Articles · Apps

Authenticator apps you can actually move to a new phone

A time-based code is generated from a shared secret and the clock. Nothing about it is tied to a device, which means any authenticator can generate the same codes given the same secrets. The difficulty is entirely in whether your current app will give those secrets back, and several historically would not.

Which apps let you leave

AppExportBackup
AegisEncrypted file you holdYes, to your own storage
Google AuthenticatorTransfer to another phone by QROptional account sync
Microsoft AuthenticatorCloud backup tied to an accountYes, account based
Duo MobileAccount-based restoreYes, for supported accounts
A password manager's built-in codesYes, with the vaultYes, and see the caveat below

Advertisement

The apps

1

Aegis Authenticator - 2FA App

Beem Development
4.8 500 K+ 7 MB

Open source, encrypted vault, exports to a file you control, imports from most other apps. The right default for anyone who wants to own their codes.

2

Google Authenticator

Google LLC
3.9 100 M+ 6 MB

Simple and universally supported. Phone-to-phone transfer by QR code works well now, which was the historical complaint.

3

Microsoft Authenticator

Microsoft Corporation
4.6 100 M+ 56 MB

Necessary if your workplace uses Microsoft accounts, and it handles standard codes alongside them.

4

Duo Mobile

Cisco Systems, Inc.
4.2 50 M+ 34 MB

Common in universities and larger companies. Restore depends on the organisation's configuration.

5

Bitwarden Authenticator

Bitwarden Inc.
3.9 100 K+ 37 MB

Bitwarden Authenticator. Free, open source, with a plain export to a file.

6

Proton Authenticator & 2FA

Proton AG
4.8 500 K+ 91 MB

Proton Authenticator. End to end encrypted sync, and export that works.

7

Yubico Authenticator

Yubico AB
3.8 500 K+ 29 MB

Yubico Authenticator. Keeps the codes on a hardware key, so a stolen phone has none of them.

8

Bitwarden Password Manager

Bitwarden Inc.
4.7 5 M+ 127 MB

Bitwarden's password manager can generate codes on a paid plan, if you accept holding both factors in one vault.

9

Keepass2Android Password Safe

Philipp Crocoll (Croco Apps)
4.3 1 M+ 70 MB

Keepass2Android stores TOTP secrets in your own KeePass database, exportable by design.

10

KeePass DX

N/A
100+ 13 MB

KeePassDX. The same KeePass approach, open source, with TOTP entries built in.

11

1Password: Password Manager

AgileBits
4.6 1 M+ 604 MB

1Password includes a built in authenticator for anyone already paying for it.

The part everyone skips

Every service that offers two-factor also offers backup codes, usually shown once during setup. Those codes are the way back in when the phone is gone, and almost nobody saves them.

  1. Save the backup codes at setup Every time. A printed copy in a drawer beats a file on the phone holding the authenticator.
  2. Register a second factor where possible A second phone, a hardware key, or a second authenticator with the same secrets.
  3. Keep the recovery material away from the phone If both live on the same device, one loss takes everything.
  4. Test recovery on one account Once, deliberately, while nothing is wrong.

Should the password manager hold the codes?

Convenient
  • One app, autofilled together
  • Backed up with the vault
  • Much better than not using two-factor at all
Weaker
  • Both factors behind one master password
  • One compromise takes both
  • Defeats the purpose for high-value accounts

The reasonable middle is to split by value. Codes for forums and shopping sites in the password manager is fine. Codes for email, banking and the password manager's own account belong in a separate app, because email is the reset path for everything else.

Use Aegis if you want to own the file, save every service's backup codes today, and keep email and banking codes out of your password manager.

Frequently asked questions

Can I use the same codes on two phones?

Yes. The secret is what matters, so importing it into a second app on a second device gives identical codes. That is a legitimate backup strategy.

What happens if I lose the phone with no backup?

You use the backup codes. Without those, recovery depends entirely on each service's support process, and some have none.

Is SMS two-factor good enough?

Better than nothing, and the weakest option, because a number can be taken over. Move to an app wherever the service allows it.

Read next

Three different problems with one symptom

Nothing has infected your phone. Something you installed has permission, and the fix is a list in settings.

The port does more than charging

A phone will happily run a keyboard, a mouse and a memory stick. It will not power a desktop hard drive.

Difficult, and never in a hurry

Hard and fast are different things. Almost every game confuses them, and these do not.