Login.gov Authentication App and New Phone Setup
How Login.gov Authentication Apps Work
A Login.gov authentication app adds a second security check after you enter your email address and password. The app uses a saved connection to generate a temporary code, even when the phone has no cellular service.
The app is separate from Login.gov. It may contain codes for several accounts or services, so choose the entry labeled for your Login.gov account. A code changing on the screen is normal. Each code works only for a short time.
The connection is stored on the device or transferred by the authentication app’s own backup process. Installing the same app on a new phone does not always restore that connection automatically.
Sign In With an Authentication App
- Open {site} and select the option to sign in.
- Enter the email address and password for your Login.gov account.
- When asked for an authentication method, choose the authentication app option.
- Open the connected authentication app on your phone.
- Find the Login.gov entry and enter the current code shown there.
- Submit the code before it changes.
Do not enter a code from a different account, even if it appears in the same app. Login.gov will accept only the code produced by the connection previously added to that Login.gov account.
Set Up the Authentication App on a New Phone
A replacement phone must be connected as a new authentication method. If the old device is unavailable, first sign in using another method already attached to your account, such as backup codes, a security key, a passkey, or another method offered on your sign-in screen.
- Sign in with your email address, password, and an available backup authentication method.
- Open your account settings and find the area for authentication methods.
- Choose the option to add an authentication app.
- Open an authentication app on the new phone and start its process for adding an account.
- Scan the code displayed by Login.gov. If scanning is not possible, use the manual setup option shown during enrollment.
- Enter the temporary code generated on the new phone to confirm the connection.
- Add or review a backup authentication method before signing out.
The login.gov authentication app new phone process does not bypass two-factor authentication. You must prove access with an existing method before changing security settings.
If You Still Have Your Old Phone
Keep the old phone connected until the new phone has been added and tested. Sign in with the old phone, add the authentication app on the replacement phone from account settings, and complete the confirmation step.
Then sign out and perform a fresh sign-in using the code from the new phone. Check that the code belongs to the correct Login.gov entry and is accepted. Only after that test should you remove the old authentication-app entry from your account or erase the old device.
Review your other authentication methods at the same time. Keeping more than one usable method can prevent another lockout if a phone is lost, damaged, or reset.
If You Cannot Access Your Authentication App
On the authentication screen, look for the option to use another method. The choices shown depend on what you previously added to your account. Use an available backup method and then add the new phone through account settings.
Backup codes must be unused and belong to this account. A security key, passkey, or other listed method must also have been connected before the lockout. Login.gov support cannot accept personal details as a substitute for an authentication method and cannot sign in to an agency account for you.
If no authentication method is available, follow the official account recovery or account deletion instructions presented by Login.gov. You may need to delete the inaccessible Login.gov account and create a new one with the same email address after the required security process is complete. Recreating Login.gov does not itself restore an agency session; return to the agency that uses Login.gov and follow its instructions for reconnecting access.
Fix Common Authentication Code Problems
Invalid code: Wait for a new code, enter it carefully, and submit it before it expires. Do not reuse the previous code.
Wrong account entry: If the app lists several services or duplicate Login.gov entries, select the entry connected to the account you are signing in to.
Incorrect device time: Set the phone’s date, time, and time zone to update automatically. Authentication codes depend on accurate time.
Old connection: A restored or copied app entry may not match the active method on your account. Sign in with another method and enroll the new phone again.
Repeated failures: Stop entering codes for a moment, check the email address and account entry, then restart sign-in. If Login.gov displays a temporary restriction or another instruction, follow the message rather than repeatedly retrying.
Never send a screenshot of a current code or setup image to anyone. Either could allow another person to attempt access.
Get Official Login.gov Help
Use the Help or Contact option on the official Login.gov site. Choose the topic for signing in, authentication methods, or account access, and describe the point where the process stops. Include the exact error wording, the type of authentication method, and whether another method is available.
You may identify the email address associated with the account when the official support process asks for it. Do not share your password, temporary authentication code, backup codes, setup key, security-key secret, or a scannable setup image. Support should not need those secrets to explain the official recovery steps.