Skip to content

Authenticator Apps Arena

Proton Pass vs Ente Auth

Ente Auth wins · 1619 (12 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round to Ente Auth
    Proton Passnone0/10

    No llms.txt or agent-oriented docs found; probes explicitly return 404 for llms.txt and docs.md endpoints, and no evidence mentions agent-readable documentation formats.

    • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
    Ente Authfullprobed7/10

    Ente serves a live llms.txt at ente.com/llms.txt confirmed by two independent probes, giving an agent a fair entry point; however, docs-as-markdown and OpenAPI endpoints 404, so agent-oriented documentation beyond the single llms.txt file is thin. missing for 10: markdown-served docs pages, OpenAPI/agent-consumable API spec, broader agent-oriented doc structure beyond one root file.

    • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
    • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
    • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
    • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Proton Pass
    Proton Passpartialprobed6/10

    Proton Pass ships an official CLI documented as designed for scripts, deployments, and CI/CD pipelines, supporting CRUD on vaults and items — a clear headless/automation capability. However, evidence is limited to vendor blog docs with no independent/hands-on corroboration of CI usage, no details on authentication flow for non-interactive/headless environments, and no community validation of real-world CI deployment. Missing for 10: independent hands-on CI usage reports, details on non-interactive auth/session handling for automation, and broader ecosystem examples (e.g., GitHub Actions integration).

    • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
    • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
    • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
    • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
    Ente Authpartialprobed3/10

    Ente provides an official CLI (ente-cli) that can run headlessly to export/backup Auth codes, which is scriptable and could be used in automation/CI contexts, but evidence only documents it for exporting/decrypting backups, not for generic headless operation, generating TOTP codes on demand, or CI-integrated workflows. Missing for 10: documentation of CLI usage for retrieving/generating codes programmatically, CI-specific examples, and any first-party statement about automation/agentic use beyond backup.

    • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
    • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
  3. ai-native userConnect an agent via an official MCP server

    weight 3 · round drawn
    Proton Passnone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Ente Authnone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      • ai-native userUse an official CLI

        weight 2 · round to Proton Pass
        Proton Passfullprobed7/10

        Proton Pass has an official CLI documented in a first-party blog post that supports CRUD on vaults and items (including SSH keys) and secret retrieval for scripts/CI/CD pipelines, which is directly relevant to AI-native/agentic automation workflows. Missing for 10: independent/hands-on corroboration of the CLI's reliability, no mention of AI-agent-specific integrations or MCP-style tooling, and no detail on scripting API depth or language bindings.

        • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
        • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
        • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
        Ente Authpartialprobed6/10

        Ente ships an official CLI (github.com/ente/ente/tree/main/cli) confirmed to be packaged via Homebrew as 'ente-cli', documented as scriptable tooling to 'automatically backup your Auth codes' and decrypt exports — this is a real, official, automatable interface. However it is scoped narrowly to backup/export/decrypt operations rather than full account/code management or general agentic control. Missing for 10: broader CLI command coverage (add/edit/delete codes, sharing, sync), first-party docs detailing CLI usage beyond export, and independent hands-on reports of using it in automated/agentic workflows.

        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
      • ai-native userDrive the product through a documented public API

        weight 3 · round to Proton Pass
        Proton Passpartialprobed5/10

        Proton Pass offers a CLI for CRUD operations on vaults and items (passwords, notes, SSH keys, etc.) usable in scripts/CI pipelines, which provides programmatic access, but this is a CLI wrapper rather than a documented public REST/GraphQL API with SDKs, and llms.txt/docs.md probes both 404. missing for 10: a formal public API specification (REST/GraphQL/SDK), API reference docs, and independent developer corroboration of programmatic/agentic use beyond the CLI.

        • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
        • [claimed-docs] Create, read, update, and delete vaults
        • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
        • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
        • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
        • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
        Ente Authpartialprobed3/10

        Ente provides a CLI (ente-cli) for exporting/backing up Auth codes and a documented deep-link scheme (enteauth://search), but there is no documented public REST/GraphQL API or SDK for driving the product programmatically — OpenAPI probes returned 404s. missing for 10: a documented public API/SDK covering core operations (add/edit/delete codes, sharing, sync), API authentication docs, and independent developer corroboration of API usage.

        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
        • [claimed-docs] Added support for search deep links via enteauth://search.
        • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
      • ai-native userIssue scoped/least-privilege API credentials for an agent

        weight 2 · round drawn
        Proton Passnone0/10

        Proton Pass CLI supports retrieving secrets/items for CI/CD and vault-level CRUD, but there is no evidence of issuing scoped or least-privilege API credentials/tokens specifically for an AI agent (e.g., fine-grained scopes, agent-specific permission tiers). Vaults provide organizational grouping, not credential scoping mechanisms for automated agents.

        • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
        • [claimed-docs] Create, read, update, and delete vaults
        • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
        Ente Authnone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        • ai-native userBuild against official SDKs

          weight 2 · round drawn
          Proton Passnone0/10

          Evidence shows only a CLI tool for secrets retrieval in CI/CD pipelines, not a developer SDK for building applications; no mention of SDKs, API libraries, or language bindings for programmatic integration exists in the evidence pack.

            Ente Authnone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            Agentic features

            1. ai-native userSet up automations that run autonomously in the background

              weight 2 · round drawn
              Proton Passnone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Ente Authnone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                • ai-native userOperate the product with natural-language commands

                  weight 2 · round drawn
                  Proton Passnone0/10

                  Proton Pass offers a CLI for scripted secret retrieval and CRUD operations, but there is no evidence of natural-language command support, AI assistant integration, or conversational interface anywhere in the docs or community discussion. Missing for 10: any NL command parsing, chat/AI interface, or agentic natural-language control.

                    Ente Authnone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Api quality

                    1. ai-native userExplore an interactive API reference with runnable examples

                      weight 2 · round drawn
                      Proton Passnone0/10

                      No evidence of an interactive API reference or runnable examples; documentation covers CLI usage and product features only, and probes for docs/llms.txt endpoints returned 404. Missing for 10: interactive API reference, runnable code examples, developer API docs portal.

                      • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
                      • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
                      • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                      Ente Authnone0/10

                      No evidence of an interactive API reference or runnable examples; OpenAPI/swagger probes returned 404s and no developer API docs are mentioned anywhere in the pack.

                      • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                      • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
                    2. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                      weight 2 · round drawn
                      Proton Passnone0/10

                      No evidence of a machine-readable API spec (OpenAPI or similar); only a CLI tool for scripts/CI/CD is documented, and probes for llms.txt and docs-md endpoints both returned 404.

