An authenticator app adds a second check to a sign-in, so a password alone is not enough. Depending on the account, the app may display a short-lived code to enter or send an approval prompt. That can make a stolen password less useful—but app codes can still be phished, and account recovery or a stolen device can create other risks.
What two-factor authentication adds to a login
Two-factor authentication (2FA), also called two-step verification or multi-factor authentication (MFA), requires proofs from two different categories: something you know, such as a password; something you possess, such as a phone or security key; or something inherent, such as a biometric. The Federal Trade Commission (FTC) explains these categories in its consumer guidance on two-factor authentication.
As an Amazon Associate I earn from qualifying purchases.
With an authenticator app, the password is usually the first proof and access to the enrolled app is the second. A login may ask you to type a code shown in the app or approve a notification. If someone learns your password but does not control the enrolled authenticator, the password alone should not satisfy the account’s sign-in requirement.
For a time-based one-time passcode, the app and account rely on a shared secret and a changing value, commonly tied to time. The app displays the resulting code; the account checks the code when you enter it. This is the general mechanism described by the National Institute of Standards and Technology (NIST), though exact enrollment and sign-in behavior varies by service. See NIST’s SP 800-63B-4 authenticator guidance.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What an authenticator app can do
Generate a one-time code
Many authenticator apps display a passcode that changes periodically. You enter it during sign-in after entering your password. The code is a second check, not a replacement for the password, and you should enter it only on the account’s genuine sign-in page or app.
Send an approval prompt
Some services use an app notification instead of a manually entered code. A prompt may show details about the attempted login, such as the account, device, location, date, or time. Check those details before approving; deny a request you did not initiate. Number matching adds a step in which you enter into the app a number displayed on the login screen. CISA describes this as an improvement to push-based MFA, not the same as phishing-resistant authentication.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How app codes compare with other sign-in methods
| Method | What it offers | Important limitation |
|---|---|---|
| Authenticator-app code | Delivers the code through the enrolled app rather than SMS or the receiving email account. The FTC says this avoids exposure to SIM-card swap attacks and compromise of the email account receiving codes. | A manually entered code is not bound to the specific login session. A phishing site can relay it to the real service, so it is not phishing-proof. |
| App push prompt or number matching | Can be convenient; number matching requires confirming a number shown on the sign-in screen. | Approval prompts are not equivalent to phishing-resistant cryptographic authentication. CISA presents number matching as an improvement while organizations work toward phishing-resistant MFA. |
| SMS or email code | Provides a second step when that is the only method an account offers. | The FTC advises that an app or security key is safer when available; CISA ranks text and email codes below the stronger methods in its cited comparison. |
| Security key or supported passkey | Supported FIDO2/WebAuthn methods can provide phishing-resistant authentication by binding the authentication to the legitimate service. | The account and device must support the method. It is an alternative authenticator, not a required accessory for an app. |
The FTC’s consumer guidance puts the app-code advantage plainly: “But using an app is safer because the passcode isn’t susceptible to a SIM card swap attack or to someone hacking your email.” That advantage concerns how the code is delivered; it does not mean the code cannot be stolen through phishing. NIST explains that a manually entered one-time passcode is not tied to the particular authenticated session and can be relayed by an impostor.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For accounts that support them, security keys and passkeys using FIDO2/WebAuthn can resist phishing because the authentication is bound to the legitimate service. CISA’s comparison places security keys ahead of number-matching app prompts, one-time app codes, biometrics, and text or email codes. These are general guidance rankings, not a guarantee that every implementation has identical security. NIST describes the relevant methods in its authenticator guidance and authenticator examples.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to turn it on for an account
- Sign in to the account and open its settings. Look for a section named Security, Password and Security, Privacy, or something similar.
- Choose Two-factor authentication, Two-step verification, or MFA. CISA’s MFA guidance recommends enabling it wherever an account offers it.
- Select an authenticator app if the account offers that option, then follow the service’s enrollment steps. The flow may ask you to scan a setup code or enter a verification code to confirm enrollment.
- Save any recovery codes the service provides in a secure place. Do not assume every provider offers the same recovery options.
- Sign out or use the service’s test flow, if available, to verify that the app works before relying on it.
Prioritize accounts whose compromise could expose other accounts or sensitive information. CISA highlights email, banking, healthcare, social media, and online-purchase accounts as worthwhile places to check. Its MFA guidance also discusses choosing stronger methods where available.
Changing phones and recovering access
Plan the move before wiping or retiring the phone with your authenticator. NIST advises users of software-based one-time-passcode authenticators to bind the authenticator on the new device and invalidate the old one; a compliant synchronization method may also transfer the secret. Follow the account provider’s own transfer instructions, since apps and services handle enrollment differently.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- While you can still use the old device, check the account’s transfer and recovery instructions.
- Enroll the new device or use the provider’s supported transfer process.
- Verify that you can complete a sign-in with the new authenticator.
- Remove or invalidate the old authenticator when the provider’s process calls for it, then store recovery codes securely if offered.
Keep the recovery email address and phone number listed on important accounts accurate and accessible. The FTC’s account-recovery guidance recommends checking that the listed contact details are yours and that you can access them.
Recommended Free Tools
What an authenticator app does not protect against
- Phishing: A fake sign-in page can capture a password and relay a manually entered app code in real time.
- Compromised or lost devices: Someone with access to an unlocked device or its authenticator may be able to approve sign-ins or view codes, depending on device and app protections.
- Weak recovery processes: If an attacker can take over the account through recovery channels, the second-factor setup may not be enough to keep the account safe.
- Provider implementation: How the service enrolls, checks, and recovers authenticators affects the protection a user actually receives.
Use unique passwords, protect your devices, treat unexpected login prompts as suspicious, and choose a security key or supported passkey when you want stronger phishing resistance and the account offers it. An app is still a useful second step when that is the practical option.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




