Yes. An authenticator app does not need a phone. A 2FA code is computed from a secret key the site gives you at setup and the current time — the open TOTP standard, RFC 6238 — so any device that holds the key makes the same six digits, a computer as well as a phone. On a computer you can use a browser extension (2FA Authenticator — ours — or Authenticator by authenticator.cc), a desktop app (Proton Authenticator, Ente Auth, KeePassXC), a password manager that makes codes (Bitwarden Premium, 1Password), or a hardware key such as a YubiKey with the Yubico Authenticator app, which keeps the secrets on the key itself.
Setup needs no phone either: the site shows its QR code on your screen, several of these read it straight from there, and sites that show a QR code almost always offer the same secret as text you can paste too. What a computer cannot replace is a service that sends codes only by text message, or confirms sign-ins in its own phone app — those are listed below.
Ways to get 2FA codes without a phone
Options that generate codes on a Windows, Mac or Linux computer, as each vendor documented them on October 9, 2026. "Reads the QR code from the screen" means the vendor describes capturing the setup QR code from your display — no phone and no camera.
| Option | What it is | Where the secret keys are kept | Price | Account needed | Reads the QR code from the screen |
|---|---|---|---|---|---|
| 2FA AuthenticatorOurs | Chrome extension | In the browser | Free; new installations may have an account limit, which Pro removes | No | Yes |
| Authenticator (authenticator.cc) | Chrome extension | In the browser | Free | No | Yes |
| Proton Authenticator | Desktop app (also on phones) | In the app on your device | Free | Optional | Not documented |
| Ente Auth | Desktop app (also on phones) | In the app on your device | Free | Optional | Not documented |
| KeePassXC | Password manager, desktop app | In your KeePassXC database file | Free | No | Not documented |
| Bitwarden | Password manager | In the vault, next to your passwords | Premium, $19.80/year | Yes | Yes |
| 1Password | Password manager | In the vault, next to your passwords | Subscription (no free plan) | Yes | Yes |
| YubiKey | Hardware key + Yubico Authenticator app | On the key; Yubico says they cannot be extracted | You buy the key | No | Yes |
"Not documented" means we found no vendor page describing it, not that it cannot be done. Without a QR scan you add the account from the text key under the QR code; authenticator.cc's quickstart, Ente's FAQ, KeePassXC's user guide and Yubico's guide all describe that. Bitwarden stores keys on the free plan but generates codes only with Premium; 1Password offers a trial but no free plan. We make 2FA Authenticator.
Which one fits
You sign in to most things in Chrome. A browser extension keeps the codes where you type them. 2FA Authenticator inserts the code into the field with a right-click or Ctrl+Shift+Y and scans a setup QR code straight off the page; a new installation may have a limit on free accounts, which Pro removes. Authenticator (authenticator.cc) is free, has far more users and supports more code types, though its Chrome Web Store build was last updated in August 2024.
You want an app outside the browser. Proton Authenticator and Ente Auth are free and open source, run on Windows, macOS and Linux as well as phones, and need no account unless you want sync — so a phone can be a second copy later, or never. KeePassXC keeps codes in its encrypted database file on your computer and can fill them in the browser through its extension.
You already pay for a password manager. Bitwarden (Premium, $19.80/year) and 1Password generate codes and fill them right after the password, and both document reading a setup QR code off the screen. The catch is in the section on keeping codes and passwords together, below.
You want the secrets off the computer entirely. A YubiKey with the Yubico Authenticator app stores each account's secret in the key's secure element, where Yubico says it cannot be extracted. The app runs on Windows, macOS and Linux, scans the setup QR code from the screen, and shows the codes while the key is plugged in. A YubiKey 5 holds up to 64 accounts on firmware 5.7 and later, 32 on older firmware. You buy the key — and because the secrets cannot be copied off it, Yubico recommends registering a second key as a backup.
When you still need a phone
A computer can replace an authenticator app. It cannot replace a phone where the service itself has made the phone the second factor:
Codes by text message or email only. Some services offer no authenticator-app option at all: the code arrives by SMS or email, and there is nothing for an authenticator to generate. Apple Account is a well-known case — Apple's help says the code is shown on your trusted Apple devices or sent to your trusted phone number, and describes no third-party authenticator app.
The service's own app. Some banks confirm sign-ins in their own app instead of standard codes; Truist, for example, uses its Truist Authenticator mobile app. If your employer requires approval in a particular app, that is its choice too, and another app's codes will not be accepted.
Setup only in the phone app. TikTok's help describes turning on authenticator-app 2-step verification only in the TikTok mobile app, and it asks for a second method such as a phone number or email. Once it is set up, the codes can live anywhere — our TikTok guide shows how to get the QR code from the phone into the extension.
Codes that are on a phone already. If your accounts are in Google Authenticator today, you need the phone once to export them — see importing from Google Authenticator — or you set each account up again from the computer.