                      • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
                      • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
                      • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                      Ente Authnone0/10

                      Probe results explicitly show all candidate OpenAPI/Swagger paths return 404, and there is no documented machine-readable API spec anywhere in the evidence pack; missing for 10: any published OpenAPI/Swagger file, API reference docs, or equivalent machine-readable spec.

                      • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                    3. ai-native userRely on versioned APIs with a documented deprecation policy

                      weight 2 · round drawn
                      Proton Passnone0/10

                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        Ente Authnone0/10

                        Ente Auth is a 2FA authenticator app; there is no evidence of a public API, API versioning scheme, or documented deprecation policy — OpenAPI probes 404 and no API docs exist in the evidence pack.

                        • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                        • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md

                      Automation depth — how much of the product can run unattendedAutomation depth

                      How much of the product can run unattended

                      1. ai-native userPerform bulk operations across many items at once

                        weight 2 · round to Proton Pass
                        Proton Passpartialclaimed5/10

                        The official CLI supports scripted CRUD on vaults and items (passwords, notes, SSH keys, etc.) which could be used to script bulk operations, and the import/export tools allow migrating many items at once. However, there is no documented explicit 'bulk edit/delete/tag' feature or batch API, and no community evidence of anyone actually scripting bulk operations at scale. Missing for 10: dedicated bulk-action API/UI, documented batch limits, and independent confirmation of large-scale scripted use.

                        • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                        • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                        • [claimed-docs] Create, read, update, and delete vaults
                        • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.
                        • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                        Ente Authpartialprobed4/10

                        Ente Auth documents bulk import from other 2FA apps and a CLI tool for scripted export/backup of all codes, which supports some automation-depth for a bulk operation, but there is no evidence of programmatic bulk editing, deleting, or tagging across many stored codes at once (only single-item edit/delete via long-press is documented). missing for 10: bulk edit/delete/tag API or CLI beyond import/export, evidence of scripted multi-item management, independent hands-on confirmation of bulk workflows.

                        • [claimed-docs] Bulk import from other 2FA apps
                        • [claimed-docs] Ente Auth natively supports imports from many 2FA providers.
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                        • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.

                      Openness — open source, data portability, and self-hosting storiesOpenness

                      Open source, data portability, and self-hosting stories

                      1. ai-native userDo everything through the API that I can do in the UI

                        weight 2 · round to Proton Pass
                        Proton Passpartialprobed5/10

                        Proton Pass ships a CLI/API that supports CRUD on vaults and items (passwords, notes, cards, identities, SSH keys, custom items), enabling scripted/CI access similar to core UI functions. However, there's no evidence the CLI/API exposes other UI capabilities like vault sharing, TOTP generation, Pass Monitor/Sentinel checks, alias management, or emergency access. Missing for 10: API coverage for sharing, TOTP/2FA, monitoring, aliases, emergency access, and any independent confirmation of API completeness.

                        • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                        • [claimed-docs] Create, read, update, and delete vaults
                        • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                        • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                        Ente Authnone0/10

                        Ente Auth exposes only a CLI for exporting/decrypting backups, not a general API covering all UI actions (add/edit/share/organize codes, etc.); probes for OpenAPI/API docs all returned 404, and no documentation describes a comprehensive API surface.

                        • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                      2. ai-native userExport all of my data in open formats and leave

                        weight 3 · round to Proton Pass
                        Proton Passfullclaimed7/10

                        Proton Pass supports data export in multiple open, portable formats (unencrypted ZIP, CSV, PGP-encrypted JSON) allowing users to leave with their data, and also offers an import tool for migrating in from other managers. Missing for 10: independent hands-on verification of export completeness/fidelity, and no evidence of bulk API/CLI-based export for programmatic 'leave' workflows beyond CLI CRUD operations.

                        • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                        • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                        • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.

                        Ente ships an official CLI to export and decrypt Auth data and documents password-encrypted local backups, and some HN commenters confirm easy export/import between apps (comm-6,7,8; probe-rt-1). But a first-hand HN commenter explicitly states 'You cant easily export your codes into a different format using this app, meaning that it is difficult to migrate away' (comm-2), directly contradicting the frictionless open-format export claim. Missing for 10: a documented plain/open (non-proprietary) full export format, resolution of the lock-in complaint, and independent verification that CLI-exported data is usable outside Ente.

                        • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                        • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                        • [claimed-docs] the data is encrypted using a key derived from the user's password
                        • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                        • [community] I'm waiting for bitwarden or aegis export capability before trying this out. You cant easily export your codes into a different format using…
                        • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …
                        • [community] I think it has its own backup service. But it otherwise lets you export/import your data. I feel like as long as I can do an export in some …
                      3. ai-native userRead the product's source under an open license

                        weight 2 · round to Ente Auth
                        Proton Passpartialcommunity5/10

                        Community evidence confirms Proton Pass client apps are open source on GitHub (protonpass org), but users note this covers only the clients, not the full product/server-side, and there was confusion over whether it was truly open-sourced. No first-party docs in the pack mention a license or open-source repo at all. Missing for 10: official documentation citing the open-source license, confirmation that server/backend code is open, and clarity on license terms.

                        • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                        • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…
                        • [community] Please note that we do have encrypted notes... And it is open source: https://github.com/protonpass
                        Ente Authfullprobed7/10

                        Ente's own llms.txt explicitly states 'Ente's apps and server are open source,' and a GitHub repo (ente/ente) is referenced for the CLI/export tooling; independent HN commentary corroborates ('thank you for releasing it open source'). Missing for 10: explicit license name/text and a direct link to the license file are not shown in the evidence pack.

                        • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
                        • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                        • [community] This looks quite nice, thank you for releasing it open source... One note as I signed up for an account is that the email verification went …
                        • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                      4. ai-native userSelf-host the core product

                        weight 3 · round to Ente Auth
                        Proton Passnone0/10

                        No evidence anywhere in the docs pack of a self-hosted server option; Proton Pass is offered only as a hosted SaaS with client apps, and community comments confirm only the client apps are open source while the backend/server is closed ('only the clients are open source').

                        • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                        • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…
                        Ente Authfullprobed8/10

                        Ente explicitly documents self-hosting instructions, pointing users to run Ente Auth at localhost/machine-ip:3003, and the product is described as open source, consistent with independent verification via the llms.txt runtime probe. missing for 10: independent hands-on report of a full self-hosted deployment (beyond docs/probe), and details on self-hosting server setup/requirements beyond the port reference.

