Pricing
Crew2FA is free. Not freemium, not a free trial, not a free tier with paid upgrades. Free.
What "free" means here
- No per-seat cost. Add your whole crew — 3 people or 30 — the price stays at zero.
- No feature gates. Unlimited organizations, unlimited TOTP sites per organization, unlimited shared codes. Nothing is locked behind a paid tier because there is no paid tier.
- No trial. Your account never expires, never downgrades, never asks for a credit card.
- No upsell. We will never email you asking you to "upgrade to Pro". There is no Pro.
How we keep the lights on
Two revenue streams, neither of them from you:
- Ads on public pages. Anonymous visitors see third-party ads (currently Google AdSense). The ads respect the EU/UK consent regime (we use Google's Funding Choices CMP) and the California "Do Not Sell" rules. Authenticated pages serve zero ads — we don't believe people who trusted us with their 2FA should have to look at an ad for vitamins while checking their codes.
- The operator's own wallet. The server runs on a Hetzner CX23 (about €5/month) plus a Cloudflare free-tier account and a domain registration (about €10/year). That's it. The operator pays for these out of pocket, not from a business account that depends on user fees.
What is NOT free — and why
Three things you have to supply yourself, because we genuinely cannot help with them:
- An authenticator app
- You need a TOTP authenticator on your phone (or laptop). TOTP is an open standard, so this isn't vendor lock-in — we support every compliant app. Free options include Google Authenticator, Aegis (Android), and 2FAS (iOS + Android). We don't make a recommendation because we don't have one — any of them works.
- Internet connectivity
- Once you're logged in, you can view every TOTP code your organization has stored without touching your authenticator again — the authenticator is only used at login, not for fetching the shared codes themselves. Your authenticator app computes its login code locally, from the secret you scanned at signup plus your phone's clock — the app never talks to our server and never sends the code to us. You read the 6-digit code off the app, type it into our login form, and we verify it against our stored copy of your secret. If our server is unreachable (your internet is down or ours is), you can't complete login — but your authenticator keeps computing valid codes, you just have nowhere to type them. The codes are valid everywhere; the only constraint is reaching this site.
- A working email address
- You need an email address that can receive mail from us. We send up to five categories of transactional email — never marketing, never a newsletter, never promotional:
- Signup verification. One magic link at signup, valid 24 hours.
- Password-reset link. When you request one. Single-use, expires in 1 hour.
- Password-changed heads-up. To you, immediately after you complete a reset — a defense-in-depth signal in case someone else rotated your password.
- Invite-redeemed notice. To organization admins when their invitee signs up, unless Opt-out is chosen in their profile.
- Invite-expired notice. To organization admins when their invitee fails to sign up, unless Opt-out is chosen in their profile.
Will it stay free?
Our commitment, in three sentences:
We will not charge existing users retroactively. We will not introduce a paid tier and lock features behind it. If we ever had to shut down the service, we would announce it publicly 90 days in advance and publish a tool to export your TOTP secrets in standard base32 format.
The full terms are in the Terms of Service. The short version: this is a hobby project that the operator funds personally, and "free" is not a marketing slogan — it's a structural commitment.
What we don't do, in exchange for "free"
- We don't sell your data. See the Privacy policy; the relevant sentence is "We do not sell your data" and it's not buried.
- We don't run third-party analytics. No Google Analytics, no Meta Pixel, no Hotjar. The Cloudflare free tier gives us anonymized request counts; that's enough.
- We don't A/B test you. Every visitor sees the same pricing page.
- We don't email marketing. Every mail we send is transactional — signup verification, password reset, password-changed heads-up, and (to admins only, opt-out-able per user) invite lifecycle notifications. No newsletter. No "we miss you" re-engagement campaign. No upsell. No "feature announcement" emails.
Questions we expect
If it's free, why do I have to create an account?
Because TOTP verification requires the server to know your encrypted secret. We can't verify your code without storing it. Anonymous usage isn't an option — TOTP is intrinsically server-stateful.
If it's free, why do I have to enable 2FA?
This is a 2FA app. The whole product is the second factor. There's no first-factor-only "free lite" tier because the second factor is what we're offering.
Can I share codes with people outside my organization?
You can add anyone to your organization — including organizations of one. If you want a single shared codespace for a vendor login shared across teams, create an org, add the relevant teammates, and drop the TOTP site in.
Do you have a refund policy?
There is no charge, so there is nothing to refund. If you ever do see a charge from us, it's fraud and you should dispute it with your bank; we never charge anyone for anything.
How can I support the project?
Use it, tell a coworker who shares a vendor login, and report bugs via bug_report@crew2fa.com. There's no Patreon, no GitHub Sponsors button, no "buy me a coffee" link — the operator funds it personally and prefers it that way.
No credit card. No trial period. Only transactional email — never marketing.