Best 2FA Authenticator Apps 2026: Proton vs Ente vs Google vs Microsoft
Six authenticator apps compared on the thing that actually decides the choice: whether your TOTP seeds are backed up, who holds the key to that backup, and what happens the day the phone is gone.
Answer first
Install Proton Authenticator. It is free on Android, iOS, Windows, macOS and Linux, it is open source, its backup and sync are end-to-end encrypted, and it imports from whatever you are using now. If you want copyleft licensing and a web client, use Ente Auth instead; it is equally free and equally end-to-end encrypted. If you are on Android and want nothing in anyone's cloud, use Aegis and send its encrypted backup somewhere off the phone today. If work runs on Microsoft 365, keep Microsoft Authenticator for the work account and put your personal seeds elsewhere.
The question everyone gets wrong
Buyers compare authenticator apps on interface and platform support. The decision is actually made on one question: where is the TOTP seed backed up, and who can read that backup?
A TOTP seed is a shared secret. Whoever holds it can generate valid codes for that account forever, from anywhere, without touching your account and without leaving a trace you would notice. So there are only four real designs, and every app is one of them:
- End-to-end encrypted cloud backup. The provider stores your seeds and cannot read them. Proton Authenticator, Ente Auth and Authy all work this way. This is the best default.
- Cloud backup that the provider can read. Google Authenticator's sync is encrypted in transit and at rest, but Google holds the keys. End-to-end encryption has been signalled since 2023 and has not shipped. Better than no backup, worse than option one.
- Device-bound, with a backup you manage. Aegis, or any app in offline mode. Nothing to compel, nothing to breach, and nothing to save you if you skip the backup step.
- Device-bound, with no backup. This is where most people actually are, and it is why "I lost my phone" is the most common 2FA disaster by a wide margin.
The failure mode is never exotic. It is a dropped phone, an unbacked-up vault, and a week of arguing with support desks about whether you are you.
What changed since this page was last written
- Proton Authenticator launched in 2025 and reset the baseline. A free, open-source, end-to-end encrypted, genuinely cross-platform authenticator did not exist before it.
- Microsoft removed password management from Authenticator between June and August 2025, consolidating it into Edge. Two-factor codes and passkeys were unaffected, but an app a lot of people treated as a light password vault stopped being one.
- Authy lost its desktop apps when Twilio discontinued them in 2024, and a 2024 breach of an unsecured Twilio API exposed 33 million Authy phone numbers. No seeds were taken, but the product is no longer the default it was.
- Raivo OTP is effectively abandoned, sold to a company called Mobime in 2023 with no meaningful updates since. It has been removed from this comparison.
If the accounts you are protecting are your email, your password manager or your domain registrar, stop reading here and go further than TOTP: a real-time phishing proxy can relay a valid six-digit code faster than you can read it. See the hardware security key comparison for what to use instead, and the password manager comparison for where synced passkeys live.
