Skip to content
Personal Security · Authentication

Best 2FA Authenticator Apps 2026: Proton vs Ente vs Google vs Microsoft

Six authenticator apps compared on the thing that actually decides the choice: whether your TOTP seeds are backed up, who holds the key to that backup, and what happens the day the phone is gone.

By ·Apr 1, 2026·Updated Sep 18, 2026·15 min·6 tools compared
2FAAuthenticationTOTPMFASecurity

Answer first

Install Proton Authenticator. It is free on Android, iOS, Windows, macOS and Linux, it is open source, its backup and sync are end-to-end encrypted, and it imports from whatever you are using now. If you want copyleft licensing and a web client, use Ente Auth instead; it is equally free and equally end-to-end encrypted. If you are on Android and want nothing in anyone's cloud, use Aegis and send its encrypted backup somewhere off the phone today. If work runs on Microsoft 365, keep Microsoft Authenticator for the work account and put your personal seeds elsewhere.

The question everyone gets wrong

Buyers compare authenticator apps on interface and platform support. The decision is actually made on one question: where is the TOTP seed backed up, and who can read that backup?

A TOTP seed is a shared secret. Whoever holds it can generate valid codes for that account forever, from anywhere, without touching your account and without leaving a trace you would notice. So there are only four real designs, and every app is one of them:

  1. End-to-end encrypted cloud backup. The provider stores your seeds and cannot read them. Proton Authenticator, Ente Auth and Authy all work this way. This is the best default.
  2. Cloud backup that the provider can read. Google Authenticator's sync is encrypted in transit and at rest, but Google holds the keys. End-to-end encryption has been signalled since 2023 and has not shipped. Better than no backup, worse than option one.
  3. Device-bound, with a backup you manage. Aegis, or any app in offline mode. Nothing to compel, nothing to breach, and nothing to save you if you skip the backup step.
  4. Device-bound, with no backup. This is where most people actually are, and it is why "I lost my phone" is the most common 2FA disaster by a wide margin.

The failure mode is never exotic. It is a dropped phone, an unbacked-up vault, and a week of arguing with support desks about whether you are you.

What changed since this page was last written

  • Proton Authenticator launched in 2025 and reset the baseline. A free, open-source, end-to-end encrypted, genuinely cross-platform authenticator did not exist before it.
  • Microsoft removed password management from Authenticator between June and August 2025, consolidating it into Edge. Two-factor codes and passkeys were unaffected, but an app a lot of people treated as a light password vault stopped being one.
  • Authy lost its desktop apps when Twilio discontinued them in 2024, and a 2024 breach of an unsecured Twilio API exposed 33 million Authy phone numbers. No seeds were taken, but the product is no longer the default it was.
  • Raivo OTP is effectively abandoned, sold to a company called Mobime in 2023 with no meaningful updates since. It has been removed from this comparison.

If the accounts you are protecting are your email, your password manager or your domain registrar, stop reading here and go further than TOTP: a real-time phishing proxy can relay a valid six-digit code faster than you can read it. See the hardware security key comparison for what to use instead, and the password manager comparison for where synced passkeys live.

Quick Comparison

AppBest forBackup modelCross-device syncOpen sourcePlatformsPrice
Proton AuthenticatorMost people, on any mix of devicesEnd-to-end encrypted backup and sync, or local exportYes, via an optional Proton accountYesAndroid, iOS, Windows, macOS, Linux, Apple WatchFree
Ente AuthOpen-source stack with real cloud recoveryEnd-to-end encrypted cloud backup, externally audited cryptographyYes, across mobile, desktop and webYes (AGPL-3.0)Android, iOS, macOS, Windows, Linux, webFree
Aegis AuthenticatorAndroid users who want nothing in a cloudLocal encrypted vault, password-encrypted backup files you move yourselfNoYesAndroid onlyFree
Microsoft AuthenticatorMicrosoft 365 and Entra ID environmentsCloud backup tied to a Microsoft account (and iCloud on iOS)Restore to a new device, not true multi-deviceNoAndroid, iOSFree
Google AuthenticatorThe simplest thing that works, already installedGoogle account sync, encrypted in transit and at rest but not end-to-endYes, via Google accountNoAndroid, iOSFree
AuthyExisting users who have not moved yetEncrypted cloud backup protected by a separate backup passwordYes, multiple mobile devicesNoAndroid, iOS (desktop apps discontinued in 2024)Free

