Apps
Authenticator
Two-step sign-in codes on your phone, sign-in approvals with a tap, Google Authenticator's transfer format, an optional encrypted backup to your account, and Passwords, an end-to-end encrypted password manager.
Cactive Authenticator is a phone app for two-step sign-in codes: the 6- or 8-digit codes a website asks for after your password, including your own Cactive account's. It works without an account; signing in is only for approving sign-ins with a tap, the optional backup and Passwords.
Adding accounts
When a site asks you to set up an authenticator app, tap +, then:
- Scan a QR Code: point the camera at the QR code the site shows.
- Enter a Setup Key: type the account name and the key (the letters A–Z and the digits 2–7, at least 16 of them), and choose Time Based (most sites) or Counter Based. More Options has the algorithm (SHA-1, SHA-256 or SHA-512), 6 or 8 digits, and the period in seconds or the starting counter.
Setting up on the phone itself, a site's otpauth:// link (and a transfer link) opens the app, which shows the account and adds it when you tap Add Account.
Time-based codes (RFC 6238) change every period, usually 30 seconds: the ring beside each code shows the time left, and the code turns red for its last 5 seconds. Counter-based codes (RFC 4226) change when you tap Next code. An account that's already on the phone (the same key) isn't added twice.
Using codes
- Tap an account to copy its code.
- Search by service or account name.
- Press and hold an account to change its service and account name, show its own QR code, or remove it.
- Reorder Accounts moves accounts up and down, or to the top or bottom (press and hold).
Moving accounts to another phone
Transfer uses Google Authenticator's format (otpauth-migration:// QR codes), so accounts move to and from Google Authenticator as well as between phones with this app.
- Export Accounts: choose the accounts, confirm with Face ID or your passcode, and show the QR codes one after another ("1 of 3"), up to 10 accounts each. Afterwards you can remove the exported accounts from this phone.
- Import Accounts: in Google Authenticator on the other phone, open Transfer accounts, choose Export accounts, and scan each QR code it shows. Accounts already here are skipped.
The format has no period: accounts whose codes last other than 30 seconds can't move this way. Open the account and show its own QR code (otpauth://) instead, which any authenticator app reads.
Security
- Accounts are kept in the iPhone's Keychain (on Android, the Keystore), readable only while the phone is unlocked. They move to a new iPhone in an encrypted backup of the phone, like other Keychain items.
- Require Face ID (Settings) locks the app: it asks for Face ID, Touch ID or the passcode when it opens, straight away or after 1 or 5 minutes away.
- Codes never show in the app switcher: the app covers them whenever you leave it. On Android, screenshots are off too.
- Showing an account's QR code and exporting ask for Face ID or the passcode first.
Sign-in approvals
Instead of typing a code when you sign in to Cactive with your password, approve the sign-in on your phone. The sign-in page shows a two-digit number, and your phone gets a notification, Are you trying to sign in?, naming the app or site, the browser and roughly where it is. Tap the same number among the three the app shows, confirm with Face ID or your passcode, and the browser carries on by itself.
Turning it on
- Turn on two-step sign-in for your account first (an authenticator app or codes by text), so a code is always there to fall back to.
- In the app, open Settings, then Sign-In Approvals, sign in, and tap Turn On. If your sign-in in the app isn't recent, it asks you to sign in again, with two-step sign-in or a passkey.
- Confirm with Face ID, Touch ID or your passcode, and allow notifications.
The phones that approve are listed on your account page under Authenticator app, in Sign-In Approvals: name, when each was added and last used, and where its key is kept. Turn approvals off there, or remove a phone. Turn Off on This Phone in the app removes it too.
Answering
- Tap the notification. Without one (notifications off, or it didn't arrive), open the app: a request that's waiting opens by itself.
- Check what's signing in, from which browser and where. If it's you, tap the number shown on the sign-in page.
- No, It's Not Me blocks the sign-in. Whoever got that far knows your password, so the app offers Sign Out Everywhere (every browser, the other phone apps and the command line, but not this app) and Change Password.
- A number that isn't the one on the sign-in page blocks the sign-in too. Requests expire after 2 minutes.
- When a sign-in you approved goes through, the app says so: New sign-in approved.
The sign-in page still offers a code from the app, a backup code or a text instead.
How it's kept safe
- The phone's key is made in the iPhone's Secure Enclave and never leaves it: not in backups, not moved to another phone. Every approval needs Face ID, Touch ID or the passcode, and a phone without a passcode can't approve. On Android, the key is kept in storage the Android Keystore encrypts, and the app asks for the phone's unlock before each approval.