Quick Comparison
| App | Best for | Backup model | Cross-device sync | Open source | Platforms | Price |
|---|---|---|---|---|---|---|
| Proton Authenticator | Most people, on any mix of devices | End-to-end encrypted backup and sync, or local export | Yes, via an optional Proton account | Yes | Android, iOS, Windows, macOS, Linux, Apple Watch | Free |
| Ente Auth | Open-source stack with real cloud recovery | End-to-end encrypted cloud backup, externally audited cryptography | Yes, across mobile, desktop and web | Yes (AGPL-3.0) | Android, iOS, macOS, Windows, Linux, web | Free |
| Aegis Authenticator | Android users who want nothing in a cloud | Local encrypted vault, password-encrypted backup files you move yourself | No | Yes | Android only | Free |
| Microsoft Authenticator | Microsoft 365 and Entra ID environments | Cloud backup tied to a Microsoft account (and iCloud on iOS) | Restore to a new device, not true multi-device | No | Android, iOS | Free |
| Google Authenticator | The simplest thing that works, already installed | Google account sync, encrypted in transit and at rest but not end-to-end | Yes, via Google account | No | Android, iOS | Free |
| Authy | Existing users who have not moved yet | Encrypted cloud backup protected by a separate backup password | Yes, multiple mobile devices | No | Android, iOS (desktop apps discontinued in 2024) | Free |
Proton Authenticator
- Best for
- Most people, on any mix of devices
- Backup model
- End-to-end encrypted backup and sync, or local export
- Cross-device sync
- Yes, via an optional Proton account
- Open source
- Yes
- Platforms
- Android, iOS, Windows, macOS, Linux, Apple Watch
- Price
- Free
Ente Auth
- Best for
- Open-source stack with real cloud recovery
- Backup model
- End-to-end encrypted cloud backup, externally audited cryptography
- Cross-device sync
- Yes, across mobile, desktop and web
- Open source
- Yes (AGPL-3.0)
- Platforms
- Android, iOS, macOS, Windows, Linux, web
- Price
- Free
Aegis Authenticator
- Best for
- Android users who want nothing in a cloud
- Backup model
- Local encrypted vault, password-encrypted backup files you move yourself
- Cross-device sync
- No
- Open source
- Yes
- Platforms
- Android only
- Price
- Free
Microsoft Authenticator
- Best for
- Microsoft 365 and Entra ID environments
- Backup model
- Cloud backup tied to a Microsoft account (and iCloud on iOS)
- Cross-device sync
- Restore to a new device, not true multi-device
- Open source
- No
- Platforms
- Android, iOS
- Price
- Free
Google Authenticator
- Best for
- The simplest thing that works, already installed
- Backup model
- Google account sync, encrypted in transit and at rest but not end-to-end
- Cross-device sync
- Yes, via Google account
- Open source
- No
- Platforms
- Android, iOS
- Price
- Free
Authy
- Best for
- Existing users who have not moved yet
- Backup model
- Encrypted cloud backup protected by a separate backup password
- Cross-device sync
- Yes, multiple mobile devices
- Open source
- No
- Platforms
- Android, iOS (desktop apps discontinued in 2024)
- Price
- Free
Proton Authenticator
Best OverallBest for: Almost everyone: free, open source, end-to-end encrypted sync, and it runs on desktop as well as phone
“Launched in 2025 and now the default recommendation. It is free on every platform, open source, syncs with end-to-end encryption, and does not require a Proton account unless you want sync. It also imports directly from Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth and LastPass, which removes the main reason people stay on an app they have outgrown.”
Pros
- End-to-end encrypted backup and sync, so Proton cannot read your TOTP seeds even though it stores them, which is the exact property Google Authenticator's sync does not have
- Runs on Android, iOS, Windows, macOS, Linux and Apple Watch, so the codes are on the laptop when the phone is charging in another room
- Works with no account at all if you prefer purely local storage, and supports direct export as well as import, so you are never locked in
Cons
- New enough that its long-term track record is short, and it inherits whatever view you hold of Proton as a company
- Sync requires a Proton account, which is another credential to protect, and that account becomes a high-value target once it holds your second factors
Why end-to-end encryption on the backup is the whole argument
A TOTP seed is a shared secret. Anyone holding it can generate valid codes for your account forever, silently, from anywhere. That makes the question of who can read your backup more important than any feature on a comparison table. Proton Authenticator encrypts backups and sync end-to-end, meaning the keys stay on your devices. Google Authenticator's sync is encrypted in transit and at rest but Google holds the keys, so a compelled disclosure or an internal compromise reaches your seeds. Both are better than no backup. Only one keeps the seed out of the provider's hands.
Desktop support and why it matters
Most authenticator apps are phone-only, which quietly makes your phone a single point of failure for every account you own. Proton Authenticator ships desktop apps for Windows, macOS and Linux alongside the mobile apps. That is not just convenience: a second device with the same seeds is the cheapest form of redundancy available, and it is the answer to the most common 2FA disaster, which is not a hack but a dropped phone.