                        • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                        • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
                        • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …

                      Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support

                      Passkeys in the vault — storage, sign-in, cross-ecosystem sync

                      Storage

                      1. everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes

                        weight 3 · round to Proton Pass
                        Proton Passpartialclaimed6/10

                        Docs confirm Proton Pass supports passkeys for passwordless authentication and separately supports TOTP code generation, indicating both capabilities coexist rather than TOTP-only. However, there is no detailed description of the sign-in autofill flow for passkeys or independent/hands-on confirmation that passkey sign-in works reliably across sites/apps. Missing for 10: hands-on/community validation of passkey autofill and sign-in success, cross-platform passkey sync confirmation, and detail on browser/app integration for passkey use.

                        • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                        Ente Authnone0/10

                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        Sync

                        1. power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

                          weight 2 · round to Proton Pass
                          Proton Passpartialcommunity4/10

                          Proton Pass confirms passkey support (proton-pass-docs-8) and offers apps across iOS, Android, browsers, and a desktop app (with offline access per proton-pass-docs-9), implying cross-platform sync of vault items including passkeys. However, there's no explicit documentation confirming passkeys specifically sync across all platforms (vs. just being stored), and community comments note desktop app limitations/lack thereof at the time (proton-pass-comm-2, proton-pass-comm-14), raising doubt about full ecosystem parity. Missing for 10: explicit cross-platform passkey sync confirmation, Linux/Windows native app evidence beyond browser extensions, and independent hands-on verification that passkeys created on one platform are usable on another.

                          • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                          • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                          • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                          • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…
                          Ente Authnone0/10

                          Ente Auth is a TOTP/2FA code manager; the only passkey mention in evidence (doc-14) refers to passkey login for the separate Ente Photos account, not Ente Auth storing/syncing passkeys as credentials across iOS/Android/Windows/Linux/browsers. No evidence shows Ente Auth itself functions as a cross-platform passkey vault.

                          • [claimed-docs] Ente also offers [Legacy](/help/photos/features/legacy/) (emergency contacts) and support for [Passkeys](/help/photos/features/passkeys).
                          • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.

                        Portability — your secrets stay yours — open export, bulk import, device migrationPortability

                        Your secrets stay yours — open export, bulk import, device migration

                        Export

                        1. power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

                          weight 3 · round to Proton Pass
                          Proton Passpartialclaimed5/10

                          Proton Pass docs confirm a general data-export feature with multiple output options (PGP-encrypted ZIP, unencrypted ZIP, CSV), which supports the 'open, readable format' portability need, but no evidence explicitly confirms that TOTP secrets/seeds specifically are included in these exports (as opposed to being locked to Proton's own TOTP display). No community or hands-on report verifies successful TOTP secret export and re-import elsewhere. missing for 10: explicit confirmation that TOTP seeds are included in CSV/JSON export, independent verification that exported TOTP secrets can be imported into another app.

                          • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                          • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                          • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                          Ente Auth does offer local encrypted backups and a CLI ('ente-cli') that can export and decrypt Auth data (docs-8/9/11, probe-rt-1), and Authy-specific tooling explicitly produces a 'plaintext export format' for importing into Ente (docs-5/40) — but this is import-facing, not an open export for leaving Ente. A hands-on community report explicitly states the opposite of the 'no lock-in' claim: 'You cant easily export your codes into a different format using this app, meaning that it is difficult to migrate away once you have already moved your codes over' (comm-2), while other users only describe importing into Ente, not exporting out to a different app's format. Missing for 10: documented open/standard export format usable directly by other authenticator apps, and independent confirmation that migrating away (not just in) is easy.

                          • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                          • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                          • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                          • [claimed-docs] you should type this for MacOS... This will generate a text file called authy_codes.txt, which contains your Authy codes in Ente's plaintext…
                          • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                          • [community] I'm waiting for bitwarden or aegis export capability before trying this out. You cant easily export your codes into a different format using…
                          • [community] Ente has free backups and it's own encrypted export format, which sounds promissing.

                        Import

                        1. power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

                          weight 2 · round to Ente Auth
                          Proton Passpartialclaimed4/10

                          Proton Pass documents a general import tool that migrates passwords and other items from most major password managers, and it can generate TOTP codes for saved logins, but there is no explicit evidence of bulk import specifically from dedicated authenticator apps or of preserving TOTP secrets during that import process. missing for 10: explicit documentation of bulk TOTP import from authenticator apps, confirmation that the import tool carries over 2FA secrets rather than just passwords, independent or hands-on confirmation of successful token migration.

                          • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.
                          • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                          • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                          Ente Authfullcommunity9/10

                          Ente Auth has a dedicated bulk-import feature and docs listing native support for many 2FA providers (2FAS, Aegis, andOTP, Bitwarden, Google Authenticator, LastPass, Proton, Raivo OTP) plus conversion paths for others like Authy, with community testimony confirming easy export/import migration from Aegis. missing for 10: no independent hands-on walkthrough of the bulk-import UI itself, only docs and one community mention.

                          • [claimed-docs] Ente Auth natively supports imports from many 2FA providers.
                          • [claimed-docs] Bulk import from other 2FA apps
                          • [claimed-docs] 2FAS Authenticator * Aegis Authenticator * andOTP (including encrypted backups, except MOTP) * Bitwarden * Google Authenticator * …
                          • [claimed-docs] you might be still able to import from them by first converting the data from your old provider into these plaintext files and then importin…
                          • [claimed-docs] you should type this for MacOS... This will generate a text file called authy_codes.txt, which contains your Authy codes in Ente's plaintext…
                          • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …

                        Migration

                        1. everyday userMoving to a new phone transfers all my tokens in one guided step

                          weight 2 · round to Ente Auth
                          Proton Passpartialclaimed3/10

                          Proton Pass stores TOTP secrets in E2E-encrypted vaults that sync via the cloud (docs-5, docs-9, docs-16), which implies that logging into a new phone would pull down existing 2FA tokens, but no evidence explicitly documents a guided 'new device setup' or migration wizard for phones. The only explicit migration flows described are import/export between different password manager products (docs-3, docs-4, docs-11), not device-to-device transfer. missing for 10: explicit documentation of a phone-to-phone onboarding/migration step, confirmation that TOTP tokens sync automatically without manual re-entry, and any hands-on account of switching phones.

                          • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                          • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                          • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                          Ente Authfullprobed7/10

                          Ente Auth syncs codes end-to-end encrypted across all devices (docs-27, docs-34), so on a new phone a user simply logs into their existing account and their tokens reappear automatically—effectively a single guided step. Community feedback corroborates that switching devices via export/import was 'very easy' (ente-auth-comm-6), and offline-mode users can restore via password-protected local/CLI backups (docs-7, docs-8, docs-9, docs-11, ente-auth-probe-rt-1). Missing for 10: no explicit first-party step-by-step 'new phone setup/restore' walkthrough, and no independent hands-on account of the exact new-device login-and-sync flow.