Proton Authenticator

Best for
Most people, on any mix of devices
Backup model
End-to-end encrypted backup and sync, or local export
Cross-device sync
Yes, via an optional Proton account
Open source
Yes
Platforms
Android, iOS, Windows, macOS, Linux, Apple Watch
Price
Free

Ente Auth

Best for
Open-source stack with real cloud recovery
Backup model
End-to-end encrypted cloud backup, externally audited cryptography
Cross-device sync
Yes, across mobile, desktop and web
Open source
Yes (AGPL-3.0)
Platforms
Android, iOS, macOS, Windows, Linux, web
Price
Free

Aegis Authenticator

Best for
Android users who want nothing in a cloud
Backup model
Local encrypted vault, password-encrypted backup files you move yourself
Cross-device sync
No
Open source
Yes
Platforms
Android only
Price
Free

Microsoft Authenticator

Best for
Microsoft 365 and Entra ID environments
Backup model
Cloud backup tied to a Microsoft account (and iCloud on iOS)
Cross-device sync
Restore to a new device, not true multi-device
Open source
No
Platforms
Android, iOS
Price
Free

Google Authenticator

Best for
The simplest thing that works, already installed
Backup model
Google account sync, encrypted in transit and at rest but not end-to-end
Cross-device sync
Yes, via Google account
Open source
No
Platforms
Android, iOS
Price
Free

Authy

Best for
Existing users who have not moved yet
Backup model
Encrypted cloud backup protected by a separate backup password
Cross-device sync
Yes, multiple mobile devices
Open source
No
Platforms
Android, iOS (desktop apps discontinued in 2024)
Price
Free
1

Proton Authenticator

Best Overall

Best for: Almost everyone: free, open source, end-to-end encrypted sync, and it runs on desktop as well as phone

“Launched in 2025 and now the default recommendation. It is free on every platform, open source, syncs with end-to-end encryption, and does not require a Proton account unless you want sync. It also imports directly from Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth and LastPass, which removes the main reason people stay on an app they have outgrown.”

Pros

  • End-to-end encrypted backup and sync, so Proton cannot read your TOTP seeds even though it stores them, which is the exact property Google Authenticator's sync does not have
  • Runs on Android, iOS, Windows, macOS, Linux and Apple Watch, so the codes are on the laptop when the phone is charging in another room
  • Works with no account at all if you prefer purely local storage, and supports direct export as well as import, so you are never locked in

Cons

  • New enough that its long-term track record is short, and it inherits whatever view you hold of Proton as a company
  • Sync requires a Proton account, which is another credential to protect, and that account becomes a high-value target once it holds your second factors
Honest Weakness: It is a 2025 product. Proton publishes the source and says the apps are open for inspection, but Proton Authenticator does not yet have the years of adversarial attention that Google Authenticator and Authy have absorbed. The product page does not cite a named third-party audit of the Authenticator app specifically, as distinct from Proton's other apps. That is a smaller risk than running unencrypted cloud sync, which is why it still ranks first, but it is a real one and it is the reason to keep an exported backup rather than trusting sync alone.

Why end-to-end encryption on the backup is the whole argument

A TOTP seed is a shared secret. Anyone holding it can generate valid codes for your account forever, silently, from anywhere. That makes the question of who can read your backup more important than any feature on a comparison table. Proton Authenticator encrypts backups and sync end-to-end, meaning the keys stay on your devices. Google Authenticator's sync is encrypted in transit and at rest but Google holds the keys, so a compelled disclosure or an internal compromise reaches your seeds. Both are better than no backup. Only one keeps the seed out of the provider's hands.

Desktop support and why it matters

Most authenticator apps are phone-only, which quietly makes your phone a single point of failure for every account you own. Proton Authenticator ships desktop apps for Windows, macOS and Linux alongside the mobile apps. That is not just convenience: a second device with the same seeds is the cheapest form of redundancy available, and it is the answer to the most common 2FA disaster, which is not a hack but a dropped phone.

