We're on Product Hunt today! Leave a comment

How to move 2FA to a new phone, and what to do if you lost the old one

To move 2FA to a new phone, use your authenticator app's own transfer while you still have the old phone: Google Authenticator shows an export QR code (Menu → Transfer codes) or syncs through your Google Account, Microsoft Authenticator restores from its cloud backup onto a phone of the same kind, Authy adds the new phone to your Authy account, and 2FAS restores from its Google Drive or iCloud sync. Sign in to a few accounts with codes from the new phone before you erase the old one.

If the phone is already lost and nothing was synced or backed up, nobody can recover the codes — not the app's maker and not us. You get back into each account through the service itself: its recovery codes, another sign-in method, or its account recovery, which can ask for ID and take days. To make the next lost phone a non-event, keep a second copy of your codes somewhere other than the phone — for example in 2FA Authenticator, our Chrome extension (free to use; new installations may have an account limit, which Pro removes) — and keep recovery codes offline.

How each authenticator app moves to a new phone

As each vendor documents it on October 9, 2026. "If it was on" is the part that matters: a backup switched on after the phone is gone does not exist.

How each authenticator app moves to a new phone
AppHow the codes moveNeeds the old phoneBackup if the old phone is gone
Google AuthenticatorExport QR code (Transfer codes), or Google Account syncYes for the export QR code; no with Google Account syncGoogle Account sync, if it was on
Microsoft AuthenticatorCloud backup and recovery; work or school accounts need signing in againNo, if backup or sync was already onCloud backup, if it was on — restores only to the same kind of phone
AuthyAdd the new phone to your Authy account; approve it from the old phone or by SMS or callNo, if backup or sync was already onEncrypted backups, if they were on — needs the backup password
2FAS AuthCloud sync between phones of the same kind; a password-protected file between Android and iPhoneNo, if backup or sync was already onGoogle Drive (Android) or iCloud (iPhone) sync, if it was on, or an exported file
2FA AuthenticatorOursExport a file and import it; Chrome sync between computersNo — it runs in Chrome on a computer, not on the phoneYes — the codes stay in Chrome on your computer, with daily automatic copies and export files

Authy has no export to other apps, and its desktop apps ended on March 19, 2024, so a computer can no longer be a spare Authy device. 2FA Authenticator is ours, and it is not a phone app: it runs in Chrome on a computer, which is why changing or losing a phone does not touch it.

Before you reset the old phone

1. Check which apps hold your codes. Many people have some in Google Authenticator and some in Microsoft Authenticator or Authy, and each moves separately.

2. Move them with each app's own method, below. An account that will not move can be set up again while you can still sign in: turn its authenticator-app 2FA off and on, or look for "change authenticator app". Our setup guides show where that setting is for 108 services — Google, Microsoft and GitHub among them.

3. On the new phone, sign in to your most important accounts with the new codes — your email first, because it is how every other account gets recovered.

4. Save fresh recovery codes for the accounts that matter, somewhere that is not the phone.

5. Only then erase the old phone. Keeping it in a drawer for a week costs nothing and saves you if one account was missed.

App by app

Google Authenticator. On the old phone open Menu → Transfer codes → Export codes, pick the accounts, and a QR code appears; on the new phone open Menu → Transfer codes → Import codes and scan it. If Google Account sync is on, signing in to the same Google Account on the new phone brings the codes over by itself, old phone or not. Without sync, the export QR code needs the old phone in your hand.

Microsoft Authenticator. Turn on cloud backup on the old phone — it uses a personal Microsoft account on Android and iCloud on iPhone — then recover from it on the new phone. The backup restores only to the same kind of phone: iPhone to iPhone, Android to Android. Codes for other services, such as Amazon or Facebook, come back as they were; for work or school accounts only the account name comes back, and you sign in to each one again. If that is not possible, your organization's help desk can clear your settings so you register the new phone at your next sign-in.

Authy. Authy accounts belong to a phone number. Install Authy on the new phone, enter the number, and approve the new device from the old one or by SMS or a call. Your tokens come across from the old device, or from Authy's encrypted backups if they were on — and those need your backup password, which Twilio never receives and cannot recover. Authy cannot export to another app, so leaving Authy means setting up each account again.

2FAS Auth. With 2FAS Backup on, its sync — Google Drive on Android, iCloud on iPhone — restores your tokens on a new phone of the same kind signed in to the same account. Between Android and iPhone, export a password-protected backup file on the old phone and import it on the new one. If you set a backup password, 2FAS cannot recover it.

2FA Authenticator (ours). It is not on your phone, so a new phone changes nothing for it. That makes it useful during a move: while the codes are in Chrome, you can sign in to each service on the computer and set up 2FA on the new phone without the old one. It cannot put codes into a phone app for you, though its export as otpauth:// links is a format almost any other authenticator can read (backup). To move it to another computer, use Chrome sync or an export file — see multiple devices and restore.