                          • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                          • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                          • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                          • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                          • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                          • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …
                          • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…

                        Privacy posture — data-handling and privacy storiesPrivacy posture

                        Data-handling and privacy stories

                        1. ai-native userChoose where my data is stored (region/residency)

                          weight 2 · round to Ente Auth
                          Proton Passnone0/10

                          No evidence pack item mentions data residency, regional data storage options, or any control over where user data is physically stored; Proton Pass docs cover encryption, vaults, CLI, and export but not region selection. Missing for 10: any documentation of data residency/region choice, EU-only or multi-region storage options, or admin controls for data location.

                            Ente Authpartialprobed5/10

                            Ente Auth offers self-hosting instructions (running your own Ente Auth server) and an offline mode that keeps codes only on-device, both of which let a user control where their data lives rather than being forced into a fixed cloud region. However, there's no explicit region/residency selection (e.g., choosing an EU vs US data center) for its hosted cloud service. Missing for 10: explicit multi-region cloud storage options, documented data-residency guarantees for the hosted service.

                            • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                            • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                            • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…
                          • ai-native userPrevent my data from being used to train AI models

                            weight 3 · round to Ente Auth
                            Proton Passpartialclaimed4/10

                            Proton Pass's end-to-end encryption of all vault fields (docs-10) structurally means Proton cannot access plaintext user data, which would prevent it from being used to train AI models, but there is no explicit policy statement addressing AI training data use. Missing for 10: an explicit privacy policy or documentation statement about AI training opt-out/data usage, and independent confirmation of this claim.

                            • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                            Ente Authpartialprobed5/10

                            Ente Auth stores codes with end-to-end encryption, meaning Ente itself cannot access plaintext data, which structurally prevents it from being used to train AI models — but there is no explicit policy statement addressing AI training use of data. Missing for 10: an explicit AI-training data-use policy/statement, and any independent confirmation of this posture beyond the general E2E encryption claim.

                            • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                            • [claimed-docs] the data is encrypted using a key derived from the user's password
                            • [probe] PROBE docs-md: HTTP 404 at https://ente.com/help/auth/.md
                          • ai-native userControl data retention and deletion

                            weight 2 · round to Ente Auth
                            Proton Passpartialclaimed5/10

                            Docs show users can create/read/update/delete vaults and items via the CLI/app, and can export or migrate data before deleting it, giving concrete control over stored data. However there is no explicit documentation on account-level data retention policies, deletion timelines, or how long Proton retains deleted data, which is central to a full 'control retention and deletion' story. Missing for 10: explicit retention-period/account-deletion policy documentation, independent confirmation that deleted data is purged.

                            • [claimed-docs] Create, read, update, and delete vaults
                            • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                            • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                            • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                            Ente Authpartialprobed7/10

                            Ente Auth lets users delete/trash codes with recovery or permanent deletion (docs-18/33/38), control backup location and encryption (docs-9/10), run fully offline with no cloud retention (doc-7), and export/decrypt all data via the official CLI for full portability (docs-11, probe-rt-1). However there's no explicit documentation on cloud-side account/data deletion policies or retention periods for encrypted server backups. Missing for 10: documented cloud account deletion/retention policy, independent confirmation of full data erasure on request.

                            • [claimed-docs] You can now trash codes that you don't need. ... You can recover codes from here, in case of accidental deletions, or delete them permanentl…
                            • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.
                            • [claimed-docs] You can now trash codes that you don't need. These items will be moved to a separate section within the app, under the "Trash" header.
                            • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                            • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                            • [claimed-docs] Custom backup location: Choose where to store your backups on your device.
                            • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                            • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                          • ai-native userOpt out of telemetry and usage tracking

                            weight 2 · round to Proton Pass
                            Proton Passpartialcommunity4/10

                            Community evidence confirms telemetry exists in the browser extension and can be disabled, but only via Proton account settings, not directly within the extension itself, indicating a real but limited opt-out mechanism (proton-pass-comm-13). No first-party documentation from Proton Pass describes a formal telemetry/opt-out policy or setting. missing for 10: official docs on telemetry settings, in-extension opt-out toggle, confirmation of no tracking by default.

                            • [community] There's still nothing about the telemetry in the browser extension?... telemetry data is anonymous, but it's always sent to the remote endpo…
                            Ente Authnone0/10

                            No evidence pack mentions any telemetry, analytics, or usage-tracking settings, opt-out toggles, or privacy policy statements about data collection in Ente Auth; the evidence covers import/export, backups, and sync features only.

                            Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture

                            How it protects itself — app lock, E2EE design, audits, breach alerting

                            App lock

                            1. everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

                              weight 2 · round to Ente Auth
                              Proton Passnone0/10

                              No evidence pack item mentions app-level biometric or PIN lock for Proton Pass; the closest related items cover offline vault access, 2FA/TOTP generation, and encryption, but none address a lock screen or app-level authentication gate. Missing for 10: any mention of biometric unlock, app PIN lock, or auto-lock timeout feature.

                                Ente Authfullclaimed8/10

                                Docs explicitly confirm FaceID lock (Settings → Security → Lockscreen) and a custom lock screen supporting PINs and passwords, directly matching the story's biometric/PIN app-lock requirement. missing for 10: no independent/hands-on confirmation that the lock actually blocks access on a borrowed device, and no mention of Android biometric or desktop lock parity beyond FaceID/PIN.

                                • [claimed-docs] You can enable FaceID lock under Settings → Security → Lockscreen.
                                • [claimed-docs] You can now further protect your codes with a custom lock screen that supports PINs and passwords.

                              Audits

                              1. security engineerThe vendor publishes independent security audits of the app and its sync protocol

                                weight 2 · round drawn
                                Proton Passnone0/10

                                No evidence of any independent third-party security audit report, pentest, or audit of the sync protocol; evidence only covers feature docs (encryption claims, Sentinel, Monitor) and open-source status debates in community threads. Community comments even question whether the client is fully open source, but no audit report is cited or linked anywhere.

                                  Ente Authnone0/10

                                  No evidence pack item references any independent security audit of Ente Auth or its sync protocol; documentation focuses on features, encryption claims, and migration, not third-party audit reports.

                                  Monitoring

                                  1. power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

                                    weight 2 · round to Proton Pass
                                    Proton Passfullclaimed8/10

                                    Pass Monitor explicitly scans the dark web for credential leaks (breach detection), checks password health (weak/reused detection), and flags accounts missing 2FA, directly matching the story; this is documented as a core built-in feature rather than a third-party tool. Missing for 10: independent hands-on verification of Pass Monitor's accuracy/coverage and detail on exposed-credential alerting granularity beyond docs claims.