Migration in and out

The app imports from Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth and LastPass, and exports in a form you can take elsewhere. Treat the export as part of setup, not as a feature you will use later. Generate one, encrypt it, and store it where you store your recovery codes, because the export is what survives a lost phone, a forgotten account password and a vendor you have decided you no longer trust.

Free on all platforms, no ads, no tracking. A Proton account is optional and only needed for sync.

Visit Proton Authenticator
2

Ente Auth

Best Open Source

Best for: Open-source cloud recovery, on every platform including the web

“Free, AGPL-3.0 licensed, end-to-end encrypted cloud backup, and it runs on mobile, desktop and the web. Ente states its cryptography has been externally audited. If your objection to Proton is that you want the source under a copyleft licence and the project independent of a large privacy brand, this is the pick.”

Pros

  • End-to-end encrypted cloud backups with externally audited cryptography, per the vendor, so recovery does not require trusting the operator with the seeds
  • Fully open source under AGPL-3.0 with the code and the repository public, and distributed through F-Droid as well as the app stores
  • Offline mode works with no account and no backup at all, so the same app covers the local-only user and the sync user

Cons

  • The vendor states the cryptography was externally audited but does not link the audit report on the product page, so the claim cannot be checked from the page itself
  • The free authenticator is funded by a paid photo product from the same company, which makes its long-term economics dependent on a business you may never use
Honest Weakness: Ente Auth is free and the company says it will stay free forever, but it is a free product cross-subsidised by Ente's paid encrypted photo storage. That is a legitimate model and plenty of good software runs on it. It is also a dependency worth naming: if the photo business struggles, the authenticator's funding goes with it. The mitigation is the same as everywhere else on this page, and it is cheap: export your seeds, encrypt the export, store it offline. An open-source app with an export function is very hard to be trapped by.

Web access as a recovery path

Ente is the only app here with a browser client. That is a meaningful difference on the worst day: phone gone, laptop at home, and you need into your email from a borrowed machine. It is also an added attack surface, because a browser client means your vault can be reached from any device that can reach the internet. Both statements are true. Whether the trade is worth it depends on whether your realistic failure mode is losing a phone or being targeted.

What AGPL-3.0 actually changes

Copyleft licensing means a company that forks Ente and runs it as a service has to publish its changes. Compared with a permissive licence, that makes a closed, diverged derivative much harder to build. For an app that holds the keys to every other account you own, the practical value is continuity: if the company stops, the code and the protocol stay usable and forkable, and the encrypted backups stay decryptable by software you can obtain.

Offline mode

Ente Auth runs with no account and no cloud at all if you choose. That makes it the one app on this page that covers both ends of the backup argument with the same binary. Cloud recovery for people who will lose a phone before they are targeted, and pure local storage for people whose threat model runs the other way. Aegis does local-only better, but it only does Android.

Free. The company states the authenticator is free and will remain free.

Visit Ente Auth
3

Aegis Authenticator

Best for Privacy

Best for: Android users who want their TOTP seeds to never leave the device

“The reference implementation of local-first 2FA on Android. Free, open source, offline, with an encrypted vault, optional biometric unlock and password-encrypted backup files you move yourself. There is no sync and no cloud, which is either the point or a dealbreaker, depending on who is holding the phone.”

Pros

  • Works completely offline with no account, no server and no telemetry, so there is no provider that can be breached, compelled or shut down
  • Encrypted vault with optional biometric unlock, and automatic backups written to a location you choose and encrypted with a password you choose
  • Broad import and export support across other 2FA apps, so adopting it or leaving it is a five-minute job

Cons

  • Android only, with no iOS version and no desktop client, so a mixed-device household needs a second app
  • No sync of any kind, which means backup discipline is entirely yours and there is no safety net if you skip it
Honest Weakness: Aegis will not save you from yourself. The automatic backup is only as good as the place you point it at, and pointing it at the same phone's internal storage means one dropped handset takes both the vault and the backup. The app cannot warn you that your backup destination is worthless, and there is no cloud copy to fall back on. Set the backup target to somewhere off-device on the day you install it, then verify you can actually restore from it, or Aegis's biggest strength quietly becomes its biggest risk.

