud touchpoint.

                                        • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                                        • [claimed-docs] Use without an account

                                        2FAS Auth is described as open-source, local-first with no public API for token generation, and pricing docs confirm it's free with no telemetry, consistent with fully offline TOTP generation without vendor account requirement. Community evidence questions cloud-sync/backup security but this concerns 2FAS Pass (password manager), not the core Auth TOTP generation flow. missing for 10: independent hands-on confirmation that TOTP codes generate with device fully offline (airplane mode test), and explicit documentation stating no account/signup is ever required.

                                        • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                        • [probe] PROBE runtime (recorded 2026-09-15): machine-readable pricing verified live at https://2fas.com/.well-known/pricing.md — '# 2FAS Pricing... …
                                        • [claimed-docs] data can be encrypted with your password, so we encourage you to do that.

                                      Organization

                                      1. power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

                                        weight 2 · round drawn
                                        Ente Authpartialclaimed6/10

                                        Ente Auth's marketing docs confirm search (deep-link search feature), service icons, and favoriting/organizing features ('Organize with ease', 'Favorite services to the top', 'Don't scroll'), directly supporting quick access to tokens. However, there is no concrete evidence of folder or group/category organization for large token sets — only vague 'organize with ease' copy and free-text notes (500-char annotations), not structured grouping. Missing for 10: explicit folder/category/tagging feature documentation, evidence of grouping many tokens, independent hands-on confirmation of organization UX at scale.

                                        Docs confirm token customization with 'full control over groups, badges, icons, and labels' and Apple Watch access, directly supporting organization by groups/icons for quick access, but there is no mention of search functionality within the token list, no detail on folder/group UX depth, and no independent hands-on account of managing 'dozens of tokens' at scale. missing for 10: explicit search feature evidence, hands-on/independent validation of organization UX at scale, deeper detail on folder vs group implementation.

                                        • [claimed-docs] Token customization Full control over the groups, badges, icons, and labels.
                                        • [claimed-docs] Token customizationFull control over the groups, badges, icons, and labels.
                                        • [claimed-docs] Apple Watch Improved convenience and accessibility.
                                        • [claimed-docs] Apple WatchImproved convenience and accessibility.

                                      Variants

                                      1. power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

                                        weight 2 · round to Ente Auth
                                        Ente Authpartialclaimed4/10

                                        Evidence confirms HOTP entries are supported (the changelog notes sharing is now limited to TOTP and hidden for HOTP entries), implying native HOTP counter support. However, there is no mention anywhere in the evidence pack of Steam Guard token support, or of custom period/digit-length configuration for TOTP entries. missing for 10: explicit Steam Guard support, custom period/digit-length configuration, and any hands-on confirmation beyond the changelog note.

                                        • [claimed-docs] Sharing is now limited to TOTP codes; the share option is hidden for HOTP entries.
                                        2FASnone0/10

                                        No evidence in the pack addresses Steam Guard tokens, HOTP counter-based codes, or custom period/digit-length configuration for 2FAS Auth — the docs only mention generic 'token customization' for groups/badges/icons/labels, which is unrelated to non-standard token algorithms.

                                        • [claimed-docs] Token customization Full control over the groups, badges, icons, and labels.
                                        • [claimed-docs] Token customizationFull control over the groups, badges, icons, and labels.

                                      Not comparable on these axes

                                      1. ai-native userPlug MCP servers into this product so it can use their tools

                                        weight 3 · not comparable
                                        Ente Authn/a

                                        Ente Auth is a 2FA/authenticator app; MCP server plugin capability is unrelated to its product category and no evidence suggests otherwise.

                                          2FASn/a

                                          2FAS is a password manager/2FA authenticator app, not an AI agent or platform with MCP tool-plugin capability; the product's own docs explicitly state 'Public API: None' and it has no agent/tool-integration surface. Plugging MCP servers into it for tool use is a category error for this product type.

