We're on Product Hunt today! Leave a comment

Authenticator app without a phone: how to get 2FA codes on your computer

Yes. An authenticator app does not need a phone. A 2FA code is computed from a secret key the site gives you at setup and the current time — the open TOTP standard, RFC 6238 — so any device that holds the key makes the same six digits, a computer as well as a phone. On a computer you can use a browser extension (2FA Authenticator — ours — or Authenticator by authenticator.cc), a desktop app (Proton Authenticator, Ente Auth, KeePassXC), a password manager that makes codes (Bitwarden Premium, 1Password), or a hardware key such as a YubiKey with the Yubico Authenticator app, which keeps the secrets on the key itself.

Setup needs no phone either: the site shows its QR code on your screen, several of these read it straight from there, and sites that show a QR code almost always offer the same secret as text you can paste too. What a computer cannot replace is a service that sends codes only by text message, or confirms sign-ins in its own phone app — those are listed below.

Ways to get 2FA codes without a phone

Options that generate codes on a Windows, Mac or Linux computer, as each vendor documented them on October 9, 2026. "Reads the QR code from the screen" means the vendor describes capturing the setup QR code from your display — no phone and no camera.

Ways to get 2FA codes without a phone
OptionWhat it isWhere the secret keys are keptPriceAccount neededReads the QR code from the screen
2FA AuthenticatorOursChrome extensionIn the browserFree; new installations may have an account limit, which Pro removesNoYes
Authenticator (authenticator.cc)Chrome extensionIn the browserFreeNoYes
Proton AuthenticatorDesktop app (also on phones)In the app on your deviceFreeOptionalNot documented
Ente AuthDesktop app (also on phones)In the app on your deviceFreeOptionalNot documented
KeePassXCPassword manager, desktop appIn your KeePassXC database fileFreeNoNot documented
BitwardenPassword managerIn the vault, next to your passwordsPremium, ⁨$19.80⁩/yearYesYes
1PasswordPassword managerIn the vault, next to your passwordsSubscription (no free plan)YesYes
YubiKeyHardware key + Yubico Authenticator appOn the key; Yubico says they cannot be extractedYou buy the keyNoYes

"Not documented" means we found no vendor page describing it, not that it cannot be done. Without a QR scan you add the account from the text key under the QR code; authenticator.cc's quickstart, Ente's FAQ, KeePassXC's user guide and Yubico's guide all describe that. Bitwarden stores keys on the free plan but generates codes only with Premium; 1Password offers a trial but no free plan. We make 2FA Authenticator.

Which one fits

You sign in to most things in Chrome. A browser extension keeps the codes where you type them. 2FA Authenticator inserts the code into the field with a right-click or Ctrl+Shift+Y and scans a setup QR code straight off the page; a new installation may have a limit on free accounts, which Pro removes. Authenticator (authenticator.cc) is free, has far more users and supports more code types, though its Chrome Web Store build was last updated in August 2024.

You want an app outside the browser. Proton Authenticator and Ente Auth are free and open source, run on Windows, macOS and Linux as well as phones, and need no account unless you want sync — so a phone can be a second copy later, or never. KeePassXC keeps codes in its encrypted database file on your computer and can fill them in the browser through its extension.

You already pay for a password manager. Bitwarden (Premium, $19.80/year) and 1Password generate codes and fill them right after the password, and both document reading a setup QR code off the screen. The catch is in the section on keeping codes and passwords together, below.

You want the secrets off the computer entirely. A YubiKey with the Yubico Authenticator app stores each account's secret in the key's secure element, where Yubico says it cannot be extracted. The app runs on Windows, macOS and Linux, scans the setup QR code from the screen, and shows the codes while the key is plugged in. A YubiKey 5 holds up to 64 accounts on firmware 5.7 and later, 32 on older firmware. You buy the key — and because the secrets cannot be copied off it, Yubico recommends registering a second key as a backup.

When you still need a phone

A computer can replace an authenticator app. It cannot replace a phone where the service itself has made the phone the second factor:

Codes by text message or email only. Some services offer no authenticator-app option at all: the code arrives by SMS or email, and there is nothing for an authenticator to generate. Apple Account is a well-known case — Apple's help says the code is shown on your trusted Apple devices or sent to your trusted phone number, and describes no third-party authenticator app.

The service's own app. Some banks confirm sign-ins in their own app instead of standard codes; Truist, for example, uses its Truist Authenticator mobile app. If your employer requires approval in a particular app, that is its choice too, and another app's codes will not be accepted.