Local-first is a threat model, not a feature

Choosing Aegis says you think the more likely bad outcome is a provider compromise, a legal demand or an account takeover of your cloud account, rather than you losing a phone. For journalists, activists, people in hostile jurisdictions and anyone who has already been targeted, that is a defensible reading. For most people it is not, and the honest advice is that a cloud backup you actually have beats a local backup you meant to make.

Making the backup real

Configure the automatic backup on day one, send it somewhere that is not the phone, and pick a password you have not used elsewhere and have stored in your password manager. Then restore it once, onto a second device or a fresh install, before you need to. An untested backup is a belief, not a control. This is the single highest-value thing to do with Aegis and the most commonly skipped.

When to pair it with something else

If you use an iPhone as well as an Android phone, or a laptop, Aegis cannot cover you alone. The clean pairing is Aegis for high-value accounts held only on the Android device, plus Proton Authenticator or Ente Auth for everything else. Splitting deliberately by account value is different from having tokens scattered across three apps because you kept switching.

Free, open source, available on Google Play and F-Droid.

Visit Aegis Authenticator
4

Microsoft Authenticator

Best for Enterprise

Best for: Microsoft 365 and Entra ID accounts, where it is the app the tenant expects

“If work runs on Microsoft 365, this is already the app your administrator has configured, and it does the Microsoft-specific things no other app can: number-matching push approval, passwordless sign-in and passkeys for the work account. As a general-purpose TOTP app it is now weaker than it was, because Microsoft removed password management from it in 2025.”

Pros

  • Number matching on push approvals defeats MFA fatigue attacks, where an attacker spams approval prompts until someone taps yes to make them stop
  • Supports passwordless sign-in and passkeys for Microsoft work and personal accounts, not just TOTP codes
  • Deep Entra ID integration: conditional access, device registration and administrator-controlled enrolment work without third-party stitching

Cons

  • Microsoft removed password storage and autofill between June and August 2025, pushing those functions into Microsoft Edge, so an app people used as a light password manager no longer is one
  • Cloud backup is tied to a Microsoft account (and iCloud on iOS), restores to a new device rather than running on several at once, and is not open source
Honest Weakness: Microsoft shrank this app's job while most users were not watching. Between June and August 2025 it stopped accepting new stored passwords, then turned off autofill, then cut access to passwords already saved in it, with the functionality consolidated into Edge. Two-factor codes and passkeys were unaffected, but anyone who treated Authenticator as their password vault had to migrate on Microsoft's timetable. Take the lesson rather than the grievance: a free app bundled by a platform vendor serves that vendor's product strategy, and the features it gives you can be withdrawn on a three-month notice.

Number matching and MFA fatigue

A push prompt that asks only yes or no can be defeated by volume: send enough prompts at three in the morning and someone taps approve. Number matching fixes this by displaying a code on the login screen that must be typed into the app, so approval requires the person to be looking at the real sign-in attempt. This is the single most valuable thing Microsoft Authenticator does that a pure TOTP app cannot, and it only applies to accounts that use Microsoft push, not to the TOTP codes it also stores.

Where it is the right answer and where it is not

Use it for the Microsoft work account because the tenant configuration expects it and because conditional access, device registration and passwordless sign-in all depend on it. Do not make it the home for the other thirty TOTP seeds in your life. Those belong somewhere with end-to-end encrypted, portable, cross-platform backup, because the recovery story for a Microsoft Authenticator restore is tied to a Microsoft account you may not control forever.

The 2025 password removal, in order

June 2025: no new passwords could be saved. July 2025: autofill stopped working. August 2025: saved passwords became inaccessible in the app. Microsoft's guidance was to export and move to Edge or another password manager. If you still have not migrated, the export window is closed and the passwords live in whichever Microsoft account they synced to.

5

Google Authenticator

Best Free Option

Best for: The default that is good enough, especially if the alternative is no 2FA at all

“It is simple, it is free, it is already on hundreds of millions of phones, and since 2023 it backs up to your Google account so losing a phone is no longer catastrophic. The one thing to understand before choosing it: that backup is not end-to-end encrypted, so Google can technically read your TOTP seeds.”

