What Is an Authenticator App and How Does It Work?
What Is an Authenticator App?
An authenticator app is a security app that helps prove you are the person trying to sign in. If you are wondering “what’s an authenticator app?” or “what’s authenticator app?” the short answer is: it provides a second check after you enter your password.
This added check is often called two-factor authentication, two-step verification, or multifactor authentication. A stolen password may not be enough to enter your account because the person signing in must also complete the check shown by the authenticator app.
The app may display a short verification code or ask you to approve a sign-in notification. The exact options depend on both the authenticator app and the account provider. Some providers also support security keys, text messages, backup codes, or other approved methods.
An authenticator app does not manage your password or replace the company that holds your account. Sign-in settings, recovery decisions, and identity checks remain under the control of the relevant account provider.
How Authenticator Apps Work
Many authenticator apps create a temporary code, commonly six digits long. The app and the account provider share information established during setup. Each side uses that information and the current time to generate or check the code.
A code normally changes after a short period. A countdown circle, bar, or timer may show how much time remains. The old code stops working after it expires, which limits how long someone could use a copied code.
Some apps use approval prompts instead. After you enter your password, the app may show a notification asking whether you are signing in. Check the account name, device, and location shown before approving. Deny an unexpected request. Never approve repeated prompts merely to make them disappear.
Time-based codes can often appear without cellular service, text messaging, or an active internet connection because the phone creates them locally. Approval notifications usually require an internet connection. Features differ, so do not assume every app works in exactly the same way.
How to Set Up an Authenticator App
Start while you can still sign in to the account. Keep the account open on one device and have the phone with the authenticator app nearby. In the account’s security settings, look for wording such as two-factor authentication, two-step verification, multifactor authentication, or authenticator app.
- Select the option to add or set up an authenticator app.
- Follow the account provider’s instructions. A QR code commonly appears on the screen.
- Open the authenticator app and choose its option for adding an account. Use the camera to scan the QR code. If scanning is unavailable, the provider may offer a setup key that can be entered manually.
- Check that a new entry appears in the app. Its label usually identifies the provider or the account.
- Enter the current code on the setup screen, or complete the requested approval, to confirm that the connection works.
- Save any backup codes offered by the account provider in a secure place separate from the phone.
Treat the QR code, setup key, and backup codes as sensitive. Someone who copies setup information may be able to generate valid codes. Do not send screenshots of them or enter them into an unexpected message or form.
Do not close the setup screen until the test succeeds. Setup screens and transfer features vary, so follow the instructions displayed by the account provider and authenticator app.
How to Use a Verification Code
When a sign-in screen asks for an authenticator code, leave that screen open and switch to the authenticator app. Find the entry that matches the account you are entering. Be careful if you have several entries with similar names.
- Read the current code shown beside the correct account.
- Return to the sign-in screen.
- Enter the code exactly as displayed, without substituting your password or a code from a text message.
- Submit it before the countdown ends.
If only a few seconds remain, wait for the next code and enter the new one. A code is generally intended for one sign-in attempt. Never share it with someone who contacts you unexpectedly, even if that person claims to provide support.
For an approval prompt, review the details rather than approving automatically. If the app asks you to match a number, select or enter the number displayed on the sign-in screen. Reject the request if you did not start it.
What to Do If a Code Does Not Work
First, wait for a fresh code and try once more. An error often means the previous code expired while it was being entered. Check every digit and make sure you selected the entry for the correct provider and account.
If fresh codes repeatedly fail, check the phone’s date and time settings. Time-based codes depend on an accurate clock. Turn on the device option that sets the date, time, and time zone automatically, then reopen the authenticator app and try the newest code.
- Do not reuse a code that has already changed.
- Make sure the sign-in page is asking for an authenticator code, not a texted code, backup code, password, or approval prompt.
- If duplicate account entries appear, use the one linked during the most recent successful setup.
- Look for an option such as try another way only if it offers a backup method previously approved for your account.
A backup code, security key, recognized device, or another method may be available, but only the account provider can determine which choices are valid. Avoid repeated guessing if the account warns that attempts are limited.
Changing or Losing Your Phone
Before replacing a working phone, review the authenticator app’s official transfer or backup instructions and the security settings for each linked account. Some apps can transfer entries directly, while others require you to remove the old authenticator and enroll the new phone separately.
Confirm that codes or prompts work on the new phone before erasing, trading in, or resetting the old one. Keep provider-issued backup codes stored securely and separately. A normal phone backup may not include authenticator entries, so verify the result rather than assuming they transferred.
If the phone is lost, broken, or already erased, use only recovery choices shown by the relevant account provider. These may include a saved backup code, a security key, a recognized device, or an identity check. Availability varies by account.
Authenticator-app support cannot independently restore access to an unrelated account. Recovery must go through the company or organization that controls that account. On its official site, find the sign-in help, account recovery, security, or support section and follow the displayed process. Once access is restored, remove the lost phone from the account’s security methods and enroll the replacement device.