Migration in and out
The app imports from Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth and LastPass, and exports in a form you can take elsewhere. Treat the export as part of setup, not as a feature you will use later. Generate one, encrypt it, and store it where you store your recovery codes, because the export is what survives a lost phone, a forgotten account password and a vendor you have decided you no longer trust.
Free on all platforms, no ads, no tracking. A Proton account is optional and only needed for sync.
Ente Auth
Best Open SourceBest for: Open-source cloud recovery, on every platform including the web
“Free, AGPL-3.0 licensed, end-to-end encrypted cloud backup, and it runs on mobile, desktop and the web. Ente states its cryptography has been externally audited. If your objection to Proton is that you want the source under a copyleft licence and the project independent of a large privacy brand, this is the pick.”
Pros
- End-to-end encrypted cloud backups with externally audited cryptography, per the vendor, so recovery does not require trusting the operator with the seeds
- Fully open source under AGPL-3.0 with the code and the repository public, and distributed through F-Droid as well as the app stores
- Offline mode works with no account and no backup at all, so the same app covers the local-only user and the sync user
Cons
- The vendor states the cryptography was externally audited but does not link the audit report on the product page, so the claim cannot be checked from the page itself
- The free authenticator is funded by a paid photo product from the same company, which makes its long-term economics dependent on a business you may never use
Web access as a recovery path
Ente is the only app here with a browser client. That is a meaningful difference on the worst day: phone gone, laptop at home, and you need into your email from a borrowed machine. It is also an added attack surface, because a browser client means your vault can be reached from any device that can reach the internet. Both statements are true. Whether the trade is worth it depends on whether your realistic failure mode is losing a phone or being targeted.
What AGPL-3.0 actually changes
Copyleft licensing means a company that forks Ente and runs it as a service has to publish its changes. Compared with a permissive licence, that makes a closed, diverged derivative much harder to build. For an app that holds the keys to every other account you own, the practical value is continuity: if the company stops, the code and the protocol stay usable and forkable, and the encrypted backups stay decryptable by software you can obtain.
Offline mode
Ente Auth runs with no account and no cloud at all if you choose. That makes it the one app on this page that covers both ends of the backup argument with the same binary. Cloud recovery for people who will lose a phone before they are targeted, and pure local storage for people whose threat model runs the other way. Aegis does local-only better, but it only does Android.
Free. The company states the authenticator is free and will remain free.
Aegis Authenticator
Best for PrivacyBest for: Android users who want their TOTP seeds to never leave the device
“The reference implementation of local-first 2FA on Android. Free, open source, offline, with an encrypted vault, optional biometric unlock and password-encrypted backup files you move yourself. There is no sync and no cloud, which is either the point or a dealbreaker, depending on who is holding the phone.”
Pros
- Works completely offline with no account, no server and no telemetry, so there is no provider that can be breached, compelled or shut down
- Encrypted vault with optional biometric unlock, and automatic backups written to a location you choose and encrypted with a password you choose
- Broad import and export support across other 2FA apps, so adopting it or leaving it is a five-minute job
Cons
- Android only, with no iOS version and no desktop client, so a mixed-device household needs a second app
- No sync of any kind, which means backup discipline is entirely yours and there is no safety net if you skip it
Local-first is a threat model, not a feature
Choosing Aegis says you think the more likely bad outcome is a provider compromise, a legal demand or an account takeover of your cloud account, rather than you losing a phone. For journalists, activists, people in hostile jurisdictions and anyone who has already been targeted, that is a defensible reading. For most people it is not, and the honest advice is that a cloud backup you actually have beats a local backup you meant to make.
Making the backup real
Configure the automatic backup on day one, send it somewhere that is not the phone, and pick a password you have not used elsewhere and have stored in your password manager. Then restore it once, onto a second device or a fresh install, before you need to. An untested backup is a belief, not a control. This is the single highest-value thing to do with Aegis and the most commonly skipped.