Pros

  • Google account sync means a lost phone is a recoverable event rather than a rebuild of every account, which was the app's defining weakness before 2023
  • Minimal interface with essentially nothing to configure, which matters when you are setting up 2FA for someone who will not maintain it
  • Universally recognised, so service setup instructions and support articles almost always assume it

Cons

  • Sync is encrypted in transit and at rest but not end-to-end, so Google holds the decryption keys to your second factors; end-to-end encryption has been signalled since 2023 but has not shipped
  • Not open source, Android and iOS only, and your entire second-factor set becomes an asset of a single Google account
Honest Weakness: The sync feature that fixed Google Authenticator's biggest problem created a smaller, quieter one. Security researchers flagged in 2023 that the synced traffic was not end-to-end encrypted, Google acknowledged the criticism and said end-to-end encryption was coming, and it still had not shipped as of 2026. The practical effect is concentration risk: compromise the Google account and you reach both the recovery email and the second factors protecting everything else. If you use it, put a hardware key on the Google account itself and keep at least one high-value account's seed somewhere Google does not hold.

The sync trade-off, stated plainly

Before 2023, losing your phone meant losing every token. Now the seeds sync to your Google account, which solved the common disaster and introduced an uncommon one. Google encrypts the data in transit and at rest but holds the keys, so the seeds are reachable by a compelled disclosure, an internal compromise or an attacker who takes over the Google account. For most people, who are far more likely to drop a phone than to be targeted, the trade is still worth it. For anyone whose Google account is itself a target, it is not.

Simplicity is a real feature

The reason to still recommend this app is the person who will otherwise use SMS or nothing. It has no accounts to create beyond the Google account already on the phone, no backup password to lose, no vault to configure, and every service's setup page assumes it. Getting a non-technical family member from SMS codes to Google Authenticator is a larger security improvement than getting an enthusiast from Authy to Proton.

Concentrating risk in one account

If Google Authenticator holds your seeds and Gmail is your recovery address, your Google account is a single control point for your entire digital life. Defend it accordingly: register two hardware security keys on it, enrol in Advanced Protection if you can live with the restrictions, and keep the seeds for your most valuable non-Google account (bank, exchange, domain registrar) in a different app entirely.

6

Authy

Honorable Mention

Best for: People already using it, who need a reason to decide whether to move

“Authy still exists, is still free, and still does encrypted cloud backup and multi-device sync on mobile. It is ranked last because Twilio discontinued the desktop apps in 2024 and because a 2024 breach of an unsecured Twilio API exposed 33 million Authy phone numbers. Neither event exposed TOTP seeds, but both are reasons the app is no longer the default it once was.”

Pros

  • Encrypted cloud backup protected by a backup password that Twilio does not hold, so the seeds themselves are not readable by the provider
  • Multi-device sync across several phones and tablets, with the ability to revoke a device, which is still ahead of Google and Microsoft on that one dimension
  • Free, mature, and widely supported in service setup documentation

Cons

  • Desktop applications were discontinued in 2024 and users were forcibly logged out, removing the redundancy that made Authy attractive in the first place
  • The account is bound to a phone number, which makes SIM swapping part of your threat model whether you want it to be or not
Honest Weakness: Two things happened in 2024 and together they changed the recommendation. Twilio shut down the Authy desktop apps and logged everyone out, which removed the laptop copy that was the whole point for many users. Separately, attackers abused an unauthenticated Twilio API endpoint to confirm 33 million phone numbers as belonging to Authy accounts. Twilio said no seeds or systems were reached, and that appears to be correct, but a verified list of phone numbers known to belong to 2FA users is a targeting list for SIM swap and phishing. Combined with the account being tied to a phone number in the first place, that is enough to move.

What the backup password actually protects

Authy's backup encryption uses a password you set and Twilio does not store, which means Twilio genuinely cannot read your seeds. That is a better design than Google Authenticator's sync. It also means that if you forget the backup password, nobody can help you, and the seeds in the cloud are unrecoverable. If you are staying on Authy, confirm today that your backup password is in your password manager, because the failure mode is total and silent.

Migrating off

Authy does not offer a bulk export, which is the practical friction keeping people on it. The migration is manual: for each account, go to its security settings, disable the existing authenticator, and re-enrol using your new app's QR scanner. Do the high-value accounts first (email, password manager, domain registrar, financial), keep Authy installed until each one is confirmed working in the new app, and print fresh recovery codes as you go.

