Keep the old phone working until every important account accepts a code from the new phone. Use the authenticator app’s supported sync or export tool, protect any transfer QR code, and confirm backup methods before erasing or trading in the old device.
An authenticator app does not always behave like an ordinary app backup. The visible account names may transfer while one service still expects an older secret, or the codes may remain only on the old device if cloud synchronization was never enabled. Treat the move as an account-security change, not just a phone setup task.
Make an account inventory first
Open the authenticator app on the old phone and list the services it protects. Record only the service and account name—never copy current six-digit codes or secret setup keys into an unprotected note. Pay special attention to email, password managers, banking, cloud storage, social media, work accounts and the account used to locate or erase the phone.
For each critical service, confirm at least one independent recovery method. That might be a printed backup-code set, a hardware security key, a trusted device or a recovery process maintained by the service. SMS can help in some situations, but it should not be the only fallback for high-value accounts because a lost SIM or number-porting problem can block it.
Transfer while both phones are available
- Update the authenticator app from its official store page on both devices.
- Install the same official app on the new phone and secure the phone with a strong screen lock.
- Use the app’s documented synchronization, export or transfer option. Never upload a transfer QR code to a website or send it through chat.
- Keep the old phone offline but intact after the transfer; do not erase it yet.
- Check that the new phone’s date, time and time zone are set automatically.
Google Authenticator can synchronize codes when signed in to a Google Account. It also supports a manual transfer: the old device displays one or more export QR codes and the new device imports them. Other authenticator apps use different backup models, so follow the app developer’s documentation rather than assuming the Google steps apply.
Test accounts without locking yourself out
Start with a lower-risk account. Open its security settings in a browser or trusted device, generate a new login challenge, and enter the code shown on the new phone. A code changing every 30 seconds is normal; repeated rejection usually points to the wrong account entry, incorrect device time or a transfer that did not complete.
Test every important service individually. Do not sign out of all trusted sessions at once. When a service offers its own “change authenticator” workflow, use it: scan the newly issued QR code with the new phone, verify a code, then remove the old authenticator only after the service confirms the change.
Erase the old phone only after verification
Wait until the new phone has worked for normal sign-ins and you have confirmed recovery options. Then remove the old device from relevant account device lists, sign out where appropriate, and use the manufacturer’s factory-reset procedure. If the old phone was lost or stolen, remotely lock or erase it and review recent sign-in activity immediately.
Before changing phones or SIMs, make sure your recovery number remains active and registered correctly with your carrier. Never give an OTP, backup code, authenticator code or transfer QR image to a caller claiming to be from a bank, e-wallet, carrier or support team.
Official guidance
Reviewed by PHWhy Editorial on August 19, 2026. Menu names vary by authenticator app and service; use the provider’s current security instructions.