Lost your phone? How to recover 2FA

First, the honest part. A 2FA code is computed from a secret key stored in the app. If that key lived only on the lost phone, it is gone, and nobody can produce it again — not the app's maker, not a repair shop, and not us: 2FA Authenticator never receives anyone's secret keys. What can get you back in is the service you are signing in to. Work through these in order.

1. Check whether a copy survived. Google Authenticator with Google Account sync: install it on the new phone and sign in. Microsoft Authenticator with cloud backup: recover on a phone of the same kind. Authy with backups: install it, enter your number, verify by SMS or call, then enter the backup password. 2FAS with sync: turn on 2FAS Backup with the same Google or iCloud account. If you also added the accounts to 2FA Authenticator, the codes are still in Chrome on your computer.

2. Use the service's recovery codes. Most services hand out a set of one-time codes when you turn 2FA on. Google gives ten backup codes, each working once; GitHub calls them recovery codes. Enter one where the site asks for the 2FA code.

3. Try another sign-in method. A security key or passkey, a text message to a number you still have, or a prompt on another device that is still signed in. GitHub, for example, accepts a passkey or a security key in place of the lost app.

4. Ask the service for account recovery. It is slow on purpose. Google asks questions about the account, and it works best from a device and place you usually sign in from. Coinbase asks for a photo of your ID and takes up to 24 hours (Coinbase 2FA guide). A Microsoft work or school account goes through your organization's help desk. Some services cannot help at all: GitHub says its Support cannot restore access to an account with 2FA once both the 2FA credentials and the recovery methods are lost.

5. Lock the lost phone out. Google suggests erasing a lost phone remotely and, if your codes were synced, removing the device from your Google Account; without sync, it says to visit each site and set the codes up again. In Authy, remove the old device from your devices. Once you are back in an account, set its 2FA up again and save the new recovery codes.

How not to be locked out next time

Keep a second copy of every code. The simplest is two apps from the same QR code: when a site shows its setup QR code, scan it with your phone app and with 2FA Authenticator — both then show the same codes (multiple devices). Accounts already in Google Authenticator come across once through its export QR code.

Keep recovery codes off the phone. Print them, or keep them in a password manager. A screenshot in the phone's gallery is lost with the phone.

Turn on your app's backup, and keep its password somewhere else. Authy's and 2FAS's backup passwords cannot be recovered by the vendor.

Export a backup file now and then. In 2FA Authenticator: Settings → Export, protected with a password (backup); Import on another computer reads it back (restore). The extension's automatic daily copies live inside the extension — they protect against deleting an account by mistake, not against losing the computer.

Add a second way to sign in wherever a service offers one, such as a security key or a passkey.

Frequently asked questions

How do I move Google Authenticator to a new phone?
On the old phone open Google Authenticator → Menu → Transfer codes → Export codes, choose the accounts, and scan the QR code it shows with Google Authenticator on the new phone (Menu → Transfer codes → Import codes). If you use Google Account sync, signing in to the same Google Account on the new phone is enough.
Can I move my 2FA codes without the old phone?
Only if a backup or sync was already on: Google Authenticator's Google Account sync, Microsoft Authenticator's cloud backup, Authy's backups (with the backup password), or 2FAS's Google Drive or iCloud sync. Otherwise the codes were only on the old phone, and you recover each account through the service — its recovery codes, another sign-in method, or its account recovery.
Do I have to set up 2FA again on every website after changing phones?
Not when your app moves the codes for you. You do for Microsoft work or school accounts, which need signing in again after a restore; for Microsoft Authenticator when you switch between iPhone and Android, since its backup restores only to the same kind of phone; and when leaving Authy for another app, because Authy has no export.
I lost my phone. Can you recover my authenticator codes?
No. Your secret keys never reach us, and an authenticator's maker cannot recreate a key that existed only on the lost phone. If a sync or backup was on, restore it on the new phone. If not, get back into each account through the service: recovery codes first, then another sign-in method, then its account recovery.
Can I move my authenticator from Android to iPhone?
It depends on the app. Microsoft Authenticator's backup does not cross between Android and iPhone, so its accounts are set up again. 2FAS syncs within one platform; between them, it moves with an exported password-protected file. Google Authenticator's export QR code and Google Account sync are documented for both Android and iPhone.
Is a browser extension a good backup for my phone authenticator?
It is a second copy that does not go missing with the phone. It does not read your phone app: you add each account to it, by scanning the site's setup QR code or importing Google Authenticator's export QR code, and it then shows the same codes. Keep the computer protected too — 2FA Authenticator can lock your codes with a password (password protection).

Keep a copy that does not live on your phone

2FA Authenticator keeps your 2FA codes in Chrome on your computer. Free to use, open source, no account — 200,000 people use it.

Add 2FA Authenticator to Chrome — free

Sources

Checked October 9, 2026. We make one of the products compared here; if a line about another one is wrong or out of date, tell us and we will fix it.