                                    • [claimed-docs] Pass Monitor is a security feature in Proton Pass that scans the dark web for credential leaks, checks on the health of your passwords, and …
                                    • [claimed-docs] Pass Monitor is a security feature in Proton Pass that scans the dark web for credential leaks, checks on the health of your passwords, and …
                                    • [claimed-docs] Proton Sentinel uses AI and human analysis to make it much harder for an attacker to take over your account.
                                    • [claimed-docs] Proton Sentinel is an advanced account protection program that provides maximum security for those who need it. It mitigates security threat…
                                    Ente Authnone0/10

                                    Ente Auth is a TOTP/HOTP authenticator app; nothing in the evidence pack shows breach-monitoring, weak/reused-credential detection, or exposure alerts — its documented features are around code storage, import/export, sharing, and lockscreen security.

                                    Push

                                    1. it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

                                      weight 2 · round drawn
                                      Proton Passnone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                        Ente Authnone0/10

                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                        Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting

                                        Running it yourself — self-hosted servers, open-source clients

                                        Server

                                        1. it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter

                                          weight 2 · round to Ente Auth
                                          Proton Passnone0/10

                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                            Ente Authpartialprobed6/10

                                            Ente explicitly documents running the Auth server locally (e.g. at http://localhost:3003) and its server code is confirmed open source, supporting self-hosting for IT admins wanting to keep secrets in-perimeter. However, the evidence pack lacks detailed self-hosting setup docs (Docker/compose instructions, hardware requirements, upgrade/security guidance) and no independent community reports specifically about self-hosting the Auth server (only cloud usage is discussed in community threads). Missing for 10: full self-hosting deployment guide, independent hands-on verification of self-hosted Auth server, and security/perimeter assurances specific to self-hosted mode.

                                            • [claimed-docs] Alternatively, if using Ente Auth, get started by adding an account (assuming you are running Ente Auth at `http://<machine-ip>:3003` or `ht…
                                            • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                                            • [probe] PROBE llms.txt: HTTP 200 at https://ente.com/llms.txt # Ente > Ente builds private, end-to-end encrypted apps for photos, two-factor authen…

                                          Source

                                          1. security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed

                                            weight 2 · round to Ente Auth
                                            Proton Passpartialcommunity6/10

                                            Community evidence confirms Proton Pass clients are open source with a public GitHub repo (github.com/protonpass), directly supporting inspectability of the code handling secrets. However, other community comments show confusion/skepticism about finding or verifying this ('haven't been able to find the repository', 'it seems only the clients are open source'), and there's no first-party doc in the pack explicitly stating open-source status or citing security audits. Missing for 10: first-party documentation confirming open-source licensing/repo, evidence of independent security audits or community code review of the seed-handling logic, and clarity on scope (client-only vs. broader).

                                            • [community] Please note that we do have encrypted notes... And it is open source: https://github.com/protonpass
                                            • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                                            • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…
                                            Ente Authfullprobed7/10

                                            Ente's own llms.txt explicitly states 'Ente's apps and server are open source,' and a community poster on HN independently confirms 'thank you for releasing it open source,' corroborating that the client code is publicly available for inspection. Missing for 10: a direct link/reference to the actual auth client source repo, and independent evidence of community security review or audits of the seed-handling code.

                                            • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …
                                            • [community] This looks quite nice, thank you for releasing it open source... One note as I signed up for an account is that the email verification went …

                                          Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces

                                          Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

                                          Automation

                                          1. ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

                                            weight 2 · round to Proton Pass
                                            Proton Passpartialprobed4/10

                                            Proton Pass ships an official CLI documented for scripting/CI-CD use that can 'securely retrieve secrets and other items' (docs-1/14) and lists item types it can read (docs-15), but TOTP/2FA codes are not explicitly named among the retrievable item types, and no docs or community evidence confirm a CLI/API command that outputs a live TOTP code for use in an automated login flow. missing for 10: explicit CLI/API command or output field for TOTP codes, hands-on confirmation of an agent successfully pulling a 2FA code programmatically.

                                            • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                            • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                            • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                            • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                            • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                                            Ente Authnone0/10

                                            Evidence only shows a CLI for exporting/backing up and decrypting Ente Auth data (ente-auth-docs-11, ente-auth-probe-rt-1), not for programmatically retrieving a live/current TOTP code for use in an automated 2FA login. No API, CLI subcommand, or docs describe generating a real-time code for agent consumption.

                                            • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                            • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                            • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                                          2. ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

                                            weight 1 · round to Proton Pass
                                            Proton Passpartialprobed6/10

                                            Proton Pass ships an official CLI that allows secure programmatic retrieval of secrets, passwords, SSH keys, and other items across scripts and CI/CD pipelines, which functions as a local endpoint an agent could query instead of screen-scraping the app. However, the docs don't explicitly confirm TOTP/2FA code retrieval via the CLI (2FA generation is only described in the app itself), and there is no mention of an agent-specific or MCP-style interface, nor independent hands-on verification of CLI use by AI agents. Missing for 10: explicit CLI support for TOTP code retrieval, agent/MCP-oriented interface documentation, independent corroboration of CLI usage in agentic workflows.

                                            • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                            • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                            • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                            • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                            • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                                            Ente Authnone0/10

                                            No evidence of any local API, IPC endpoint, or programmatic interface for querying codes; the only related tooling is the export/backup CLI (docs-11, probe-rt-1), which produces files rather than a queryable local endpoint an agent could hit live. No OpenAPI/local server documentation was found (probe-3 confirms no openapi endpoint).

                                            • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                            • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                            • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…

                                          Browser

                                          1. everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

                                            weight 2 · round to Proton Pass
                                            Proton Passfullcommunity8/10

                                            Docs confirm TOTP code generation for saved logins and passkey support, and community evidence from an actual user confirms the browser extension autofills TOTP/2FA smoothly ('Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek'). Passkey autofill is documented but not independently corroborated with hands-on testing. Missing for 10: independent hands-on confirmation of passkey autofill specifically, and more detail on passkey UX in the extension.

                                            • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                            • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                                            • [community] I've been a Proton Unlimited subscriber... Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek.
                                            • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                            Ente Authnone0/10

                                            No evidence of a browser extension for Ente Auth; the product is described as apps for mobile, desktop and web with manual QR-scan/setup-key entry, not autofill via a browser extension for TOTP or passkeys during login.

                                            Desktop

                                            1. power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile

                                              weight 2 · round to Ente Auth
                                              Proton Passdisputedcontradicted5/10

                                              Proton's own support docs describe a dedicated desktop app with offline vault access and TOTP code generation (docs-9, docs-16, docs-5), suggesting a first-class desktop experience. However, community hands-on reports explicitly state there was no desktop app for Proton Pass ('And no desktop app for proton pass, maybe some day though?' and 'Pity it's only available on iOS and Android as apps and as browser extensions elsewhere'), directly contradicting the vendor's desktop-app documentation. Missing for 10: independent corroboration that the desktop app actually exists and works as described, and resolution of the timeline discrepancy between docs and community reports.

