Skip to content

Authenticator Apps Arena

Google Authenticator vs Authy

Google Authenticator wins · 99 (27 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    Google Authenticatornone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Authynone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      • ai-native userRun the product headlessly / in CI for automation

        weight 2 · round drawn
        Google Authenticatornone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          Authynone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          • ai-native userConnect an agent via an official MCP server

            weight 3 · round drawn
            Google Authenticatornone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              Authynone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              • ai-native userUse an official CLI

                weight 2 · round drawn
                Google Authenticatornone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  Authynone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  • ai-native userDrive the product through a documented public API

                    weight 3 · round to Authy
                    Google Authenticatornone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                      Twilio's own docs describe an SDK/API for integrating Authy (authy-docs-1, authy-docs-13), but a direct probe of the same page shows the Authy API is deprecated and 'closed to new customers' with 'no programmatic surface remains open to new integrations' (authy-probe-rt-1), meaning an AI-native user cannot actually drive Authy via a documented public API today. Missing for 10: an open, actively maintained public API for new integrations, migration path documentation usable by AI agents, and independent confirmation of working programmatic access.

                      • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                      • [claimed-docs] So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…
                      • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                    • ai-native userIssue scoped/least-privilege API credentials for an agent

                      weight 2 · round drawn
                      Google Authenticatornone0/10

                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        Authynone0/10

                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        • ai-native userBuild against official SDKs

                          weight 2 · round to Authy
                          Google Authenticatornone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                            Twilio's docs claim official SDKs for common web languages to integrate Authy 2FA (authy-docs-1, authy-docs-13), but the same docs page also states the Authy API is closed to new customers and being deprecated in favor of Verify v2, meaning no new AI-native integration can actually be built against it. Missing for 10: evidence of an actively maintained, open-to-new-customers SDK, and any agentic/AI-specific tooling or examples.

                            • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                            • [claimed-docs] So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…
                            • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…

                          Agentic features

                          1. ai-native userSet up automations that run autonomously in the background

                            weight 2 · round drawn
                            Google Authenticatornone0/10

                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              Authynone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              • ai-native userOperate the product with natural-language commands

                                weight 2 · round drawn
                                Google Authenticatornone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Authynone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Api quality

                                  1. ai-native userRely on versioned APIs with a documented deprecation policy

                                    weight 2 · round to Authy
                                    Google Authenticatornone0/10

                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Twilio's docs do carry an explicit deprecation notice for the Authy API, stating it is closed to new customers and pointing to a migration guide toward Verify v2, which is a documented deprecation policy of sorts. However there is no evidence of a broader versioning scheme (e.g., v1/v2 semantics, changelogs, sunset timelines) beyond this one-time 'this API is dying' notice, and it applies to abandonment rather than an ongoing API lifecycle policy. missing for 10: evidence of a formal API versioning scheme, sunset/timeline commitments, changelog practices, and confirmation that Verify (the successor) itself has a documented deprecation policy.

                                      • [claimed-docs] For more information about migration, see Migrating from Authy to Verify for SMS
                                      • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…

                                    Automation depth — how much of the product can run unattendedAutomation depth

                                    How much of the product can run unattended

                                    1. ai-native userPerform bulk operations across many items at once

                                      weight 2 · round drawn
                                      Google Authenticatornone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                        Authynone0/10

                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                        Openness — open source, data portability, and self-hosting storiesOpenness

                                        Open source, data portability, and self-hosting stories

                                        1. ai-native userDo everything through the API that I can do in the UI

                                          weight 2 · round drawn
                                          Google Authenticatornone0/10

                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                            Authynone0/10

                                            Authy's API (the Twilio Authy API) is explicitly deprecated and closed to new customers per Twilio's own docs, and community reports confirm there is no way to export/manage 2FA data programmatically outside the mobile/desktop UI—users describe hacky workarounds just to extract seeds. There is no evidence of a supported API that mirrors the app's UI capabilities (device management, backup, sync, disabling installs, etc.).

