Two-factor by text message is far better than no second factor at all — but it is the one form of it an attacker can take without touching your phone. A SIM swap moves your number to their device, usually by social-engineering a carrier rep, and every code you rely on then arrives on their handset. Codes generated on your device instead of sent to your number remove that entire attack. Which app you use to generate them matters much less than making the switch, and the feature that should decide it is backup.
Why texted codes fail
If you take one thing from this guide: move your two-factor codes off SMS and onto an app. Texted codes were a huge step up when they arrived, but they carry a specific weakness — SIM-swapping. An attacker convinces or bribes your mobile carrier to move your phone number onto their SIM card, and every code texted to “you” now arrives on their phone. It happens, it’s targeted, and there’s nothing you can do from your side once your number’s been moved.
An authenticator app sidesteps this entirely. It generates codes on your device, from a secret shared once at setup plus the current time — no phone number involved, nothing to reroute. That’s the whole security case, and it’s a strong one. (Where a service offers a passkey, that’s better still, because it’s phishing-proof too — see our passkey guide. But plenty of accounts offer app-based 2FA and not passkeys yet, so a good authenticator remains essential.)
The one nuance worth stating plainly: SMS 2FA still beats no 2FA. For an account that offers nothing but SMS, turn it on rather than skipping a second factor entirely. Just don’t choose SMS when an app or passkey is on the table.
The feature that actually matters: backup
Most authenticator apps generate the same standard codes (called TOTP — time-based one-time passwords), so on pure security they’re near-identical. The thing that separates a good experience from a miserable one is what happens when you lose, break, or replace your phone.
- An app with encrypted cloud backup or account sync restores all your codes on a new phone by signing in. Painless.
- An app with no backup strands every code on the old device. Your only way back into each account is the one-time recovery codes that service gave you — and if you didn’t save those, you’re into slow, uncertain account-recovery support queues.
So when you compare apps below, read the “backup” column first. It’s the difference between a cracked screen being an annoyance and being a weekend lost to lockouts.
The main free authenticator apps, compared
These are free and non-affiliate — we’re listing them on merit. Details like exact backup mechanics change, so verify current specifics before relying on them.
| App | Cost | Backup / sync | Best for | Worth knowing |
|---|---|---|---|---|
| Google Authenticator | Free | Cloud backup tied to your Google account | Anyone in the Google ecosystem who wants simple and reliable | Long the default; added cloud sync after years of being backup-less. Secure your Google account well, since it now guards your codes. |
| Microsoft Authenticator | Free | Cloud backup tied to a Microsoft account | Windows/Microsoft 365 households; also handles Microsoft passwordless sign-in | Doubles as approval prompts for Microsoft accounts. Ties your backup to your Microsoft account’s security. |
| Proton Authenticator | Free | Encrypted sync across devices | Privacy-minded users; anyone already in the Proton ecosystem | From the privacy-first Proton team; fits alongside Proton Mail, VPN, and Pass. Cross-platform. |
| Authy | Free | Multi-device cloud backup | People who want codes on several devices at once | Popularized encrypted multi-device backup. Check current platform availability before committing. |
| 2FAS | Free, open-source | Optional backup to your own cloud storage | People who want open-source and control over where backups live | Community-favored open-source option; you control the backup location. |
| Aegis (Android) | Free, open-source | Encrypted local/manual export | Android users who want open-source and offline-first control | Android-only; encrypted exports you manage yourself rather than automatic cloud sync. |
A few honest reads on the table:
- You can’t really go “wrong” among these on security — they generate the same codes. Pick on backup, ecosystem fit, and whether you value open-source.
- Backup convenience and backup control are a trade-off. Automatic cloud sync (Google, Microsoft, Proton, Authy) is easiest; open-source options (2FAS, Aegis) hand you more control over where your backup lives, at the cost of a little more setup.
- Ecosystem fit is a real tiebreaker. If your life is already in Google, Microsoft, or Proton, using their authenticator keeps things tidy — one fewer account to secure separately.
The option most people overlook: your password manager
Here’s the recommendation that surprises people. If you already use a password manager, it can store your two-factor codes too — and for many people that’s the best home of all. Your password for a site and its 2FA code then live in the same vault, sync to every device together, and get backed up together. No separate app, no separate backup to worry about.