                                              • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                              • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                              • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                              • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                              • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…
                                              Ente Authfullcommunity7/10

                                              Ente Auth explicitly ships native desktop clients (Flathub Linux app, plus 'app for every platform: Mobile, desktop and web' with full sync) and desktop-specific UI features like right-click code editing, matching a first-class desktop experience; a HN user corroborates switching to it specifically for its desktop app after Authy dropped theirs. missing for 10: explicit list/docs of Windows/Mac desktop builds beyond Flathub, and an independent hands-on review confirming full feature parity with mobile.

                                              • [claimed-docs] Auth is now officially available on [Flathub](https://flathub.org/apps/io.ente.auth)!
                                              • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                              • [claimed-docs] You can delete or edit a code by long pressing (or right clicking on desktop) on that item.
                                              • [community] Ente Auth is awesome - I've been using it ever since Authy discontinued their desktop app.

                                            Watch

                                            1. everyday userRead my codes from my smartwatch without pulling out my phone

                                              weight 1 · round drawn
                                              Proton Passnone0/10

                                              No evidence of a smartwatch app, watch companion, or complication for viewing TOTP codes; evidence only covers mobile, browser extension, and CLI surfaces, with community notes even lamenting lack of a desktop app. Missing for 10: any smartwatch app/companion, watch complication, or documentation of viewing codes without the phone.

                                              • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                              • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…
                                              Ente Authnone0/10

                                              The evidence pack covers mobile/desktop/web platform support, import/export, sharing, and lockscreen features, but contains no mention of smartwatch (e.g. Wear OS, watchOS) support or companion app for viewing codes without pulling out a phone.

                                              Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup

                                              Not losing your accounts — encrypted backup, multi-device sync, recovery

                                              Backup

                                              1. security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

                                                weight 3 · round to Ente Auth
                                                Proton Passpartialclaimed5/10

                                                Proton Pass documents that all vault data is end-to-end encrypted (docs-10) and offers a PGP-encrypted export option that could serve as a backup (docs-11), implying the vendor cannot read backed-up data. However, there is no dedicated 'backup' feature documentation (only export/import), and no detailed cryptographic architecture whitepaper or independent audit is cited to substantiate the zero-knowledge key design in depth. missing for 10: dedicated backup-feature docs, detailed encryption architecture/whitepaper, independent security audit confirming vendor never holds keys

                                                • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                                • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                                • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                Ente Authpartialprobed6/10

                                                Ente docs state cloud backups are end-to-end encrypted (docs-27, docs-34) and local backups are encrypted with a password-derived key that Ente cannot recover (docs-9, docs-12), plus open-source apps/server are confirmed (probe-rt-2), supporting a 'vendor never holds key' claim. However there is no detailed cryptographic design doc (key derivation algorithm, protocol specifics, audit report) in the evidence, only high-level marketing/FAQ statements. Missing for 10: a published encryption whitepaper or technical spec, and independent security audit/corroboration of the E2E design.

                                                • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                                • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                                • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                                • [claimed-docs] the data is encrypted using a key derived from the user's password
                                                • [probe] PROBE runtime (recorded 2026-09-15): ente.com serves a live llms.txt — '# Ente — Ente builds private, end-to-end encrypted apps for photos, …

                                              Multi device

                                              1. everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

                                                weight 2 · round to Ente Auth
                                                Proton Passpartialcommunity5/10

                                                Docs confirm cross-platform clients (mobile apps, browser extensions, and a desktop app referenced in the desktop-app guide) and offline access that presumably reconciles when back online, implying cloud sync of vault items including TOTP tokens. However, no first-party documentation explicitly describes the sync mechanism or guarantees real-time multi-device consistency, and community comments note a historical lack of a desktop app and inconsistent browser-extension availability (e.g., Firefox ESR incompatibility), suggesting platform coverage has been uneven over time. Missing for 10: explicit sync/consistency documentation, independent verification that sync is truly automatic and near-instant across phone/tablet/computer.

                                                • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                                • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                                • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…
                                                • [community] Can't use the Firefox extension, FF 102 ESR is apparently too old
                                                Ente Authfullcommunity8/10

                                                Ente Auth explicitly advertises multi-platform apps (mobile, desktop, web) with end-to-end encrypted cloud sync so codes stay in sync across devices, and community evidence corroborates real-world use across app switches without complaint about sync failures. Missing for 10: independent hands-on confirmation of real-time multi-device sync latency/reliability and any edge-case sync bugs reported by users.

                                                • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                                • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                                • [community] Ente Auth is awesome - I've been using it ever since Authy discontinued their desktop app.
                                                • [community] I have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This …

                                              Recovery

                                              1. everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

                                                weight 3 · round to Ente Auth
                                                Proton Passpartialclaimed4/10

                                                Proton Pass stores TOTP codes and other secrets inside end-to-end encrypted vaults that live on Proton's servers (docs-5, docs-10), and offers export (docs-4/11) and Emergency Access (docs-20) features that could serve as backup/recovery mechanisms, implying data isn't lost with a device. However, there is no explicit documentation in the pack describing a dedicated 'lost phone / new device' recovery flow, account recovery phrase, or step-by-step restoration of 2FA tokens after device loss. Missing for 10: explicit account-recovery/recovery-phrase documentation, explicit cross-device sync confirmation, and a stated process for restoring TOTP secrets specifically after losing a device.

                                                • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                                • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                                                • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                                • [claimed-docs] Emergency Access
                                                Ente Authfullprobed8/10

                                                Ente Auth documents end-to-end encrypted cloud sync/backups so codes restore on a new device after login, plus a recovery key to bypass 2FA lockouts, local encrypted backups, and a CLI export tool as additional restore paths. missing for 10: no independent hands-on account of a real device-loss recovery walkthrough, and no detail on exact steps to restore cloud-synced codes on a fresh device beyond general sync claims.

                                                • [claimed-docs] Auth has an app for every platform. Mobile, desktop and web. Your codes sync across all your devices, end-to-end encrypted.
                                                • [claimed-docs] Auth provides end-to-end encrypted cloud backups so you don't have to worry about losing your tokens.
                                                • [claimed-docs] We recommend that you ensure you store your recovery key in a safe place (writing it down on a paper is a good idea). This key can be used t…
                                                • [claimed-docs] Automatic daily backups: When enabled, Ente Auth creates one local backup per day when you open the app.
                                                • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                                • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                                • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                                • [community] Ente has free backups and it's own encrypted export format, which sounds promissing.