The trade-off: codes on the same computer as your passwords
Two-factor authentication is meant to need two different things. If the computer that remembers your passwords also makes your codes, someone who takes over that computer — malware that copies browser data, or a person at your unlocked desk — may get both. KeePassXC's own guide says it bluntly: keeping TOTP codes in the same database as the password eliminates the advantages of two-factor authentication, and it suggests a separate database you unlock only when needed.
What codes on a computer still stop is what most account takeovers are: a password leaked from another site, guessed, or typed into a phishing page. The attacker has the password but not your computer, so there is no code. A phone adds protection mainly against someone who already controls your computer.
1. Lock the codes. Turn on password protection in 2FA Authenticator: the codes are then encrypted on your device, backups included, and cannot be read without your password. Desktop apps and password managers have their own locks — use them.
2. Keep codes apart from passwords. Codes in a separate app or extension, rather than in the vault that holds the passwords, mean one stolen master password is not enough.
3. Keep a backup off the computer. 2FA Authenticator takes an automatic copy once a day and keeps the last seven, but those copies live inside the extension and go with it if it is removed. Export a password-protected file to a USB stick or another place you control — how to back up.
4. Save every site's recovery codes. They get you back in if the computer is lost or dies, with no authenticator at all. Print them or store them away from this computer.
5. Add a phone later if you get one. Scanning the same QR code with a phone app during setup gives you a second device showing the same codes — a backup, not a requirement.
How to set up 2FA on any site without a phone
1. Install an authenticator on the computer — ours is 2FA Authenticator.
2. Sign in to the site and open its security settings. Turn on two-factor authentication (sometimes called 2-step verification), and if it offers text messages first, choose authenticator app. Our setup guides show where this is for 108 services.
3. The site shows a QR code. In 2FA Authenticator: Add Account → QR Code → "Scan QR from screen". If it will not scan, use the site's "Can't scan the QR code?" or "Enter manually" link and paste the text key — where to find the secret key.
4. Type the six-digit code from the extension back into the site. Until you do, 2FA is not on.
5. Save the recovery codes the site shows next, then back up the authenticator itself.
If the site rejects the code, the usual reason is that it made a new QR code after you scanned the first one — start the setup again and scan the code that is on the screen now. More causes in why codes don't work.
Frequently asked questions
- Can I use an authenticator app without a phone?
- Yes. Authenticator codes (TOTP) are computed from a secret key and the current time, so a computer makes them just as a phone does. Use a browser extension, a desktop app such as Proton Authenticator or Ente Auth, a password manager with a built-in authenticator, or a hardware key such as a YubiKey.
- Is there an authenticator app for PC?
- Yes, and several are free: Proton Authenticator, Ente Auth and KeePassXC run on Windows, macOS and Linux, and browser extensions such as 2FA Authenticator and Authenticator (authenticator.cc) work in Chrome on any of them. Google Authenticator and Microsoft Authenticator have no PC version — see Microsoft Authenticator alternatives.
- How do I scan a 2FA QR code without a phone?
- The QR code is on your computer screen, so an app on the computer can read it there: 2FA Authenticator, Authenticator (authenticator.cc), Bitwarden, 1Password and Yubico Authenticator all document scanning it from the screen. Or skip the QR code: the site's "Can't scan?" link shows the same secret as text.
- Will codes on my computer work for an account I set up on my phone?
- Only if the computer has the same secret key. Export the accounts from the phone app if it allows that, or turn 2FA off and on again on the site and scan the new QR code from the computer — after which the phone's old entry for that account stops working.
- What happens if I lose the computer?
- You get back in with a backup: a file exported from the authenticator, or the recovery codes each site gave you at setup. Without either, you go through each site's account recovery. That is why the backup should not live only on the same computer.
- Do I need a phone number for 2FA?
- Not for authenticator-app 2FA: the code comes from the app, not from a text message. Some services still ask for a phone number or an email address as a second method or for account recovery.
2FA codes on your computer, no phone needed
2FA Authenticator scans the setup QR code from your screen and keeps the codes in Chrome. Free to use, open source, no account — 200,000 people use it.
Add 2FA Authenticator to Chrome — freeSources
Checked October 9, 2026. We make one of the products compared here; if a line about another one is wrong or out of date, tell us and we will fix it.
- RFC 6238 — TOTP: Time-Based One-Time Password Algorithm
- 2FA Authenticator — Chrome Web Store
- 2FA Authenticator — source code (MIT)
- Authenticator (authenticator.cc) — Chrome Web Store
- Add Your First Account | Authenticator (authenticator.cc)
- Proton Authenticator
- Ente Auth
- Ente Auth — FAQ
- KeePassXC Password Manager
- KeePassXC User Guide — Adding TOTP to an Entry
- Bitwarden — Integrated authenticator (TOTP generation needs Premium)
- Bitwarden — Pricing
- 1Password — Use 1Password as an authenticator
- 1Password — Pricing
- Yubico Authenticator App for Desktop and Mobile
- Yubico Authenticator User Guide — Accounts: OATH
- YubiKey Technical Manual — OATH Specifics
- Two-factor authentication for Apple Account - Apple Support
- Authenticator app | Truist Bank