Comparison
Fob vs Authy: An Honest Comparison
If you are picking between Fob and Authy in 2026, you are doing it after the noise. Twilio sunset the Authy desktop apps in August 2024, the mobile app still works, and Authy has never let users export their accounts. This page lays out where each one lands so you can decide.
We will not pretend Fob is the right answer for everyone. For some users, Authy is the right answer, and we will say so plainly.
The 60-second answer
Pick Authy if
- You have fewer than 10 accounts and no need to organize them.
- You specifically value phone-number-based recovery and the SMS flow it implies.
- You trust Twilio long-term and the brand recognition is part of why you picked Authy originally.
- Multi-device sync via phone-number-associated devices is load-bearing for you and already works the way you want.
Pick Fob if
- You want a real export at any time, in a standard format, without filing a support ticket.
- You have 20+ accounts and want to filter by tag (
crypto,work,family). - You want recovery that does not depend on your phone number being intact.
- You want vendor independence with published architecture (now) and a third-party security audit committed post-launch (report at fob.codes/security when complete).
Migrating off Authy is not one minute and one QR code. Authy has no export, so you re-enroll account by account. The path is at /import/authy.
Side by side
| Feature | Authy | Fob |
|---|---|---|
| Tag-based organization | No, flat list only | Yes, multi-tag per account with filter UI |
| Phone number required | Yes | No |
| Real export | No, never shipped | Yes, otpauth-migration QR plus .fobvault |
| iOS support | Yes | Coming after Android |
| Recovery model | SMS to phone number | Master password plus guided recovery wizard |
| Multi-device approach | Cloud sync via phone-number-associated devices | Restore from end-to-end encrypted cloud backup |
| Published third-party audit | Vendor-attested only | Committed post-launch |
| Cost (individuals) | Free | Free tier; encrypted cloud backup is part of Fob Premium |
| Family sharing | No | Post-MVP |
| Desktop app | Discontinued August 2024 | Not on roadmap |
A few rows are worth a closer look. On export, Authy has never shipped one. That is not a 2024 change, it is the policy from launch. If you have 40 accounts in Authy and you want to leave, the path is to log into each service and re-enroll its 2FA. Google Authenticator has export. Aegis has export. 2FAS has export. Fob has export. Authy does not.
On audits, neither app currently has a published independent third-party audit. Authy's encryption claims are vendor-attested by Twilio. Fob's first audit is committed post-launch and will be published in full at fob.codes/security, with the plan to repeat annually. The architecture (Argon2id key derivation, AES-256-GCM vault encryption, end-to-end encrypted cloud backup) is already documented at /security and is verifiable by structure, not by promise.
Where Authy wins
The Authy mobile app still works in 2026. We are not going to pretend it does not.
Multi-device sync without a master password. Authy ties devices to your phone number. Add a new device, get a verification code, and your accounts come with you. There is no master password to remember, no recovery code to lose, no Argon2id parameters to think about. For a user who values that simplicity, it is a real feature, not a marketing line.
Phone-number-as-identity is genuinely simple for some users. Recovery via SMS feels concrete in a way that "guided recovery wizard with a recovery code" does not. If you lose your phone, you get a new SIM, you sign back into Authy, your accounts come back. For users who do not want to manage a separate password, this model fits how they already think about identity.
Authy still has setup-flow brand recognition. Some older 2FA setup tutorials specifically suggest Authy by name. Banks, exchanges, and legacy enterprise systems sometimes display "scan with Authy" as the default copy. That gets you through setup with one fewer decision to make.
For low-account users, Authy is fine. If you have eight accounts, the lack of tags is not a missing feature. The flat list is the correct UI for that count. The lack of an export button matters in theory but is not painful when you could re-enroll eight accounts in a Saturday afternoon. Fob does not improve your life enough at that scale to be worth a migration.
The Twilio brand carries trust for users who already trust Twilio. Twilio is a public company with a long messaging-infrastructure history. For a user who has already decided that is a fine place to keep their 2FA seeds, Authy is the consistent choice and there is no strong reason to leave.
Where Fob wins
Fob exists because there is a class of authenticator user that Authy does not serve well, and the gap has widened over time.
Real export, any time. Fob's export is one menu deep. You get a .fobvault JSON and an otpauth-migration:// QR you can scan into any other RFC 6238 authenticator. Authy never shipped this and has not changed the policy. If you ever decide Fob is not the right app for you, you walk out with your accounts. We cannot hold them. That is the posture we think every authenticator should take, and it is the single biggest functional difference between these two apps.