Setup only in the phone app. TikTok's help describes turning on authenticator-app 2-step verification only in the TikTok mobile app, and it asks for a second method such as a phone number or email. Once it is set up, the codes can live anywhere — our TikTok guide shows how to get the QR code from the phone into the extension.

Codes that are on a phone already. If your accounts are in Google Authenticator today, you need the phone once to export them — see importing from Google Authenticator — or you set each account up again from the computer.

The trade-off: codes on the same computer as your passwords

Two-factor authentication is meant to need two different things. If the computer that remembers your passwords also makes your codes, someone who takes over that computer — malware that copies browser data, or a person at your unlocked desk — may get both. KeePassXC's own guide says it bluntly: keeping TOTP codes in the same database as the password eliminates the advantages of two-factor authentication, and it suggests a separate database you unlock only when needed.

What codes on a computer still stop is what most account takeovers are: a password leaked from another site, guessed, or typed into a phishing page. The attacker has the password but not your computer, so there is no code. A phone adds protection mainly against someone who already controls your computer.

1. Lock the codes. Turn on password protection in 2FA Authenticator: the codes are then encrypted on your device, backups included, and cannot be read without your password. Desktop apps and password managers have their own locks — use them.

2. Keep codes apart from passwords. Codes in a separate app or extension, rather than in the vault that holds the passwords, mean one stolen master password is not enough.

3. Keep a backup off the computer. 2FA Authenticator takes an automatic copy once a day and keeps the last seven, but those copies live inside the extension and go with it if it is removed. Export a password-protected file to a USB stick or another place you control — how to back up.

4. Save every site's recovery codes. They get you back in if the computer is lost or dies, with no authenticator at all. Print them or store them away from this computer.

5. Add a phone later if you get one. Scanning the same QR code with a phone app during setup gives you a second device showing the same codes — a backup, not a requirement.

How to set up 2FA on any site without a phone

1. Install an authenticator on the computer — ours is 2FA Authenticator.

2. Sign in to the site and open its security settings. Turn on two-factor authentication (sometimes called 2-step verification), and if it offers text messages first, choose authenticator app. Our setup guides show where this is for 108 services.

3. The site shows a QR code. In 2FA Authenticator: Add Account → QR Code → "Scan QR from screen". If it will not scan, use the site's "Can't scan the QR code?" or "Enter manually" link and paste the text key — where to find the secret key.

4. Type the six-digit code from the extension back into the site. Until you do, 2FA is not on.

5. Save the recovery codes the site shows next, then back up the authenticator itself.

If the site rejects the code, the usual reason is that it made a new QR code after you scanned the first one — start the setup again and scan the code that is on the screen now. More causes in why codes don't work.

Frequently asked questions

Can I use an authenticator app without a phone?
Yes. Authenticator codes (TOTP) are computed from a secret key and the current time, so a computer makes them just as a phone does. Use a browser extension, a desktop app such as Proton Authenticator or Ente Auth, a password manager with a built-in authenticator, or a hardware key such as a YubiKey.
Is there an authenticator app for PC?
Yes, and several are free: Proton Authenticator, Ente Auth and KeePassXC run on Windows, macOS and Linux, and browser extensions such as 2FA Authenticator and Authenticator (authenticator.cc) work in Chrome on any of them. Google Authenticator and Microsoft Authenticator have no PC version — see Microsoft Authenticator alternatives.
How do I scan a 2FA QR code without a phone?
The QR code is on your computer screen, so an app on the computer can read it there: 2FA Authenticator, Authenticator (authenticator.cc), Bitwarden, 1Password and Yubico Authenticator all document scanning it from the screen. Or skip the QR code: the site's "Can't scan?" link shows the same secret as text.
Will codes on my computer work for an account I set up on my phone?
Only if the computer has the same secret key. Export the accounts from the phone app if it allows that, or turn 2FA off and on again on the site and scan the new QR code from the computer — after which the phone's old entry for that account stops working.
What happens if I lose the computer?
You get back in with a backup: a file exported from the authenticator, or the recovery codes each site gave you at setup. Without either, you go through each site's account recovery. That is why the backup should not live only on the same computer.
Do I need a phone number for 2FA?
Not for authenticator-app 2FA: the code comes from the app, not from a text message. Some services still ask for a phone number or an email address as a second method or for account recovery.

2FA codes on your computer, no phone needed

2FA Authenticator scans the setup QR code from your screen and keeps the codes in Chrome. Free to use, open source, no account — 200,000 people use it.

Add 2FA Authenticator to Chrome — free

Sources

Checked October 9, 2026. We make one of the products compared here; if a line about another one is wrong or out of date, tell us and we will fix it.