Clockwork for Android

Clockwork

Kevin

version 1.5.2

TOTP codes without a network permission. Offline by design, nothing stored.

Downloads 9
Ads

Rate & Review

Antivirus & safety scan results

Scan Date: Aug 12, 2026 Software Version: 1.5.2
Status: ✅ Trusted & Safe to install This app is signed by Kevin with trusted and verified digital signature and it will updated existing Clockwork installations Certificate fingerprint: 67b1034f5b32e1d4096249272072ad8357d4917b Issuer: C:UK, CN:FDroid, L:ORG, O:fdroid.org, ST:ORG, OU:FDroid How we verify APK files security
Android antivirus Status
K7GW Clean ✅
DrWeb Clean ✅
VirIT Clean ✅
ClamAV Clean ✅
Google Clean ✅
Ikarus Clean ✅
Lionic Clean ✅
Sophos Clean ✅
Yandex Clean ✅
Alibaba Clean ✅
Tencent Clean ✅
Xcitium Clean ✅
Fortinet Clean ✅
Kingsoft Clean ✅
Symantec Clean ✅
AhnLab-V3 Clean ✅
Kaspersky Clean ✅
Microsoft Clean ✅
Trustlook Clean ✅
ESET-NOD32 Clean ✅
Avast-Mobile Clean ✅
NANO-Antivirus Clean ✅
BitDefenderFalx Clean ✅

Clockwork 2-Step Verification app for Android description

Clockwork generates two-factor codes (TOTP, RFC 6238) entirely on your device. The Android app declares no INTERNET permission — it cannot go online, and you can check that claim yourself in the manifest.

The app is the projects single-file web build carried by a system WebView: the same clockwork.html you can download from a release and open on any computer.

What it does:

  • Generates TOTP codes — SHA-1, SHA-256 or SHA-512, 6 to 8 digits, any period. The countdown is a 30-mark dial with a rotating hand, not a progress ring.
  • Takes input in every shape you are likely to have it: raw Base32, otpauth:// URIs, a whole Google Authenticator export, or a QR code from the camera or an image.
  • Explains broken lines instead of failing silently.
  • Optionally remembers your secrets behind a passphrase — strictly opt-in, AES-256-GCM over PBKDF2-SHA-256 with 600,000 iterations, with an auto-lock. Without the vault, nothing is stored at all.
  • Speaks 37 languages, all bundled, including right-to-left layouts.

The camera permission exists solely for the QR scanner and is declared optional hardware; importing a QR code from an image works without it. Auto-backup is disabled, so the encrypted vault never leaves the device.

The OTP algorithms are implemented from scratch against the RFC test vectors — no OTP library. The only borrowed crypto primitive is the Web Crypto API.

Important, independent of this app:

Set up backup codes with every provider before relying on any authenticator. They are the only thing that gets you back in when the secret is gone.

Ads


Specifications