When to pair it with something else
If you use an iPhone as well as an Android phone, or a laptop, Aegis cannot cover you alone. The clean pairing is Aegis for high-value accounts held only on the Android device, plus Proton Authenticator or Ente Auth for everything else. Splitting deliberately by account value is different from having tokens scattered across three apps because you kept switching.
Free, open source, available on Google Play and F-Droid.
Microsoft Authenticator
Best for EnterpriseBest for: Microsoft 365 and Entra ID accounts, where it is the app the tenant expects
“If work runs on Microsoft 365, this is already the app your administrator has configured, and it does the Microsoft-specific things no other app can: number-matching push approval, passwordless sign-in and passkeys for the work account. As a general-purpose TOTP app it is now weaker than it was, because Microsoft removed password management from it in 2025.”
Pros
- Number matching on push approvals defeats MFA fatigue attacks, where an attacker spams approval prompts until someone taps yes to make them stop
- Supports passwordless sign-in and passkeys for Microsoft work and personal accounts, not just TOTP codes
- Deep Entra ID integration: conditional access, device registration and administrator-controlled enrolment work without third-party stitching
Cons
- Microsoft removed password storage and autofill between June and August 2025, pushing those functions into Microsoft Edge, so an app people used as a light password manager no longer is one
- Cloud backup is tied to a Microsoft account (and iCloud on iOS), restores to a new device rather than running on several at once, and is not open source
Number matching and MFA fatigue
A push prompt that asks only yes or no can be defeated by volume: send enough prompts at three in the morning and someone taps approve. Number matching fixes this by displaying a code on the login screen that must be typed into the app, so approval requires the person to be looking at the real sign-in attempt. This is the single most valuable thing Microsoft Authenticator does that a pure TOTP app cannot, and it only applies to accounts that use Microsoft push, not to the TOTP codes it also stores.
Where it is the right answer and where it is not
Use it for the Microsoft work account because the tenant configuration expects it and because conditional access, device registration and passwordless sign-in all depend on it. Do not make it the home for the other thirty TOTP seeds in your life. Those belong somewhere with end-to-end encrypted, portable, cross-platform backup, because the recovery story for a Microsoft Authenticator restore is tied to a Microsoft account you may not control forever.
The 2025 password removal, in order
June 2025: no new passwords could be saved. July 2025: autofill stopped working. August 2025: saved passwords became inaccessible in the app. Microsoft's guidance was to export and move to Edge or another password manager. If you still have not migrated, the export window is closed and the passwords live in whichever Microsoft account they synced to.
Google Authenticator
Best Free OptionBest for: The default that is good enough, especially if the alternative is no 2FA at all
“It is simple, it is free, it is already on hundreds of millions of phones, and since 2023 it backs up to your Google account so losing a phone is no longer catastrophic. The one thing to understand before choosing it: that backup is not end-to-end encrypted, so Google can technically read your TOTP seeds.”
Pros
- Google account sync means a lost phone is a recoverable event rather than a rebuild of every account, which was the app's defining weakness before 2023
- Minimal interface with essentially nothing to configure, which matters when you are setting up 2FA for someone who will not maintain it
- Universally recognised, so service setup instructions and support articles almost always assume it
Cons
- Sync is encrypted in transit and at rest but not end-to-end, so Google holds the decryption keys to your second factors; end-to-end encryption has been signalled since 2023 but has not shipped
- Not open source, Android and iOS only, and your entire second-factor set becomes an asset of a single Google account
The sync trade-off, stated plainly
Before 2023, losing your phone meant losing every token. Now the seeds sync to your Google account, which solved the common disaster and introduced an uncommon one. Google encrypts the data in transit and at rest but holds the keys, so the seeds are reachable by a compelled disclosure, an internal compromise or an attacker who takes over the Google account. For most people, who are far more likely to drop a phone than to be targeted, the trade is still worth it. For anyone whose Google account is itself a target, it is not.