Which One Should You Pick?

Use CaseOur Recommendation
Setting up 2FA for the first time, or for someone who will not maintain itGoogle Authenticator, with sync enabled. It is already there, there is nothing to configure, and every service's instructions assume it. The concentration risk is real but secondary to the fact that it will actually get used. Then put two hardware security keys on the Google account itself.
One person, several devices, wants the seeds backed up but not readable by the providerProton Authenticator. Free, end-to-end encrypted sync, and it runs on Windows, macOS and Linux as well as both phone platforms, so the laptop is a working second copy rather than a hope.
Nothing in anyone else's cloud, everAegis on Android, or Ente Auth in offline mode on iOS and desktop. In both cases the work is the backup: send the encrypted export somewhere that is not the same device, and test a restore before you need one.
Work runs on Microsoft 365 or Entra IDMicrosoft Authenticator for the work account, because number matching, conditional access and passwordless sign-in depend on it. Keep your personal TOTP seeds in Proton Authenticator or Ente Auth, because Microsoft's recovery story is tied to a Microsoft account your employer may control.
Currently on Authy and wondering whether to moveMove, but calmly. Authy still works and your seeds are encrypted with a password Twilio does not hold. The reasons to leave are the 2024 desktop shutdown and the phone-number binding. There is no bulk export, so migrate account by account starting with email, password manager, registrar and finance, and keep Authy installed until each one is confirmed.
High-value accounts: primary email, password manager, domain registrar, exchangeStop at TOTP. These accounts should be on hardware security keys or device-bound passkeys, because a TOTP code can be phished in real time by a proxy page and a WebAuthn credential cannot. Keep a TOTP enrolment only where the service will not accept a key.

How we evaluated

Every capability, price and platform claim on this page was checked against the vendor's own site or documentation on 18 September 2026. No figure is carried across from another comparison.

Apps were judged on five things, in this order:

  1. Backup model. Whether the TOTP seeds are backed up at all, and whether the provider can read the backup. This dominates everything else, because a seed is a permanent shared secret and because a lost phone is the most common thing that actually goes wrong.
  2. Recovery path. What concretely happens on a new device: restore from an encrypted cloud copy, restore from a file you kept, or re-enrol every account by hand.
  3. Portability. Whether the app imports from others and exports to something you can keep. An app that cannot export is a trap regardless of how good it is today.
  4. Platform coverage. Whether a second device can hold the same seeds, because redundancy is cheaper than recovery.
  5. Vendor trajectory. Ownership changes, discontinued components, removed features and abandoned projects. This is what moved Authy down and removed Raivo entirely.

What was checked, and where

  • Proton Authenticator: the product page for free pricing on all platforms, platform list including Apple Watch, optional-account model, end-to-end encrypted sync and backup, open-source status, and the import list (Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth, LastPass).
  • Ente Auth: the product page for free pricing, AGPL-3.0 licensing, end-to-end encrypted cloud backups, the externally audited cryptography claim, platform list including web, and offline mode.
  • Aegis: the project site for Android-only distribution via Google Play and F-Droid, the encrypted vault with optional biometric unlock, password-encrypted automatic backups, offline operation, and import/export coverage.
  • Microsoft Authenticator: Microsoft's app page and its published June-to-August 2025 timeline for withdrawing password storage and autofill.
  • Google Authenticator: Google account sync behaviour and the still-outstanding end-to-end encryption commitment first made in 2023.
  • Authy: the Authy site for current free pricing, cloud backup and multi-device support, alongside the 2024 desktop discontinuation and the 2024 Twilio API incident that exposed 33 million phone numbers.

What we deliberately did not do

No hands-on testing claims. These apps were not run through a bench test. The assessment rests on vendor documentation, published source, licensing, and the public record of each product's changes, and each entry says which of those it rests on. Where a vendor asserts something no third party has confirmed, such as Ente's external cryptography audit, the entry says the vendor asserts it.

No ranking on interface. Every app here generates six digits every thirty seconds. Differences in how attractive that looks are not worth a place in the ordering.