                                            • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                            • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                            • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                            • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                            • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                          • ai-native userExport all of my data in open formats and leave

                                            weight 3 · round to Google Authenticator
                                            Google Authenticatordisputedcontradicted3/10

                                            Docs show a QR-code based transfer/export feature for moving codes between devices (docs-3, docs-11, comm-9, comm-18), but this is a proprietary re-import-only format tied to Google Authenticator itself, not an open, portable format usable elsewhere. Community evidence explicitly contradicts any 'open format export' claim: users report Google 'makes it stupendously difficult to just get a simple text export to a file' and that 'Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted,' with data tied to a Google Account that can vanish if banned. Missing for 10: any documented open/standard export format (e.g., plain TOTP URI list, CSV, encrypted portable file), and evidence of true account-independent data portability.

                                            • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                            • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                            • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                            • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…
                                            • [community] Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels s…
                                            • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                            • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                            • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …

                                            Authy provides no official open-format export tool; community reports (authy-comm-3, authy-comm-4, authy-comm-10, authy-comm-18) describe deliberately obstructed migration, requiring hacky Electron debug-mode QR dumps (authy-comm-14) rather than any documented export feature, directly contradicting any implicit claim of open portability. missing for 10: any first-party documentation of a data export feature or open format, evidence of a supported 'leave the platform' workflow, and confirmation that TOTP seeds/secrets can be retrieved without workarounds.

                                            • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                            • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                            • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                            • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                            • [community] I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…
                                            • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                          • ai-native userRead the product's source under an open license

                                            weight 2 · round to Google Authenticator
                                            Google Authenticatorpartialclaimed4/10

                                            The official GitHub repo (google/google-authenticator) publicly hosts source for HOTP/TOTP implementations across platforms and a PAM module, suggesting some source is open, but the evidence never states an explicit open-source license nor confirms the current mobile app's source is included/maintained there. missing for 10: explicit license text (e.g., Apache 2.0) confirmation, evidence the current Android/iOS app source (not just legacy PAM/CLI code) is published, and any independent corroboration of license terms.

                                            • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                            • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                            • [github] Pluggable Authentication Module, aka PAM.
                                            Authynone0/10

                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                            • ai-native userSelf-host the core product

                                              weight 3 · round drawn
                                              Google Authenticatornone0/10

                                              Google Authenticator's core mobile app is closed-source and tied to Google account infrastructure for sync (docs-1, docs-4); the only open-source artifacts on GitHub are OTP-generator libraries and a PAM module, not the actual app users run, and there's no documented way to self-host the core product. Community threads reinforce this, complaining about lack of control over codes and dependency on Google's cloud (comm-6, comm-7, comm-12).

                                              • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                              • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                              • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                              • [github] Pluggable Authentication Module, aka PAM.
                                              • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                              • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                              • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                              Authynone0/10

                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                              Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support

                                              Passkeys in the vault — storage, sign-in, cross-ecosystem sync

                                              Storage

                                              1. everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes

                                                weight 3 · round drawn
                                                Google Authenticatornone0/10

                                                All evidence describes Google Authenticator solely as a TOTP/HOTP code generator with cloud sync of codes; there is no mention of passkey storage or passkey-based sign-in anywhere in the docs, GitHub description, or community discussion.

                                                • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                Authynone0/10

                                                Evidence only shows Twilio's separate Verify API service listing 'Passkeys' as one of many verification factors developers can integrate (authy-docs-2), not that the Authy consumer app itself stores user passkeys or lets users sign into websites/apps with them. All Authy app feature docs (docs-3 through docs-12) describe only TOTP/2FA sync, backups, and device management — no passkey storage or autofill capability is mentioned, and community evidence never discusses passkey sign-in via Authy.

                                                • [claimed-docs] Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.
                                                • [claimed-docs] Sync 2FA across mobile and tablet.
                                                • [claimed-docs] Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.
                                                • [claimed-docs] Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.

                                              Sync

                                              1. power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

                                                weight 2 · round drawn
                                                Google Authenticatornone0/10

                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                  Authynone0/10

                                                  Authy's own docs describe syncing TOTP/2FA tokens across mobile/tablet devices (authy-docs-3, authy-docs-4), not passkeys; the only 'Passkeys' mention is in Twilio Verify API docs, which is a separate developer verification service, not evidence Authy itself stores or syncs WebAuthn passkeys across iOS/Android/Windows/Linux/browsers. No evidence shows Authy functioning as a cross-platform passkey manager.

