Security

Authenticator App

An authenticator app generates temporary verification codes or approves sign-in requests. Prepare its recovery or transfer options before replacing the phone.

Authenticator phone beside a login screen, replacement phone and protected recovery envelope.

What it means

Code-generating apps commonly derive a changing code from a stored secret and time. That secret matters more than a screenshot of one code. Some apps synchronise accounts; others require a transfer or fresh registration. A working code can still be stolen through a false sign-in page.

How this affects everyday use

Rejected codes may result from incorrect device time, the wrong account entry or expired codes. Missing entries after a phone replacement usually concern transfer or recovery, not the account password.

A practical example

You replace a phone and discover the email account’s authenticator entry was never transferred. A previously stored recovery code may restore access without disabling protection permanently.

What to check

  • Confirm the code belongs to the correct account and service.
  • Check automatic date and time before repeating failed attempts.
  • Read the app’s current transfer, backup and recovery instructions.

Practical next steps

  • Register the replacement device while the old one remains accessible.
  • Test a fresh sign-in before removing the old authenticator entry.
  • If locked out, use the service’s official recovery process.

Keeping it reliable

Treat setup QR codes and shared secrets like credentials. Keep recovery material separate, lock the phone and reject approvals you did not request. Do not give a support caller your current verification code.

Technical sources

← All glossary terms