2FAS is a reasonable free, open-source authenticator that did not make the six, mainly because Proton Authenticator and Ente Auth cover the same ground with stronger cross-platform reach. Worth knowing: the 2FAS authenticator is free, while 2FAS Pass, the company's separate password and passkey manager, is a paid product.

Note

Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.

Last verified: 18 September 2026. Vendor product pages, pricing, platform lists, backup and encryption claims, and the public record of discontinuations and ownership changes were all rechecked on this date.

Frequently Asked Questions

What actually happens if I lose my phone?
It depends entirely on the app and on what you set up beforehand. With Proton Authenticator, Ente Auth, Google Authenticator or Authy, the seeds are in a backup and you install the app on a new phone, authenticate to the backup, and continue. With Aegis, or with any of the above used without sync, the seeds were only on the lost device and you are into per-account recovery. That means recovery codes if you printed them, then each service's identity verification process, which can take days and can fail outright. The practical rule is that the backup question is the only question that matters, and it has to be answered on the day you install the app, not the day you lose the phone.
Is cloud backup of TOTP seeds safe, or should I keep them device-bound?
Both are defensible; they defend against different things. A TOTP seed is a shared secret, so anyone who obtains it can generate valid codes indefinitely without touching your account. Device-bound storage (Aegis, or any app in offline mode) means no provider can ever be compelled or breached into handing it over, at the cost of making a lost phone potentially unrecoverable. End-to-end encrypted cloud backup (Proton Authenticator, Ente Auth, Authy) gives you recovery while keeping the provider unable to read the seed. Non-end-to-end cloud sync (Google Authenticator) gives you recovery while leaving the provider technically able to read it. For most people the honest ranking is: end-to-end encrypted cloud, then non-end-to-end cloud, then device-bound with a tested off-device backup, then device-bound with no backup, which is the one to avoid.
Which authenticator apps have moved to a subscription?
None of the six ranked here. All are free, and that is worth stating because the category has been drifting. The pattern to watch is adjacent rather than direct. 2FAS keeps its authenticator free but sells 2FAS Pass, a separate paid password and passkey manager. Ente Auth is free and cross-subsidised by Ente's paid encrypted photo product. Microsoft did not start charging, but it did remove password management from Authenticator between June and August 2025 and push it into Edge. The lesson for a free bundled app is not that it will start charging, it is that its feature set serves the vendor's product strategy and can shrink.
Which apps should I no longer use?
Raivo OTP, which was a well-regarded open-source iOS authenticator until it was sold to a company called Mobime in 2023. It has not been meaningfully updated since, its App Store listing points at the new owner's privacy policy, and privacy-focused communities now recommend against it. If you are still on Raivo, export and move to Ente Auth or Proton Authenticator. More generally, treat SMS as a fallback of last resort rather than a second factor: it is beaten by SIM swapping, and a carrier support agent is not an authentication control.
Can an attacker phish my TOTP code in real time?
Yes, and this is the ceiling on what any app on this page can do for you. A reverse-proxy phishing kit shows you a pixel-perfect copy of the real login page, relays your password and your six-digit code to the real site within its validity window, and captures the resulting session cookie. Your code was valid, your app was correct, and the attacker is now logged in as you. No authenticator app can prevent this, because the weakness is in the protocol: TOTP has no way to check which site is asking. The fix is WebAuthn, where the credential is bound to the origin and simply refuses to sign for a lookalike domain. That is why the recommendation for your most valuable accounts is a hardware key or a passkey, with TOTP kept only for services that will not accept one.
Will passkeys replace authenticator apps?
Eventually for most accounts, and already for the ones worth defending hardest, but not soon enough to stop choosing an authenticator app. Passkeys are phishing-resistant by design and remove the shared secret entirely, which is a genuine generational improvement over TOTP. The gap is coverage: thousands of services, including plenty of banks and government portals, still offer TOTP and nothing better. The realistic 2026 posture is to use passkeys or hardware keys everywhere they are offered, keep one well-backed-up authenticator app for the long tail that has not caught up, and make sure that app's backup is end-to-end encrypted and exportable.

About the author

is the founder and creator of LoginRadius, a customer identity platform he built and scaled to over a billion users. He is now the founder of GrackerAI, a GEO platform for B2B SaaS and cybersecurity teams, and has spent more than 15 years building identity and security products.

Related Comparisons