1Password
Stores your 2FA codes right alongside each login and autofills them — passwords and codes sync together across every device, with the category's smoothest apps and family setup.
The trade-off is real and worth stating: putting the password and its code in one vault means that if someone fully compromises your vault, they have both factors. For most people that risk is small — a properly secured vault (strong master passphrase, its own second factor) is very hard to breach — and the convenience plus guaranteed backup outweighs it. Security purists prefer to keep codes in a separate app so the two factors live apart, and that’s a perfectly defensible choice. Both are far better than SMS; pick based on whether you value one-place convenience or factor-separation more.
One caveat if you go this route: put the second factor on the vault itself using a different method — ideally a passkey or a separate authenticator — so your manager isn’t guarding its own front door with a key kept inside. We cover securing the vault in the guide to ending password reuse.
Building a whole privacy stack? Consider Proton
If you’re assembling a privacy-first toolkit rather than just picking one app, keeping your authenticator in the same family as your email and VPN has a tidiness appeal.
Proton
Proton Authenticator sits alongside Proton Mail, VPN, and Pass — if you want one privacy-focused company across your email, browsing, passwords, and 2FA, the suite is a legitimately simple answer.
This isn’t necessary — a standalone free authenticator is completely fine — but if you’re already leaning toward Proton for email and VPN (see our guide to whether you need a VPN), using its authenticator too means one company, one account to secure, one privacy philosophy across the stack.
How to choose: the criteria that actually matter
Cutting through the feature lists, here’s what we’d weigh, in order:
- Backup and recovery. Non-negotiable, and covered above. If losing your phone would strand your codes, you’ve chosen wrong. Favor an app with encrypted cloud sync, an open-source app with a backup you configure, or your password manager.
- Where it runs. It has to be on the devices you actually use. Most of these are cross-platform; a couple (like Aegis) are single-platform, so check before you commit.
- Ecosystem fit. Already deep in Google, Microsoft, or Proton? Their authenticator means one fewer separate account to secure.
- Open-source vs convenience. If you value inspectable code and controlling your own backup location, 2FAS and Aegis lead. If you value automatic, hands-off sync, the big-ecosystem apps lead.
- Consolidation vs separation. Password manager holding your codes = maximum convenience and unified backup. Separate app = your two factors live apart. Both beat SMS; choose your preference deliberately.
Notice what’s not on the list: fancy interfaces, extra features, brand prestige. On core security these apps are equivalent, so don’t overthink the pick — the mistake that actually hurts people is staying on SMS, not choosing the “wrong” excellent app.
What’s not worth it
- Staying on SMS out of habit. It’s the SIM-swap weak point. Move important accounts to an app (or a passkey) and keep SMS only where nothing else is offered.
- An authenticator with no backup, in 2026. Being stranded after a lost phone is an avoidable, self-inflicted problem now that good backup options are free.
- Paying for a standalone authenticator. The free options here are excellent. The only thing worth paying for adjacent to this is a password manager or a privacy suite you’d want anyway — the authenticator rides along.
- Screenshotting your backup codes to your camera roll. Synced, searchable, and exposed if your cloud account is. Put recovery codes in a secure note or on paper.
Don’t skip the recovery codes
Whichever app (or vault) you choose, when you enable 2FA a service hands you a set of one-time backup codes — your way in if your authenticator and its backup both fail. Treat them as part of setup:
- Good homes: a secure note attached to that login in your password manager, or a printed sheet somewhere safe at home. Both is reasonable for critical accounts.
- Bad homes: a screenshot in your photo library, an email to yourself, a file called
codes.txton the desktop.
This is the same discipline we walk through in the afternoon plan to secure your accounts — the authenticator is one piece of that larger setup.
The bottom line
Pick a free authenticator with solid backup, or — if you already use one — let your password manager hold your codes. Move your important accounts off SMS onto whichever you choose, save the recovery codes properly, and turn on passkeys wherever they’re offered on top. That’s the whole job, and it closes the most common remaining gap after a password manager. This guide is part of our Privacy & Security Kit, alongside the password manager comparison and the account-security plan that ties it all together.