AndOTP authenticator works great for me. I also wrote one that I use on an offline computer (TOTP is rfc6238) in case my phone dies or is unavailable for some reason.
My only gripe with my current usage of GrapheneOS is that sometimes when the notification bell goes off and I open the phone, the SMS was sent many minutes ago (up to an hour or so). I'm only presuming it's due to a lack of google services or something about GrapheneOS; but it might be the network operator.
Other sources I trust include:
- APKMirror (operated by Android Police): https://www.apkmirror.com
- Aptoide (only trust signature-verified "Trusted Apps", including all apps in the main "apps" store/repository): https://aptoide.com
- Direct downloads, when offered by the developer
Personally, I have never tied myself down to particular apps. What I use tends to be fairly generic and doesn't compel me to use a particular implementation by a particular company. I suspect a great number of people are like that. While my case is due to a lack of interest in the latest fads and an interest in open technologies, someone else may do so for security and privacy, while others may be interested in investing their energy in pursuits other than gadgets.
As important as technology is to the functioning of modern society, I think there is a tendency to forget that some technologies have very little lasting impact.
Authenticators usually are open source.