Tag-based organization. This is Fob's core differentiator and no major competitor has it, Authy included. Each account can carry multiple tags at the same time: a Coinbase account can be crypto, exchange, and high-value simultaneously. The filter UI is one tap. For users with 30, 50, or 100+ accounts, this turns the vault from an unsearchable wall of icons into a navigable structure. Authy has no tags, no folders, no grouping of any kind.
Recovery that does not require your phone number. Authy's recovery is SMS to your phone number. That works, until it does not, like when your phone number changes, when you are out of cell coverage, or when you are the target of a SIM-swap. Fob's recovery is a guided wizard with a recovery code you stored at setup, plus your master password. It does not depend on your number being intact.
Vendor independence by design. Twilio is a public company and has had layoffs and strategic shifts. Authy users learned in 2024 that "what happens if Twilio decides X" is a real question with no good answer when there is no export to soften the landing. Fob's export-always design means if Cleargate Labs shuts down tomorrow, you walk out with your accounts. The architecture is the trust signal, not the stability of any one vendor.
Architecture transparency. Fob publishes its encryption details at fob.codes/security: Argon2id for key derivation with stated parameters, AES-256-GCM for vault content, end-to-end encrypted cloud backup, audit reports posted in full when they come back. Authy's encryption is vendor-attested by Twilio without published architecture documents. Reasonable users land on either side of "is that enough", but the visibility difference is real.
Where it depends
A few axes do not break cleanly for either app.
Phone number as identity. Authy uses your phone number as primary identity. Fob does not require one. Some users specifically want the phone-number model: the recovery flow feels concrete, and they already trust SMS as a verification channel. Other users want to break the coupling, especially those who have been SIM-swapped before or who are reducing the number of services they hand a phone number to. Either preference is rational.
Multi-device approach. Authy syncs via phone-number associations: add a device, get a verification code, and your accounts come with you. Fob takes a different shape: create an end-to-end encrypted cloud backup on your phone, then restore it on a new device by signing in with your master password. Both put your codes on a second device; the workflow and trust model differ.
iOS support. Authy ships an iOS app that works today. Fob is on Android first; iOS is on the roadmap but not yet shipped. If you need iOS today, Fob is not yet the right answer.
Cost. Both are free for individuals. Authy has no paid tier. Fob has a Premium tier that includes end-to-end encrypted cloud backup; the local-only experience is free.
The decision framework
Authy is the right answer in more cases than the marketing for any new authenticator wants to admit.
Stay on Authy if you have fewer than 10 accounts and no organization needs. The lack of tags does not bite you. The lack of export is theoretical pain at this scale. The migration cost is real and the upgrade is small.
Stay on Authy if phone-number-based recovery is the model you want. Some users prefer SMS recovery and find a master-password-plus-recovery-code flow harder to reason about, not easier. Pick the model that matches how you think.
Stay on Authy if you trust Twilio long-term. If you have already made peace with the desktop sunset, the no-export policy, and the phone-number-as-identity model, Authy still works. There is no strong reason to switch out of vague unease.
Stay on Authy if multi-device sync via phone-number associations is load-bearing. That is what Authy was built for and it is genuinely good at it. Fob's encrypted backup is a different shape, but if Authy's specific approach already fits your life, switching costs more than it saves.
Move to Fob if Authy's no-export policy has been the friction. This is the most common reason readers of this page are here. Export-always is a posture, not a feature, and we built around it.
Move to Fob if you want tag-based organization. Above 20 accounts, tags pay for themselves on every open. No competitor does this.
Move to Fob if you do not want phone number as identity. Fob does not ask for one.
Move to Fob if you want vendor independence and published architecture. That is what /security is for.
Migration paths
If you are leaving Authy for Fob, the step-by-step is at /import/authy. We are honest with you up front: this migration is harder than the migration off other apps because Authy has no export. You log into each service, disable 2FA, and re-enroll with a Fob QR. One account at a time. The guide includes a priority order so you protect the high-value accounts first.
If you are coming from elsewhere, the sister comparison is at /compare/fob-vs-google-authenticator.
What to do next
If Authy fits your profile, stay on it. We do not need to convert everyone, and a comparison page that pretends Authy has nothing going for it would not be honest. The mobile app works, multi-device sync works, and for the users above it is the right tool.
If Authy's no-export policy has been a quiet itch, or if you have hit the point where 40 accounts in a flat list is a usability problem, that is what Fob is built for. Get it on Google Play. Android first; iOS comes after, and you can get notified from the homepage when the iOS build lands. The architecture is at fob.codes/security.
Fob is on Google Play
On Android today. iOS to follow. Tag-based filtering, end-to-end encrypted cloud backup, export anytime.
Get it on Google PlayQuestions this comparison did not answer? Email us at support@fob.codes.