Authenticator apps you can actually move to a new phone
A time-based code is generated from a shared secret and the clock. Nothing about it is tied to a device, which means any authenticator can generate the same codes given the same secrets. The difficulty is entirely in whether your current app will give those secrets back, and several historically would not.
Which apps let you leave
| App | Export | Backup |
|---|---|---|
| Aegis | Encrypted file you hold | Yes, to your own storage |
| Google Authenticator | Transfer to another phone by QR | Optional account sync |
| Microsoft Authenticator | Cloud backup tied to an account | Yes, account based |
| Duo Mobile | Account-based restore | Yes, for supported accounts |
| A password manager's built-in codes | Yes, with the vault | Yes, and see the caveat below |
Publicité
The apps
Open source, encrypted vault, exports to a file you control, imports from most other apps. The right default for anyone who wants to own their codes.
Simple and universally supported. Phone-to-phone transfer by QR code works well now, which was the historical complaint.
Necessary if your workplace uses Microsoft accounts, and it handles standard codes alongside them.
Common in universities and larger companies. Restore depends on the organisation's configuration.
The part everyone skips
Every service that offers two-factor also offers backup codes, usually shown once during setup. Those codes are the way back in when the phone is gone, and almost nobody saves them.
- Save the backup codes at setup Every time. A printed copy in a drawer beats a file on the phone holding the authenticator.
- Register a second factor where possible A second phone, a hardware key, or a second authenticator with the same secrets.
- Keep the recovery material away from the phone If both live on the same device, one loss takes everything.
- Test recovery on one account Once, deliberately, while nothing is wrong.
Should the password manager hold the codes?
- One app, autofilled together
- Backed up with the vault
- Much better than not using two-factor at all
- Both factors behind one master password
- One compromise takes both
- Defeats the purpose for high-value accounts
The reasonable middle is to split by value. Codes for forums and shopping sites in the password manager is fine. Codes for email, banking and the password manager's own account belong in a separate app, because email is the reset path for everything else.
Use Aegis if you want to own the file, save every service's backup codes today, and keep email and banking codes out of your password manager.
Frequently asked questions
Can I use the same codes on two phones?
Yes. The secret is what matters, so importing it into a second app on a second device gives identical codes. That is a legitimate backup strategy.
What happens if I lose the phone with no backup?
You use the backup codes. Without those, recovery depends entirely on each service's support process, and some have none.
Is SMS two-factor good enough?
Better than nothing, and the weakest option, because a number can be taken over. Move to an app wherever the service allows it.
Read next
This is not a rivalry. Each does something the other cannot.
You are not buying encryption. You are buying an operator whose income does not depend on you.
For a plain ZIP either works. For a split, password-protected archive, only one does.