- An approval is a signature from that key over the request, the number tapped and the browser it's for. A copied notification or app token can't approve, and an approval completes only the browser that asked, once.
- The number is never in the notification: the app asks your account for the three choices.
- Up to 5 requests in 15 minutes. After 3 are declined in 15 minutes, requests pause for an hour (codes still work, and your account page can resume them).
- It counts as two-step sign-in for an organization's sign-in policy.
See Sign-in approvals for the API.
Backup
The backup keeps an encrypted copy of your accounts in your Cactive account, for a new phone:
- In Settings, open Account Backup, sign in, and choose a passphrase of 10 characters or more.
- The phone derives a key from it (PBKDF2-HMAC-SHA-256, 600,000 iterations, a random salt) and encrypts the accounts with AES-256-GCM. Cactive stores the encrypted copy, its format version and the salt, never the passphrase or the key, so no one else can read your accounts and a forgotten passphrase can't be reset.
- Changes back up a moment after you make them. On a new phone, sign in under Account Backup and enter the passphrase to restore.
Two phones backing up with the same passphrase are combined, so an account removed on one comes back from the other's backup. Change Passphrase and Turn Off Backup (which deletes it from your account) are in the same place. Signing out turns backup off on that phone; the backup stays in your account. See Authenticator backup for the API.
Passwords
Passwords keeps your logins, passkeys, secure notes and cards, encrypted on your phone before anything reaches your Cactive account, and fills them in Safari and other apps. Nobody else can open your vault, Cactive included.
Setting it up
- Open the Passwords tab, sign in, and tap Create Vault.
- Choose a master password: 10 characters or more and not easy to guess (four or more unrelated words work well). It never leaves your phone, and nobody can reset it for you.
- Save your Emergency Kit. It holds your Secret Key, a code your phone makes (it starts with
C1). Print it or write it down and keep it somewhere safe and offline, then type its last five characters to confirm. You need the Secret Key and your master password to open your vault on a new device.
To use Passwords on another phone, sign in there, tap Enter Secret Key, and type the Secret Key or scan the QR code on your Emergency Kit (or in Passwords Settings → Emergency Kit on a phone that's set up), then enter your master password.
Every day
- Unlocking: Face ID (or Touch ID) unlocks Passwords; every 14 days it asks for your master password instead (or every 7 or 30 days: Passwords Settings). Passwords locks a minute after you leave the app; change that under Lock After Leaving, or use Lock Now.
- Items: tap + for a login (username, password, websites, notes and a one-time code from the site's setup key), a card or a secure note. Search, filter by kind or favourites, and press and hold an item to copy its username, password or code.
- Copying: copied passwords, codes and card numbers stay on this phone (they aren't offered to your Mac) and clear themselves after a minute (30 seconds to 2 minutes).
- Generating: Generate a Password makes random passwords of 8 to 64 characters, from letters, digits and symbols.
- Watchtower finds weak passwords and passwords used for more than one item. Check with Have I Been Pwned looks for passwords that appeared in public breaches: your phone sends the first 5 characters of each password's SHA-1 hash (never the password) straight to Have I Been Pwned and compares the answer itself.
AutoFill
Turn on Cactive Authenticator in Settings → General → AutoFill & Passwords (Passwords Settings → AutoFill opens it). Then:
- tap a password field and choose a login above the keyboard, or tap the key icon to pick one; Face ID unlocks it every time;
- passkeys: when a site offers to make a passkey, choose Cactive Authenticator to keep it in your vault; signing in later asks for Face ID.
Logins are offered only on the websites they were saved for (and their subdomains), never on lookalike sites or on http: pages. To suggest logins above the keyboard, iOS keeps their websites and usernames (never passwords) on your phone; Suggest Above the Keyboard turns that off.
Keeping it safe
- Cactive stores only encrypted data, plus what it needs to sync: when items change, how many there are, and your devices' names. Your master password and Secret Key never leave your devices.
- Changes need your vault's own key, not just your Cactive sign-in, so someone who steals your sign-in can't change or delete your items.
- Devices (Passwords Settings) lists the devices that can open your vault. If one is lost, remove it, change your master password and choose Replace Secret Key; Cactive also emails you when a device is added or your master password changes.
- Forgot your master password, or lost your Secret Key, with no device that can still open the vault? Reset Vault on the set-up screen deletes it after 7 days (any of your devices can cancel it meanwhile), and then you can make a new one. What was in it can't be recovered.
See Passwords vault for the API.