Back up your Google Authenticator codes
If the phone with your authenticator is lost or broken, the codes go with it — and every account with two-step login stays locked until you recover it, one by one. Keyhold keeps the same codes in an encrypted vault, with a copy in your own Google Drive.
Move the codes
- Install Keyhold — on Android from Google Play, on Windows from GitHub — and create a vault with a master password. Print the recovery sheet.
- In Google Authenticator open the menu → Transfer accounts → Export accounts, pick the accounts and continue. It shows one or more QR codes.
- Scan them with Keyhold. Keyhold cannot point a camera at the screen of its own phone, so use a second device: Keyhold on another phone (+ → Scan a QR code → Scan with the camera), or Keyhold on your computer with a photo of the QR code (Open an image). Google Authenticator may not allow screenshots of that screen.
- Choose Save all. Every account becomes its own code in the vault.
The codes keep working in Google Authenticator too — exporting switches nothing off. Remove them there only when you are ready.
Keep the backup
- Google Drive: turn it on in Keyhold's settings. The vault is encrypted on the device before it is sent, in a visible folder named Keyhold, and Keyhold can reach only the files it made itself.
- Folders or your own server: every change can also be copied there, in seven copies from the latest to one about a year old.
- The recovery key on the printed sheet opens the vault even if the master password is forgotten.
Other authenticators
Keyhold also imports from Aegis, 2FAS, andOTP and FreeOTP+. Microsoft Authenticator cannot export its codes — turn two-step login off and on again on each site and scan the new code into Keyhold.