Simplicity is a real feature
The reason to still recommend this app is the person who will otherwise use SMS or nothing. It has no accounts to create beyond the Google account already on the phone, no backup password to lose, no vault to configure, and every service's setup page assumes it. Getting a non-technical family member from SMS codes to Google Authenticator is a larger security improvement than getting an enthusiast from Authy to Proton.
Concentrating risk in one account
If Google Authenticator holds your seeds and Gmail is your recovery address, your Google account is a single control point for your entire digital life. Defend it accordingly: register two hardware security keys on it, enrol in Advanced Protection if you can live with the restrictions, and keep the seeds for your most valuable non-Google account (bank, exchange, domain registrar) in a different app entirely.
Authy
Honorable MentionBest for: People already using it, who need a reason to decide whether to move
“Authy still exists, is still free, and still does encrypted cloud backup and multi-device sync on mobile. It is ranked last because Twilio discontinued the desktop apps in 2024 and because a 2024 breach of an unsecured Twilio API exposed 33 million Authy phone numbers. Neither event exposed TOTP seeds, but both are reasons the app is no longer the default it once was.”
Pros
- Encrypted cloud backup protected by a backup password that Twilio does not hold, so the seeds themselves are not readable by the provider
- Multi-device sync across several phones and tablets, with the ability to revoke a device, which is still ahead of Google and Microsoft on that one dimension
- Free, mature, and widely supported in service setup documentation
Cons
- Desktop applications were discontinued in 2024 and users were forcibly logged out, removing the redundancy that made Authy attractive in the first place
- The account is bound to a phone number, which makes SIM swapping part of your threat model whether you want it to be or not
What the backup password actually protects
Authy's backup encryption uses a password you set and Twilio does not store, which means Twilio genuinely cannot read your seeds. That is a better design than Google Authenticator's sync. It also means that if you forget the backup password, nobody can help you, and the seeds in the cloud are unrecoverable. If you are staying on Authy, confirm today that your backup password is in your password manager, because the failure mode is total and silent.
Migrating off
Authy does not offer a bulk export, which is the practical friction keeping people on it. The migration is manual: for each account, go to its security settings, disable the existing authenticator, and re-enrol using your new app's QR scanner. Do the high-value accounts first (email, password manager, domain registrar, financial), keep Authy installed until each one is confirmed working in the new app, and print fresh recovery codes as you go.
Free
Which One Should You Pick?
| Use Case | Our Recommendation |
|---|---|
| Setting up 2FA for the first time, or for someone who will not maintain it | Google Authenticator, with sync enabled. It is already there, there is nothing to configure, and every service's instructions assume it. The concentration risk is real but secondary to the fact that it will actually get used. Then put two hardware security keys on the Google account itself. |
| One person, several devices, wants the seeds backed up but not readable by the provider | Proton Authenticator. Free, end-to-end encrypted sync, and it runs on Windows, macOS and Linux as well as both phone platforms, so the laptop is a working second copy rather than a hope. |
| Nothing in anyone else's cloud, ever | Aegis on Android, or Ente Auth in offline mode on iOS and desktop. In both cases the work is the backup: send the encrypted export somewhere that is not the same device, and test a restore before you need one. |
| Work runs on Microsoft 365 or Entra ID | Microsoft Authenticator for the work account, because number matching, conditional access and passwordless sign-in depend on it. Keep your personal TOTP seeds in Proton Authenticator or Ente Auth, because Microsoft's recovery story is tied to a Microsoft account your employer may control. |
| Currently on Authy and wondering whether to move | Move, but calmly. Authy still works and your seeds are encrypted with a password Twilio does not hold. The reasons to leave are the 2024 desktop shutdown and the phone-number binding. There is no bulk export, so migrate account by account starting with email, password manager, registrar and finance, and keep Authy installed until each one is confirmed. |
| High-value accounts: primary email, password manager, domain registrar, exchange | Stop at TOTP. These accounts should be on hardware security keys or device-bound passkeys, because a TOTP code can be phished in real time by a proxy page and a WebAuthn credential cannot. Keep a TOTP enrolment only where the service will not accept a key. |
How we evaluated
Every capability, price and platform claim on this page was checked against the vendor's own site or documentation on 18 September 2026. No figure is carried across from another comparison.
