Your codes · 4 accounts
Add accountAWSShared · 3
root@acme.in
GitHubPersonal
acme-ops
HDFC NetBankingShared · 2
finance@acme.in
GooglePersonal
admin@acme.in
Secrets are AES-encrypted and never shown in plain text. The AWS and HDFC logins are shared team entries — teammates you name see the live code, every reveal is audited, and you can revoke access any time.
Illustrative — your list reflects the accounts you add and the logins you share.
What you get
A real authenticator, built into your workplace
Everything you expect from an authenticator app — live TOTP codes, QR or manual setup, a trustworthy countdown — plus the thing a phone app can never do: securely share a login's 2FA with your team.
Codes on the same screen
The whole point: read your 6-digit code right where you are signing in. No reaching for a phone, no second app to open, no re-typing across devices.
- Live TOTP codes in the browser and the app
- Nothing to fetch from another device
- One tap to copy the current code
Add by QR or secret key
Turning on 2FA for a service? Scan the QR code it shows you, or paste the secret key by hand. Either way the account is ready in seconds.
- Scan the QR straight from setup
- Or enter the Base32 secret manually
- Issuer and account name filled in for you
Works with any 2FA service
It is standard TOTP, so it works with anything an authenticator app works with — cloud consoles, code hosts, banking and GST portals, email and more.
- AWS, Google, GitHub, Microsoft and beyond
- Banking and GST portals that use TOTP
- Any service offering authenticator-app 2FA
A countdown you can trust
Every code carries a countdown ring so you always know how long it is good for. Codes roll over on the same 30-second cadence real authenticators use.
- 6-digit codes, refreshed every 30 seconds
- A ring that empties as the window closes
- Grab a fresh code before the current one lapses
Personal by default
Your own 2FA entries are yours alone. They are not visible to admins or teammates unless you deliberately share a specific login with them.
- Private entries stay private to you
- Secrets never rendered in plain text
- You choose exactly what to share, if anything
Share a login with your team
Some accounts belong to a team, not a person — a cloud root login, a shared bank portal. Share that login's 2FA with named teammates so the whole team can get in.
- Shared team entries for group logins
- Grant access to specific people only
- Revoke a person's access at any time
Encrypted at rest
Secret keys are AES-encrypted in the database and never stored or shown in the clear. Even the people who can read a code never see the underlying secret.
- AES encryption on every stored secret
- The Base32 seed is never displayed again
- Organization-scoped — secrets stay in your workspace
Access-checked and audited
Every code-reveal is checked against who is allowed to see it and written to an audit trail, so shared access is deliberate and accountable, never a mystery.
- Each reveal verified against the share list
- A trail of who accessed which login, and when
- Answer 'who can get into this account?' instantly
Everywhere you work
The same entries follow you across the web app, mobile web and the Android app — sign in from a laptop or a phone and your codes are already there.
- Web, mobile web and the mobile app
- One login, the same codes on every device
- No separate authenticator app to install
How it works
From setup to a signed-in login in four steps
Switch it on, add an account by QR or key, read the live code — and share it with your team when the login belongs to everyone.
- 01
Switch it on
Enable SubhX Authenticator from the marketplace in a click. It turns on for your organization — no install, no separate app to distribute.
- 02
Add an account
When a service offers authenticator-app 2FA, scan its QR code or paste the secret key. The entry appears with its issuer and account name.
- 03
Read the live code
Your 6-digit code shows immediately, with a ring counting down the 30-second window. Copy it into the login prompt and you are in.
- 04
Share if it is a team login
For an account the whole team uses, share that entry with the right teammates. They see the live code; you keep control of who has access.
Security
Your secrets stay secret
A 2FA secret is only as safe as where it lives. SubhX Authenticator encrypts every secret key at rest, never renders it in plain text, and checks and records access on every single code-reveal — so sharing a login is deliberate and accountable, and your codes never leave your organization.
- Secret keys AES-encrypted in the database
- The Base32 seed is never shown again after setup
- Every reveal access-checked against the share list
- Audit trail + organization-scoped isolation
Encrypted at rest
AES
on every secret
Never in the clear
Masked
seed hidden after setup
Every reveal
Checked
against who can access
Audited & scoped
Logged
org-only isolation
Personal or shared — you decide
The 2FA a phone app can't share
Your own entries stay private to you. But some logins belong to a team — a cloud root account, a shared bank portal — and passing their codes around on chat is how secrets leak. Share the entry instead: name the teammates who need it, they see the live code, and you can pull access back the moment someone moves on.
