Skip to content

Authenticator apps compared: what to look for

By TOTP Authenticator team ·

The authenticator apps worth comparing all generate correct six-digit codes. That part of the job has been a solved problem for years. What actually differs is what happens when you lose a device, whether you can get your data back out in a format you control, how well each one handles dozens or hundreds of accounts instead of five, and how honestly each one explains its own limits before you commit to it. Here’s what we’d check, criterion by criterion, and where we think each app stands, including us.

Export and portability

Ask this before anything else: if you decided to stop using an app tomorrow, could you get your accounts out in a form another app could read? Lock-in is the single biggest risk in this category, because switching later, after you’ve accumulated fifty accounts, is exactly the kind of task people put off until a lost device forces it.

Some apps tie your account to something outside your control, such as a phone number. Authy is the clearest example: your account is bound to a phone number, so losing or changing that number complicates recovery independent of anything about the app’s security. Authy also discontinued its desktop app, which is worth knowing if a desktop is part of your workflow today. That’s a portability risk worth weighing whichever app you’re evaluating, ours included.

On our side, importing is free and built in: Google Authenticator’s own export QR codes, Aegis vault files, 2FAS backups, and plain otpauth:// lists, so arriving from any of those costs nothing. We’d judge every app on this criterion in both directions, not just on how easy it is to get in.

The backup model

This is really a question about who’s responsible for your recovery, and whether that responsibility costs money. Some apps make backup automatic through account-based cloud sync; others leave it as a manual export you have to remember to do; a few put restore itself behind a purchase, which we think is the wrong place for a paywall (see why we made backup free forever for the reasoning). Whichever model an app uses, ask it directly: if I lose this phone today, having done nothing extra in the last week, what do I actually get back, and does any of it cost money?

Organization, once you’re past a handful of accounts

Five accounts don’t need organizing. Fifty do. This is where a lot of apps show their age, having been built for a world where 2FA meant one or two banking logins rather than the dozens most people accumulate once every service requires it. Look for search that handles more than one word at a time, and folders or categories. Aegis deserves credit here: its tagging and grouping are well regarded. We’ve moved in this direction too, with opt-in issuer-based auto-categorization and search that matches on multiple terms at once, because “scroll to find it” stops working somewhere around account thirty.

Working across more than one device

If you use a browser as well as a phone, or more than one phone, sync matters. Google Authenticator does have account-based sync, and it’s worth saying that plainly rather than pretending around it. That’s a real strength if you’re already inside the Google ecosystem and want the simplest possible setup. Where we differ isn’t whether sync exists, but organization, browser-extension workflow, and how account data moves between platforms. That’s the comparison worth making, not whether the feature exists at all.

Transparency about limits

The last criterion is less concrete but matters more than it sounds: does the app’s own marketing and documentation tell you plainly what it can and can’t do? Open-source apps have a real advantage here. 2FAS and Ente both publish their source code, which you or anyone else can inspect, and that’s a meaningfully different kind of trust than “we say it’s secure.” If auditability matters to you specifically, weigh it on its own terms.

For apps that aren’t open source, the next best thing is plain language about what’s actually true: what’s free, what costs money, what the app cannot do (like restore your codes without your backup, which no app can, whatever it implies), and what data it collects. If a company’s answer to “what happens if I lose my phone” is vague, evasive, or buried three support articles deep, that itself tells you something about how they’ll treat you when something does go wrong.

Where we’d position ourselves

There isn’t one universal winner here. The right app depends on which of these criteria matter most to you. If you’re deep in the Google ecosystem and just want sync that works without thinking about it, Google Authenticator is a reasonable, honest choice. If auditability is your top priority, the open-source model of 2FAS or Ente gives you something we can’t. What we’d point to as our own strengths are organization at scale, a browser-extension workflow that goes beyond copy-pasting codes, and free, permanent account portability in and out. If those are what you’re optimizing for, see how switching works for your specific starting point.