Apps were judged on five things, in this order:
- Backup model. Whether the TOTP seeds are backed up at all, and whether the provider can read the backup. This dominates everything else, because a seed is a permanent shared secret and because a lost phone is the most common thing that actually goes wrong.
- Recovery path. What concretely happens on a new device: restore from an encrypted cloud copy, restore from a file you kept, or re-enrol every account by hand.
- Portability. Whether the app imports from others and exports to something you can keep. An app that cannot export is a trap regardless of how good it is today.
- Platform coverage. Whether a second device can hold the same seeds, because redundancy is cheaper than recovery.
- Vendor trajectory. Ownership changes, discontinued components, removed features and abandoned projects. This is what moved Authy down and removed Raivo entirely.
What was checked, and where
- Proton Authenticator: the product page for free pricing on all platforms, platform list including Apple Watch, optional-account model, end-to-end encrypted sync and backup, open-source status, and the import list (Google Authenticator, 2FAS, Aegis, Bitwarden, Ente Auth, LastPass).
- Ente Auth: the product page for free pricing, AGPL-3.0 licensing, end-to-end encrypted cloud backups, the externally audited cryptography claim, platform list including web, and offline mode.
- Aegis: the project site for Android-only distribution via Google Play and F-Droid, the encrypted vault with optional biometric unlock, password-encrypted automatic backups, offline operation, and import/export coverage.
- Microsoft Authenticator: Microsoft's app page and its published June-to-August 2025 timeline for withdrawing password storage and autofill.
- Google Authenticator: Google account sync behaviour and the still-outstanding end-to-end encryption commitment first made in 2023.
- Authy: the Authy site for current free pricing, cloud backup and multi-device support, alongside the 2024 desktop discontinuation and the 2024 Twilio API incident that exposed 33 million phone numbers.
What we deliberately did not do
No hands-on testing claims. These apps were not run through a bench test. The assessment rests on vendor documentation, published source, licensing, and the public record of each product's changes, and each entry says which of those it rests on. Where a vendor asserts something no third party has confirmed, such as Ente's external cryptography audit, the entry says the vendor asserts it.
No ranking on interface. Every app here generates six digits every thirty seconds. Differences in how attractive that looks are not worth a place in the ordering.
2FAS is a reasonable free, open-source authenticator that did not make the six, mainly because Proton Authenticator and Ente Auth cover the same ground with stronger cross-platform reach. Worth knowing: the 2FAS authenticator is free, while 2FAS Pass, the company's separate password and passkey manager, is a paid product.
Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.
Last verified: 18 September 2026. Vendor product pages, pricing, platform lists, backup and encryption claims, and the public record of discontinuations and ownership changes were all rechecked on this date.
Frequently Asked Questions
What actually happens if I lose my phone?
Is cloud backup of TOTP seeds safe, or should I keep them device-bound?
Which authenticator apps have moved to a subscription?
Which apps should I no longer use?
Can an attacker phish my TOTP code in real time?
Will passkeys replace authenticator apps?
Related Comparisons
Endpoint Security
Best Antivirus 2026: 6 Compared Against AV-Comparatives and AV-TEST
6 tools compared
Network Security
Top 5 DNS Security Solutions 2026: Cloudflare vs Quad9 vs the Rest
5 tools compared
Authentication Hardware
Best Hardware Security Keys 2026: YubiKey vs Titan vs Feitian vs Solo 2
6 tools compared
Financial Security
Top 5 Personal Finance Security Tools of 2026: Protecting Your Money and Identity
5 tools compared