- Personal entries · visible only to you
- Shared entries · granted to named teammates
- Live codes without ever exposing the secret
- Revoke a person's access in one click
AWS · root login
Shared team entry · you are the owner
Who can see this code
Priya Nair
DevOps lead
Arjun Mehta
SRE
Kabir Shah
On-call
Who it's for
Anyone who juggles logins and a phone app
Fewer lost seconds hunting for a code, and shared logins that a whole team can reach — without a secret ever landing in a chat thread.
IT & DevOps teams
Root logins to AWS, cloud consoles and code hosts are shared by nature. Give the on-call team the 2FA they need without pasting a secret into a chat.
Finance & accounts
Bank portals, GST and payment dashboards often sit behind one shared login. Share that account's codes with the finance team, and revoke when someone moves on.
Founders & admins
Stop juggling a separate phone app for a dozen services. Keep all your own 2FA in one place, on the same screen you already run the business from.
Agencies & MSPs
Managing accounts on behalf of clients means a lot of shared logins. Hand the right people access to the right account's codes, and keep an audit trail of it.
Simple pricing
One flat price for your whole organization
No per-user fee, no per-account fee, no tiers. Turn Authenticator on from the marketplace for a flat rate — then add as many accounts as you like and share as many logins as your team needs.
Authenticator add-on
₹50/ org / month
Flat — your whole organization, unlimited accounts
- Unlimited accounts and unlimited team sharing
- Add by QR scan or by pasting a secret key
- Works with any authenticator-app 2FA service
- Live 6-digit codes with a 30-second countdown
- AES-encrypted, access-checked and audited
- Web, mobile web and the mobile app — one login
Billed per organization per month while the add-on is enabled — switch it on or off whenever you like. GST applies as per Indian tax law.
Questions
The things people ask about Authenticator
What is SubhX Authenticator?+
It is built-in two-factor authentication — the same time-based one-time passwords (TOTP) you would get from an app like Google Authenticator, but inside SubhX. You read your live 6-digit codes on the same screen you sign in from, so there is no second device or separate app to reach for.
Which services does it work with?+
Any service that supports authenticator-app 2FA. It is standard TOTP, so cloud consoles like AWS and Google, code hosts like GitHub, Microsoft accounts, and most banking and GST portals that offer an authenticator option all work the same way — scan their QR or paste their secret key.
How do I add an account?+
When a service is setting up 2FA it shows you a QR code and a secret key. Scan the QR code with SubhX Authenticator, or paste the secret key in manually. The entry is created with the issuer and account name, and its live code starts ticking immediately.
Is it safe to store my 2FA secrets here?+
Yes. Secret keys are AES-encrypted at rest and never stored or shown in plain text — once an entry is added, the underlying seed is never displayed again. Every code-reveal is access-checked and written to an audit trail, and entries are scoped to your organization, so secrets never leave your workspace.
Can I share a login's 2FA with my team?+
Yes, and it is a core reason teams use it. For an account that belongs to a team rather than a person — a cloud root login, a shared bank portal — you can create a shared team entry and grant its live codes to specific teammates. You control exactly who has access and can revoke it at any time.
Do I need a second device or a separate app?+
No. That is the whole idea — the codes live on the same screen you are logging in from. Nothing to install, nothing to fetch from a phone you left on your desk. It works on the web, on mobile web and in the SubhX mobile app.
How is it priced?+
A flat ₹50 per organization per month. That covers unlimited accounts and unlimited team sharing — there is no per-user or per-account charge. It is an opt-in marketplace add-on, so you switch it on when you need it and pay only while it is enabled. GST applies as per Indian tax law.
Is it available on mobile?+
Yes. Your entries and their live codes are available on the web, on mobile web and in the SubhX Android app, all under the same login — so whichever device you are on, your codes are already there.
Bring your 2FA codes into your workplace
Live 6-digit codes on the same screen you sign in from, personal or shared with your team — turned on from the marketplace for a flat ₹50 per organization each month. Add your first account in seconds.


