Choosing an authenticator app

    An authenticator app is a large security upgrade over text-message codes, which remain vulnerable to SIM-swap fraud. The apps themselves differ less in the codes they produce than in what happens when you lose or replace your phone, and that is what should drive your choice.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    They all generate the same codes

    Almost every authenticator implements the same open standard, generating a six-digit code from a shared secret and the current time. That means any of them will work with any service that offers authenticator-app two-factor authentication, and you can move between them freely if you keep the original setup codes.

    The differences that matter are backup, synchronisation across devices, whether secrets can be exported, and how well the app protects itself with a PIN or biometric lock.

    How the main options compare

    Google Authenticator now supports account synchronisation, which fixed its historical weakness, though the export path remains limited. Microsoft Authenticator adds encrypted cloud backup and push approvals for Microsoft accounts, making it the natural choice inside that ecosystem. Authy remains popular for its multi-device support and encrypted backups, with the caveat that its desktop applications were retired.

    Password managers such as 1Password, NordPass, Proton Pass and Bitwarden also store codes. That is convenient and vastly better than no second factor, though it does put the password and the code in one place, which is a trade-off worth making consciously.

    • Google Authenticator: simple, now syncs, limited export
    • Microsoft Authenticator: encrypted backup, push approvals
    • Authy: multi-device, encrypted backup, mobile-focused
    • Password managers: convenient, single point of compromise
    • Hardware keys: strongest, phishing-resistant, costs money

    Backup is the decision that matters

    Most people who lose access to their accounts do so because they replaced a phone without moving their codes. Whatever app you choose, either enable its encrypted backup with a strong separate password or store every service's recovery codes offline at setup.

    Recovery codes are the universal safety net. Print them or keep them in an encrypted file that is not stored inside the account they protect, and regenerate them after any suspected compromise.

    Where passkeys and hardware keys fit

    Authenticator codes can still be phished: a live relay page collects your password and code and uses them within seconds. Passkeys and hardware security keys are bound to the real domain and cannot be replayed, so prefer them wherever a service supports them.

    Keep an authenticator app for the many services that still offer nothing better, and remove text-message recovery from any account that allows you to.

    Switching apps safely

    Do not delete the old app first. For each important account, sign in, disable two-factor authentication and re-enable it, scanning the new QR code with the new app and confirming a code works before moving on. Save the fresh recovery codes as you go.

    Work through your email and password manager first, then banking, then everything else. Keep the old phone accessible until the list is complete.

    • Re-enrol account by account, never bulk-delete
    • Verify a code works before moving on
    • Save new recovery codes for each service
    • Email and password manager first

    Frequently asked questions

    Is an authenticator app better than SMS codes?

    Yes. Text messages can be intercepted or redirected through SIM-swap fraud, while app codes are generated locally on your device.

    What happens if I lose my phone?

    You recover through the app's encrypted backup, a second enrolled device, or the recovery codes you saved when enabling two-factor authentication. Without one of those, account recovery becomes slow and sometimes impossible.

    Should I keep codes in my password manager?

    It is convenient and far better than nothing, but it places both factors behind one master password. If you do it, protect the manager with a strong password and a hardware key.

    Can authenticator codes be phished?

    Yes, by real-time relay pages. Passkeys and hardware security keys are the phishing-resistant options.

    Is Authy still a good choice?

    It remains a solid mobile option with encrypted backups and multi-device support, though desktop users now need an alternative.