Security

How to move Google Authenticator accounts to a new phone

Moving Google Authenticator accounts to a new phone can feel risky if you rely on time-based one-time passwords (TOTP) for email, banking, work, and critical services. Losing ac...

Mara Ellison
How to move Google Authenticator accounts to a new phone

What this guide covers and why planning matters

Moving Google Authenticator accounts to a new phone can feel risky if you rely on time-based one-time passwords (TOTP) for email, banking, work, and critical services. Losing access can lock you out of accounts and cause operational delays. This evergreen explainer shows how to transfer authenticator setups safely, using built-in export and import features where available, account recovery options when export is not available, and verification steps to confirm each service remains accessible after migration. Follow these methods to keep 2FA intact and avoid surprises.

How Google Authenticator transfer works at a high level

Unlike some newer authenticators, Google Authenticator does not currently offer a built-in cloud sync or direct device-to-device transfer. This means accounts are locally stored on each phone. Transfer therefore involves removing accounts from the old device and adding them to the new device while preserving the same shared secrets. Approaches vary by platform (Android and iOS), whether you control the old device, and whether individual services offer backup or export for 2FA seeds. The safest path is planning before you switch, ensuring you retain alternative access methods for every critical account.

Plan before you move: prerequisites and risk checklist

Before changing devices, audit your accounts and prepare fallbacks. Prioritize services that protect email, identity, money, and work. For each, confirm at least one backup option: recovery email, backup codes, a second factor (phone number SMS, security key, or authenticator backup), or admin support. If you cannot reach the account without the current device, set up a backup method on the old device first. Plan to perform the transfer while you still have full access, using stable power and reliable Wi-Fi. If the old device is lost, stolen, or resetting its operating system, treat this as an emergency recovery process, not a simple move.

Risk checklist to complete before starting

  • Charge both devices and ensure reliable internet.
  • Confirm each critical service has recovery options available.
  • Test backup codes or alternative authenticators.
  • Disable biometrics or device unlock methods only if you can re-enroll safely.
  • Keep the old device available until every account is verified on the new device.

Verify current authenticator setup on the old device

Start by listing which services are protected by Google Authenticator on the old device. On Android, open the Authenticator app and note each entry; on iOS, the process is the same within the app. For services you cannot inspect directly (e.g., system apps with embedded 2FA), use the service’s web dashboard on a computer to see which authenticator is enrolled. Capture details such as account name and service provider, but not the secrets themselves unless export is supported. This inventory reduces missed accounts after migration and helps you follow up on services that need manual reconfiguration.

Preferred method when export or transfer is available

Some apps and platforms allow you to export or re‑enroll 2FA seeds in a secure, encrypted form rather than copying the QR code manually. If a service such as 1Password, LastPass, or another identity provider is managing your authenticator entries, use its built‑in sync or change‑device workflow. Re‑enroll by scanning the provided QR code on the new device, then confirm that the code changes match. Whenever export is available, prefer it over visual transcription to avoid entry errors and to keep backups consistent. After re‑enrollment, check that push approvals or OTP codes work as expected.

Example supported transfer flow (when available)

AttributeVerified DetailSource Type
App with export support1Password, Bitwarden, AuthyProduct documentation
Native Google app supportNot available in Google AuthenticatorGoogle Help documentation
Recommended methodExport encrypted backup then re‑enroll on new deviceBest practice from security vendors

Manual transfer method: copying QR codes safely

When export is not available, move accounts by re‑enrolling each service on the new phone using QR codes or manual secrets. On the new device, add a new account in Google Authenticator, scan the service’s QR code, and enter the backup code if prompted. If you cannot scan from the old phone, you can reveal the secret key on many services (look for Show secret or Recovery code) and type it into the new device’s authenticator. This method requires careful transcription and is best done over a secure connection. Confirm each account by entering a generated code into the service’s 2FA test field or by receiving a prompt. Do not remove the old device’s enrollments until verification is complete.

Step-by-step manual workflow

  1. On the new phone, open Google Authenticator and add a new account.
  2. On the service website or app on a computer, open Security or 2FA settings.
  3. Choose Change authenticator or Replace authenticator, then scan the new QR code with the Authenticator app.
  4. Enter a backup or recovery code if the service requires it during re‑enrollment.
  5. Test by entering a fresh OTP from the new device and, if possible, approving a push from the service.
  6. Repeat for each service, keeping the old device online until you confirm access.

Handle services that block transfer by code or reset

Some providers restrict moving authenticators and may require you to sign in from the original device or prove identity through recovery options. If you cannot re‑enroll directly, sign in to the service on the old device and rotate 2FA: disable authenticator, then re‑enable and scan a new QR code on the new device. If you cannot access the old device, use account recovery immediately: start the recovery flow from the service’s login page, verify identity via backup email, phone number, or security keys, and reset 2FA. After recovery, add the new device as the authenticator and record any backup codes in a secure password manager.

Transfer when the old device is lost, stolen, or wiped

An unavailable old device shifts this task from a move to an emergency recovery. For each service, initiate account recovery using backup methods designed before the loss. If you previously saved encrypted authenticator backups (e.g., Authy cloud encrypted or Bitwarden attachments), restore them on the new device using your master password. If backups are unavailable, contact the service provider and follow their account restoration steps, which may include verifying government ID, payment methods, or support tickets. Rotate credentials after recovery to limit exposure. Treat this scenario as high-risk and document each step for audit purposes.

Post-move verification and long-term best practices

After moving Google Authenticator accounts to a new phone, run a verification pass using a checklist. Sign in to each service and confirm that OTP codes from the new device work, and that backup codes still function when needed. Store new recovery codes in a password manager or secure vault. If available, enroll a hardware security key as a stronger second factor. Set calendar reminders to review 2FA methods every 6–12 months. Finally, remove old device enrollments from services to prevent lingering access that could be abused if the old device is later found.

Frequently asked questions

  • Can I move Google Authenticator without losing access? Yes, if you plan ahead. Export where possible, use recovery codes, and confirm each service on the new device before removing the old enrollments.
  • What if a service doesn’t let me change devices? Use account recovery options immediately, rotate credentials after gaining access, and ask the service provider about administrator tools for managed accounts.
  • Is transferring via screenshots or notes safe? Avoid screenshots or storing secrets in plain notes. Use encrypted backups or a password manager with secure notes instead.
  • Do I need to update apps that share a single 2FA setup? Re‑enroll each dependent app independently; some apps store their own secrets and must be rescanned after moving authenticators.
  • How often should I review my authenticator setup? Review every 6–12 months, or immediately after any device loss, account compromise, or major phone change.

Related Reading

More pages in this topic cluster.

What Does It Mean to Whitelist a Server

To whitelist a server means to explicitly allow it to bypass security controls such as firewalls, access lists, or application filters so that it can communicate, authenticate,...

Read next
How to Create an Army: Methods, Legality, and Realistic Considerations

To create an army is to organize a coherent, trained force capable of achieving strategic objectives through disciplined coordination. In practical terms, this means assembling...

Read next
Fort Gordon Gate 2: What It Is and Why It Matters

Fort Gordon Gate 2 is a controlled access point on the Fort Gordon installation near Augusta, Georgia, serving as a security and traffic management checkpoint for personnel, veh...

Read next