                                          • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                        • ai-native userSubscribe to events via webhooks

                                          weight 2 · not comparable
                                          Ente Authn/a

                                          Ente Auth is a 2FA/authenticator app with no evidence of any event-driven webhook or subscription API; webhooks are not a fit category axis for this type of product (offline/encrypted code storage tool), and no evidence suggests it exposes such a system.

                                            2FASnone0/10

                                            2FAS is explicitly local-first with no public API ('Public API: None' per its own llms.txt), and no evidence anywhere mentions webhooks or event subscriptions; this is a password/2FA app, not an event-driven platform.

                                            • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                          • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                            weight 2 · not comparable
                                            Ente Authn/a

                                            Ente Auth is a 2FA/authenticator app; there is no evidence of any AI-generated insights or suggestions feature, and this is not a category where such analytics would be a fair expected axis — the product's scope is encrypted TOTP/HOTP code storage and sync, not data analysis.

                                              2FASn/a

                                              2FAS is a 2FA authenticator/password manager focused on secure credential storage and sync, not a data-analytics or AI-insights product; there is no dataset or usage history it analyzes to generate suggestions. The evidence explicitly confirms it has no public API and is local-first by design, reinforcing that AI-generated insights are outside its product category.

                                              • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                            • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                              weight 3 · not comparable
                                              Ente Authn/a

                                              Ente Auth is a 2FA/authenticator app with no AI assistant or agent-delegation feature of any kind in its evidence; delegating tasks to a built-in AI assistant is outside this product's category entirely.

                                                2FASn/a

                                                2FAS is a 2FA authenticator/password manager with no built-in AI assistant feature; delegating tasks to an AI assistant is not a fair axis for this product category. Evidence even confirms 'Public API: None' and no agent-callable endpoints, reinforcing this is out of scope rather than a missing feature.

                                                • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                              • ai-native userTest against a sandbox environment without touching production data

                                                weight 1 · not comparable
                                                Ente Authn/a

                                                Ente Auth is a 2FA code manager, not an API/platform product with sandbox/test environments; the notion of testing against a sandbox vs production data is a category mismatch for this type of app.

                                                  2FASn/a

                                                  2FAS is a consumer password/2FA manager with no API or developer sandbox concept; there's no test/production data separation to speak of since it's local-first with no public API ('Public API: None'). This story targets developer-platform/agentic products with sandbox environments, which is a category error for a personal auth app.

                                                  • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                                • ai-native userDefine rules that trigger actions automatically on events

                                                  weight 3 · not comparable
                                                  Ente Authn/a

                                                  Ente Auth is a 2FA/TOTP authenticator app; it has no rule engine, event triggers, or automation/workflow features—this is a category mismatch, not a missing feature of an automation product.

                                                    2FASn/a

                                                    2FAS is a local-first authenticator/password manager with no public API or event-driven automation surface (llms.txt explicitly declares 'Public API: None'); rule-based automation triggers are outside the scope of what this product category offers.

                                                    • [probe] PROBE runtime (recorded 2026-09-15): 2fas.com serves the most agent-forward docs plumbing in the arena — llms.txt with a literal 'For AI age…
                                                  • ai-native userSchedule recurring jobs or workflows

                                                    weight 2 · not comparable
                                                    Ente Authn/a

                                                    Ente Auth is a 2FA/TOTP code manager; scheduling recurring jobs or workflows is not a fair capability for this product category — it has no workflow/automation engine.

                                                      2FASn/a

                                                      2FAS is a 2FA authenticator/password manager with no workflow/job automation or scheduling engine; recurring job scheduling is outside its product category entirely.

                                                      • ai-native userVersion, review, and roll back my automations

                                                        weight 1 · not comparable
                                                        Ente Authn/a

                                                        Ente Auth is a 2FA/authenticator app, not an automation platform; there is no concept of 'automations' to version, review, or roll back in this product's domain.

                                                          2FASn/a

                                                          2FAS is a 2FA authenticator/password manager, not an automation or workflow tool; there is no concept of automations to version, review, or roll back in this product category.