From the blog
How to switch authenticator apps without getting locked out
You have an authenticator app you set up years ago. Maybe it is Google Authenticator, maybe Authy, maybe whatever your bank told you to install. It works, so why change it? Usually it comes down to one of a few reasons: you want a real backup, the app you used to like got worse, or you are tired of having codes scattered across two or three apps and want them all in one place.
And then you stop, because of one quiet fear: what if I move to a new app and lock myself out of something important? This post is for the ordinary person with a dozen or so accounts who wants to switch without that ever happening. You do not need to be technical. The trick is simple, and once you see it, switching stops being scary.
The one rule that keeps you safe
Keep your old app until the new one is proven. That is the whole secret.
You never have to delete anything from your old authenticator to start using a new one. Both apps can show codes for the same account at the same time. So you move one account, log in with the new app to confirm it works, and only then move on. Your old app keeps doing its job the entire time. Nothing gets turned off until you are sure.
If you remember nothing else from this post, remember that. The lock-out horror stories almost always come from someone deleting the old app first and finding a problem after there is no way back.
Why this is less risky than it feels
Each account is its own separate thing. Moving your email over to a new app does not touch your bank, your shopping sites, or anything else. There is no single "transfer everything" button you can get wrong. You go one account at a time, and a mistake on one never spreads to the others.
It also helps to know that the website on the other end does not care which app you use. A 6-digit code is a 6-digit code. Your bank cannot tell whether the number came from Google Authenticator or any other app, as long as it is correct. Switching apps is invisible to the services you log into.
How to switch, one account at a time
- Install the new app, but do not delete the old one. Leave your current authenticator exactly where it is. You will remove accounts from it later, at the very end, and only after everything is confirmed.
- Practice on a throwaway account first. Pick something low-stakes: an old forum, a shopping site, a newsletter login. Do not start with your bank or your email. You want your first attempt to be on something where a mistake costs you nothing.
- Add the new app in that account's security settings. Log into the service on a computer or in a browser, find its two-factor or authenticator settings, and choose to set up an authenticator app again. It will show a QR code. Scan that code with your new app.
- Confirm the new code logs you in. The service will ask you to type a code from the new app to prove it worked. Once it accepts that code, the account lives in both apps at once. That is exactly what you want.
- Now do the accounts that matter, carefully. With the flow under your belt, work through your important accounts: email first, because it is how you reset everything else, then your bank, then the rest. Same steps each time, one at a time.
- Only at the very end, clean up the old app. When every account works in the new app and you have logged into each one to prove it, you can remove them from the old authenticator. Not a moment before.
That is the entire process. At no point in that sequence are you ever without a working code, because the old app is still there until the last step.
A couple of common worries
- "Will moving an account log me out of where I am already signed in?" No. Setting up a new authenticator changes how you log in next time. It does not kick you out of sessions you already have open.
- "What if a site only allows one authenticator at a time?" A few do. For those, set up the new app and test its code in the same sitting, so the gap between removing the old setup and confirming the new one is seconds, not days. Keep the old app open just in case.
Is there a faster way than one at a time?
Sometimes. A few apps can hand off a batch of accounts at once instead of making you re-add each one by hand. It depends on the app you are leaving:
| Leaving this app | The faster path |
|---|---|
| Google Authenticator | It has a built-in "transfer accounts" export, shown as a QR code, that a guided import can read |
| Authy | No bulk export, so you re-add each account by hand using the steps above |
| Aegis or 2FAS | Both create an export file you can import in one go |
If you are coming from Google Authenticator, Fob has a guided import that reads its transfer export and brings your accounts over in about a minute. The step by step is in the Google Authenticator import guide. If you are leaving Authy, where there is no bulk export, the Authy import guide walks through the fastest by-hand path.
Even with a faster import, the one rule still holds: keep the old app until you have confirmed the new one works.
Make this the last switch you have to make
The reason switching apps feels like a chore is that most people only do it under pressure, after losing a phone or getting locked out. You can avoid ever being in that spot again. Once your accounts are in the new app, take one more minute to set up recovery, so a lost or broken phone is never an emergency.
We wrote a plain-language guide to exactly that: how to back up your 2FA codes so you never lose them when you switch phones. Do that step now, while everything is calm, and the next phone upgrade becomes a non-event.
Switch once, the easy way
Fob is built to make switching painless: a guided import that brings your accounts over, export anytime so you are never locked in, and guided recovery so a lost phone stays a minor inconvenience. Android first, iOS to follow.
Get it on Google Play