                                              Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin

                                              Shared and managed use — shared vaults, org policies, programmatic provisioning

                                              Automation

                                              1. ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

                                                weight 2 · round to Proton Pass
                                                Proton Passpartialprobed6/10

                                                Proton Pass CLI documentation shows programmatic create/read/update/delete of items (including passwords, secure notes, SSH keys) and vaults, which an agent could invoke via scripts. However, there's no explicit mention of TOTP secret seeding via the CLI, and no dedicated agent/AI integration or API/SDK beyond the CLI is documented, and no independent confirmation of these CLI capabilities working reliably. Missing for 10: explicit TOTP-seeding support via CLI, broader API/SDK for agents, and independent hands-on verification of programmatic write operations.

                                                • [claimed-docs] Create, read, update, and delete vaults
                                                • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                                • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                                • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                                                Ente Authnone0/10

                                                Evidence shows only manual QR-scan/setup-key entry, GUI import/export, and a CLI limited to exporting and decrypting backups—no documented API, SDK, or CLI subcommand for programmatically creating or updating vault entries. No OpenAPI/API surface was found (ente-auth-probe-3 confirms no openapi.json), so an agent has no documented programmatic surface to seed or update TOTP secrets.

                                                • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.
                                                • [probe] PROBE runtime (recorded 2026-09-15): Ente's official CLI is packaged in Homebrew as ente-cli 0.3.0, described by the formula itself as 'Util…
                                                • [probe] PROBE openapi: all candidate paths 404 (https://ente.com/openapi.json, https://ente.com/swagger.json, https://ente.com/api/openapi.json, htt…
                                                • [claimed-docs] Scan the QR code shown by the service.
                                                • [claimed-docs] Enter the account name, issuer, and secret (setup key).

                                              Policy

                                              1. it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

                                                weight 1 · round drawn
                                                Proton Passnone0/10

                                                No evidence of org-wide admin policy controls (enforced app lock, export restrictions, mandated master password strength) for organization members; docs cover vaults, CLI, export, 2FA, sharing but nothing about admin-enforced policies across a team.

                                                  Ente Authnone0/10

                                                  No evidence of any org-wide admin console, centralized policy enforcement, mandated master password strength, or app lock/export restrictions applied across members — Ente Auth is a personal/individual authenticator with local lock screen (per-device) and personal backup/export options, not a managed enterprise policy tool.

                                                  • [claimed-docs] You can now further protect your codes with a custom lock screen that supports PINs and passwords.
                                                  • [claimed-docs] Password-protected: All local backups are encrypted with a password you set. Keep this password safe, because Ente cannot recover it for you…
                                                  • [claimed-docs] You can use [Ente's CLI](https://github.com/ente/ente/tree/main/cli#readme) to automatically backup your Auth codes.

                                                Sharing

                                                1. it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control

                                                  weight 2 · round to Proton Pass
                                                  Proton Passpartialclaimed5/10

                                                  Evidence confirms Proton Pass supports TOTP/2FA generation for saved logins (docs-5) and secure vault sharing plus vault-based organization of items (docs-16, docs-17), which together imply TOTP items can be shared via vaults. However, there is no documentation of granular per-member access control (roles/permissions) or 'collections' as a distinct sharing unit, and no team-admin console evidence for managing member access levels within shared vaults. Missing for 10: explicit permission-level (viewer/editor/admin) documentation for shared vaults, evidence of 'collections' as an admin feature, and any IT-admin console showing per-member access management.

                                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                  • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                  • [claimed-docs] Secure vault sharing
                                                  Ente Authpartialclaimed4/10

                                                  Ente Auth documents sharing individual TOTP codes via temporary, end-to-end encrypted links with teammates (docs-16, docs-35), and explicitly restricts sharing to TOTP (not HOTP) entries (docs-30), which covers the core 'share TOTP logins with team' idea. However there is no evidence of a vault/collection construct or per-member access control (e.g., role-based permissions, group vaults, admin-managed membership) — sharing appears to be per-code link generation rather than an admin-managed shared vault. Missing for 10: evidence of collection/vault-based sharing, per-member access control or roles, and admin management console for team access.

                                                  • [claimed-docs] You can now easily share specific codes with your team, with temporary links that are end-to-end encrypted.
                                                  • [claimed-docs] Share codes with your team securely
                                                  • [claimed-docs] Sharing is now limited to TOTP codes; the share option is hidden for HOTP entries.

                                                Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core

                                                The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

                                                Enrollment

                                                1. everyday userScan a QR code and immediately start generating TOTP codes for a new account

                                                  weight 3 · round to Ente Auth
                                                  Proton Passpartialcommunity5/10

                                                  Docs confirm Proton Pass generates TOTP codes for saved logins (proton-pass-docs-5) and community reports use it as their default 2FA tool (proton-pass-comm-12), but no evidence explicitly describes scanning a QR code to add a new TOTP secret and instantly getting codes. Missing for 10: explicit QR-code scanning workflow documentation, mobile camera scan support evidence, and independent hands-on confirmation of the scan-to-code flow.

                                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                  • [community] I've been a Proton Unlimited subscriber... Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek.
                                                  Ente Authfullclaimed8/10

                                                  Docs explicitly describe scanning a QR code shown by a service to add a new account, both generally (docs-1) and for specific migration flows (docs-6/41), which immediately generates TOTP codes in the app. This core flow is directly and simply documented as the primary onboarding method. Missing for 10: independent hands-on confirmation of the exact scan-to-code-generation moment and any UX friction reports.

                                                  • [claimed-docs] Scan the QR code shown by the service.
                                                  • [claimed-docs] Enter the account name, issuer, and secret (setup key).
                                                  • [claimed-docs] Tap the add button and scan the QR code shown by the service.
                                                  • [claimed-docs] Open Ente Auth. Tap the add button and scan the QR code shown by the service.

                                                Offline

                                                1. power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes

                                                  weight 2 · round to Ente Auth
                                                  Proton Passnone0/10

                                                  Proton Pass is fundamentally an account-based, encrypted-vault service — using it at all requires creating and logging into a Proton account, and TOTP codes are stored as fields within account-synced vaults. Evidence only shows that once logged in, offline access to already-synced vaults works (proton-pass-docs-9), but nothing supports generating/viewing TOTP codes without ever creating or authenticating a vendor account, which the story explicitly requires.

                                                  • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                  Ente Authfullclaimed8/10

                                                  Docs explicitly confirm offline mode with no account required, codes stored only on-device, and no network dependency for viewing codes. Missing for 10: independent hands-on verification (e.g. airplane-mode test) beyond vendor docs, and no detail on how backups/imports work fully offline without any cloud touchpoint.

