Technology
MeldID After Update: Secured Storage Becomes a Daily Tool
The new version of MeldID expands not just the TOTP principle but everything surrounding one-time codes: local search, encrypted notes, tags, importing QR codes from images, hiding and copying codes, restoring deleted records, and syncing changes across devices. The Zero Vault architecture principle remains intact.
In the previous article, I discussed MeldID as a system that goes beyond a single account. Mobile applications for iPhone and Android combined TOTP authentication, full offline operation, secure data recovery on a new device, and login confirmation for connected services.
The new update is interesting for a different reason. It nearly skips attempting to add yet another high-profile login mechanism. The main focus is on everyday work with the secured storage.
Initially, when a user has two or three entries, a simple list suffices. But over time, it includes work email, personal accounts, dashboards, cloud services, corporate systems, and test environments. At this point, the issue is no longer generating a six-digit code. It's about quickly finding the right entry, understanding its purpose, avoiding account confusion, securely changing data, and not losing information when working across multiple devices.
This is where MeldID significantly enhances its functionality.
The main change is the organization within the secure storage
I would describe the new version as a transition from a simple list of TOTP entries to a more manageable workspace.
This doesn’t mean the app has become more complex. Quite the opposite: new features address situations that previously required manual solutions. Users no longer need to remember where a particular entry is, keep account descriptions in mind, or redo the setup after accidental deletion.
The key is that these features are interconnected. Search works alongside notes, tags help filter results, importing from QR codes is accompanied by visual highlighting of new entries, and deletion and restoration are synchronized across all devices under the same account.
Search remains local
MeldID now offers local search by service name, account name, and note content. Although straightforward, this function starts saving time when there are many entries.
For example, if there are multiple accounts for the same service—personal, work, admin—it's enough to enter part of the service name or email. If a note exists for an entry, it can also be searched.
Importantly, the search doesn’t access the TOTP secret itself. The secret isn’t turned into a searchable field nor used as an identifier. The user searches for a meaningful context—service name, account, or note—not cryptographic data.
The search query isn’t sent to the server. The app searches within the encrypted vault stored locally on the device.
Notes and tags add context to entries
Sometimes a service name isn’t enough to understand what a record is for. Therefore, TOTP entries can now have encrypted notes attached.
In such a note, you can specify which work environment the account belongs to, which department it was created for, or which login method is used. The note is stored together with the encrypted entry inside the Vault, not as separate open information on a server.
Groupings are enhanced with multi-tags. A single entry can have multiple labels, such as “Work,” “Critical,” “Europe,” or “Test.” Tags are entered as plain text: new tags can be added by pressing Enter or commas, and later deleted as compact elements.
The system also suggests existing tags and merges identical options regardless of case. So, “Work,” “work,” and “WORK” are treated as the same category.
Tags have a dedicated local filter. If the structure changes over time, a tag can be renamed or globally deleted with a long press. There’s no need to open individual entries and manually correct the same label dozens of times.
Favorites are now a dedicated system tag with a star icon, highlighted in red, allowing to quickly isolate the most important entries.
In practice, this transforms the storage from a collection of codes into a system that can be organized according to personal logic.
You can still use hidden codes
The app now allows toggling the visibility of TOTP codes. The chosen state is saved on the device, so after restart, the display remains as set.
This provides a visual security measure: the code isn’t constantly visible unless needed. But hiding doesn’t prevent working with the entry.
The code can be copied to the clipboard in both visible and hidden modes. This logical separation is useful—users may prefer not to display digits but still need to input the code into login forms.
QR codes no longer need to be rescanned
Previously, adding a TOTP entry often involved using a camera to scan a QR code displayed on a second screen. MeldID now can import TOTP entries from a photo or an image saved in the gallery.
This feature is useful in various situations. The QR code might be in a screenshot or captured during service setup. It isn’t always convenient to reopen the setup page and keep it in front of the camera again.
Just select the image containing the QR code, and the app will recognize it and create an entry inside the secure storage.
New entries are temporarily highlighted with a frame. This is especially helpful when transferring multiple accounts in a row: the user immediately sees which entries are new and won’t confuse them with existing ones.
Deleting now offers an undo option
One of the most practical updates—deletion with a grace period for recovery.
A deleted entry doesn’t disappear instantly. It can be restored within a pre-set period, requiring a separate confirmation. This prevents accidental swipe, mistaken tap, or deleting the wrong account.
Another safeguard is that while the recovery period is active, the app does not allow re-adding the same TOTP secret as a new record.
For example, if a user deletes an account and then re-scans the old QR code, without an additional check, two entries with the same secret could appear. MeldID prevents this duplication, keeping the original record intact.
Recovery also affects the encrypted Vault’s state and syncs with the server, not just local changes.
One account—one coherent storage
Working with multiple devices was one of the core ideas of mobile MeldID. The new update makes it more consistent.
Deletions, restorations, edits of notes and tags, and other changes to the Vault are synchronized across devices tied to the same account. When working with iPhone and Android or second phones, all devices reach a confirmed consistent state.
If an action is performed on one device, the synchronization mechanism prevents an outdated copy on another from secretly restoring an old entry or overwriting recent modifications. Conflict resolution has been further improved for multi-device use.
Different accounts on the same device still remain separate. Data from one account isn’t mixed with another, and changes apply only to the respective protected storage.
The distinction between offline and online scenarios remains. TOTP code generation for existing entries is independent of internet access, and new entries can be prepared locally. Changes that must be applied to all devices are synchronized once the connection is restored.
Zero Vault remains fundamental
The principle of Zero Vault continues to apply on MeldID’s side. The server only handles encrypted, opaque states of the secured storage and technical data necessary for versioning and syncing.
Secrets, notes, tags, and service names in plain text are not transmitted to the server. They do not become part of a raw table that could be viewed or used for server search.
The Vault contents are decrypted locally on a trusted device. This is why notes and tags are processed locally: the server does not need to read the contents to accept a new encrypted version or synchronize it across devices.
The new features respect this principle and do not trade privacy for convenience. Instead, they demonstrate how a protected storage can be both user-friendly and private, without turning into an open server directory.
Small details that influence trust
The update also improves translations, accessibility labels, and visual interface elements.
These might seem minor compared to QR code import or recovery features. But with features like hidden display modes, favorites, pending deletion states, and separate recovery confirmations, icons are no longer sufficient alone.
Clear labels are important for all users, and especially for VoiceOver, TalkBack, and other accessibility tools. Updated translations and clearer visual states make new scenarios more understandable across languages and platforms.
My conclusion
Having reviewed the update, I see MeldID no longer just as an app for generating TOTP codes.
The main change lies not in a single feature but in the interconnectedness: local search works with notes and tags, favorites help highlight vital entries, QR code import is simplified via image handling, newly added entries are more noticeable with frames, and recovery periods reduce accidental deletions.
Synchronization links changes across devices, while Zero Vault preserves the secure storage model.
As a result, MeldID is gradually evolving from a simple authenticator into a managed, secure workspace. TOTP codes are still generated locally and are available offline, but everything around them is now more transparent and predictable.
More about the project: MeldID.