                                                  • [claimed-docs] Ente Auth can be used without an account by choosing **Use without backups**. In offline mode, your codes are stored only on that device.
                                                  • [claimed-docs] Use without an account

                                                Organization

                                                1. power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

                                                  weight 2 · round to Ente Auth
                                                  Proton Passpartialcommunity4/10

                                                  Proton Pass supports TOTP generation tied to saved logins and vaults for organizing items into groups (e.g., personal vs. work), but there is no evidence of search functionality or service icons, and a community report explicitly notes the browser popup overlay was inadequate for managing hundreds of logins, suggesting scaling friction for power users. Missing for 10: dedicated TOTP search/filter feature, service icon display, and evidence of smooth navigation across dozens of tokens.

                                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                  • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                  • [community] Would like to see web/desktop clients for this. When I used it recently I found the unexpandable pop-up overlay in the browser to not be ade…
                                                  Ente Authpartialclaimed6/10

                                                  Ente Auth's marketing docs confirm search (deep-link search feature), service icons, and favoriting/organizing features ('Organize with ease', 'Favorite services to the top', 'Don't scroll'), directly supporting quick access to tokens. However, there is no concrete evidence of folder or group/category organization for large token sets — only vague 'organize with ease' copy and free-text notes (500-char annotations), not structured grouping. Missing for 10: explicit folder/category/tagging feature documentation, evidence of grouping many tokens, independent hands-on confirmation of organization UX at scale.

                                                Variants

                                                1. power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

                                                  weight 2 · round to Ente Auth
                                                  Proton Passnone0/10

                                                  Evidence only confirms basic TOTP code generation for saved logins; no mention of Steam Guard tokens, HOTP counters, or custom period/digit length support anywhere in the docs or community discussion. Missing for 10: any documentation of Steam Guard support, HOTP counter-based tokens, or custom TOTP period/digit configuration.

                                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                  Ente Authpartialclaimed4/10

                                                  Evidence confirms HOTP entries are supported (the changelog notes sharing is now limited to TOTP and hidden for HOTP entries), implying native HOTP counter support. However, there is no mention anywhere in the evidence pack of Steam Guard token support, or of custom period/digit-length configuration for TOTP entries. missing for 10: explicit Steam Guard support, custom period/digit-length configuration, and any hands-on confirmation beyond the changelog note.

                                                  • [claimed-docs] Sharing is now limited to TOTP codes; the share option is hidden for HOTP entries.

                                                Not comparable on these axes

                                                1. ai-native userPlug MCP servers into this product so it can use their tools

                                                  weight 3 · not comparable
                                                  Proton Passn/a

                                                  Proton Pass is a password manager, not an AI agent or agent-serving platform; there is no evidence of MCP server functionality, and this axis is a category error for this product type.

                                                    Ente Authn/a

                                                    Ente Auth is a 2FA/authenticator app; MCP server plugin capability is unrelated to its product category and no evidence suggests otherwise.

                                                    • ai-native userSubscribe to events via webhooks

                                                      weight 2 · not comparable
                                                      Proton Passnone0/10

                                                      No evidence of any webhook or event subscription mechanism; Proton Pass offers a CLI for CRUD operations but nothing about push/webhook notifications. Missing for 10: any webhook API, event subscription mechanism, or documentation referencing such a feature.

                                                        Ente Authn/a

                                                        Ente Auth is a 2FA/authenticator app with no evidence of any event-driven webhook or subscription API; webhooks are not a fit category axis for this type of product (offline/encrypted code storage tool), and no evidence suggests it exposes such a system.

                                                        • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                          weight 2 · not comparable
                                                          Proton Passnone0/10

                                                          Evidence only covers password/vault management, monitoring, and Sentinel's fraud-detection AI for account security — none of this provides AI-generated insights or suggestions derived from the user's stored data (e.g., summarization, pattern detection, recommendations beyond breach/weak-password alerts). No feature described as generating insights or suggestions from the data itself.

                                                            Ente Authn/a

                                                            Ente Auth is a 2FA/authenticator app; there is no evidence of any AI-generated insights or suggestions feature, and this is not a category where such analytics would be a fair expected axis — the product's scope is encrypted TOTP/HOTP code storage and sync, not data analysis.

                                                            • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                              weight 3 · not comparable
                                                              Proton Passn/a

                                                              Proton Pass is a password manager; no built-in AI assistant for task delegation exists in the evidence, and this capability is outside the product's category (only AI-related mentions are Proton Sentinel's fraud-detection use of AI, not an assistant users can delegate tasks to).

                                                                Ente Authn/a

                                                                Ente Auth is a 2FA/authenticator app with no AI assistant or agent-delegation feature of any kind in its evidence; delegating tasks to a built-in AI assistant is outside this product's category entirely.

                                                                • ai-native userTest against a sandbox environment without touching production data

                                                                  weight 1 · not comparable
                                                                  Proton Passn/a

                                                                  Proton Pass is a password manager, not a platform with sandbox/staging environments for testing against production-like data; this axis is a category error for its product type.

                                                                    Ente Authn/a

                                                                    Ente Auth is a 2FA code manager, not an API/platform product with sandbox/test environments; the notion of testing against a sandbox vs production data is a category mismatch for this type of app.

                                                                    • ai-native userDefine rules that trigger actions automatically on events

                                                                      weight 3 · not comparable
                                                                      Proton Passn/a

                                                                      Proton Pass is a password manager; defining automation rules that trigger actions on events is outside its product category (no workflow/automation engine exists), so this axis does not apply.

                                                                        Ente Authn/a

                                                                        Ente Auth is a 2FA/TOTP authenticator app; it has no rule engine, event triggers, or automation/workflow features—this is a category mismatch, not a missing feature of an automation product.

                                                                        • ai-native userSchedule recurring jobs or workflows

                                                                          weight 2 · not comparable
                                                                          Proton Passn/a

                                                                          Proton Pass is a password manager with a CLI for secret retrieval in scripts/CI, not a workflow/job scheduling platform; scheduling recurring jobs is outside its product category.

                                                                            Ente Authn/a

                                                                            Ente Auth is a 2FA/TOTP code manager; scheduling recurring jobs or workflows is not a fair capability for this product category — it has no workflow/automation engine.

                                                                            • ai-native userVersion, review, and roll back my automations

                                                                              weight 1 · not comparable
                                                                              Proton Passn/a

                                                                              Proton Pass is a password manager, not an automation/workflow tool; versioning, reviewing, and rolling back 'automations' is not a concept that applies to its product category.

                                                                                Ente Authn/a

                                                                                Ente Auth is a 2FA/authenticator app, not an automation platform; there is no concept of 'automations' to version, review, or roll back in this product's domain.