                                                  • [claimed-docs] Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.
                                                  • [claimed-docs] Sync 2FA across mobile and tablet.
                                                  • [claimed-docs] On any device. Your phone, tablet, even your Apple Watch.
                                                  • [claimed-docs] It's available for iOS, Android, macOS, Windows, and Linux.

                                                Portability — your secrets stay yours — open export, bulk import, device migrationPortability

                                                Your secrets stay yours — open export, bulk import, device migration

                                                Export

                                                1. power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

                                                  weight 3 · round to Google Authenticator
                                                  Google Authenticatordisputedcontradicted3/10

                                                  Docs and community posts confirm a QR-code 'export' exists, but it is a proprietary migration QR built for transferring to another Google Authenticator instance, not an open/readable text format, and users explicitly report Google 'makes it stupendously difficult to just get a simple text export to a file' and that codes cannot be included in backups. This directly contradicts the story's requirement of an open, readable, portable export for switching apps freely. Missing for 10: an official plain-text/otpauth-URI export, documented compatibility with third-party apps, and confirmation the QR format is standardized/open rather than proprietary.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                  • [community] Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels s…
                                                  • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                                  • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                  • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…

                                                  Authy provides no official export feature for TOTP secrets, and community reports (authy-comm-3, authy-comm-4, authy-comm-10, authy-comm-18) confirm the app deliberately blocks migration/export, with users resorting to hacky workarounds like extracting keys via a deprecated Chrome extension debug mode (authy-comm-13, authy-comm-14). Docs never claim an export feature exists — only backup/sync within Authy's own ecosystem (authy-docs-5, authy-docs-3). missing for 10: any documented open/standard export format, first-party export tool, official migration path preserving secrets, and evidence contradicting the well-documented lock-in behavior.

                                                  • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                                  • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                  • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                  • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                                  • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                  • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                  • [community] I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…

                                                Import

                                                1. power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

                                                  weight 2 · round drawn
                                                  Google Authenticatornone0/10

                                                  Evidence only covers transferring/syncing Google Authenticator codes between devices running Google Authenticator itself (QR export/import, Google Account sync), not bulk import of tokens originating in other authenticator apps (e.g., Authy, Microsoft Authenticator). No documentation or community report describes cross-app bulk import.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                  • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                  • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                                  Authynone0/10

                                                  Evidence shows Authy lets users add individual accounts via QR code capture (authy-docs-12) but nothing indicates a bulk import feature that pulls multiple existing tokens/accounts from other authenticator apps at once. Community evidence instead focuses on Authy making it hard to export data out, which is the opposite direction from what the story asks about.

                                                  • [claimed-docs] Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.
                                                  • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                  • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                  • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…

                                                Migration

                                                1. everyday userMoving to a new phone transfers all my tokens in one guided step

                                                  weight 2 · round to Authy
                                                  Google Authenticatordisputedcontradicted4/10

                                                  Google's own docs describe a guided one-step transfer via signing into a Google Account (auto-sync) or scanning a QR export code between old/new devices, which matches the story closely. However, multiple hands-on community reports concretely contradict this working reliably in practice—users report app upgrades wiping all tokens, phone replacements losing TOTP keys despite expecting sync/backup, and account bans erasing synced codes entirely. missing for 10: independent verification that the guided transfer works consistently without data loss, and resolution of documented upgrade/sync failures.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                  • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                  • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.
                                                  • [community] Every time I upgraded to a new iOS 7 beta, it wiped my Google Authenticator account tokens... I can't log in to my CampBX account anymore.
                                                  • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …

                                                  Authy's own docs describe encrypted cloud backup, multi-device sync, and 'add new device with SMS/voice/existing device approval' as the guided path to move 2FA tokens to a new phone, which directly matches this story (authy-docs-3,4,5,10). Community comments about difficulty exporting data are about moving to a *different app*, not the in-ecosystem new-phone transfer, so they don't contradict this specific flow. Missing for 10: independent/hands-on confirmation that the new-phone restore process itself is smooth and single-step (most community friction reports concern cross-app export, not device-to-device transfer).

                                                  • [claimed-docs] Sync 2FA across mobile and tablet.
                                                  • [claimed-docs] On any device. Your phone, tablet, even your Apple Watch.
                                                  • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                                  • [claimed-docs] Add new devices with SMS, voice or existing device approval.
                                                  • [community] I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).

                                                Privacy posture — data-handling and privacy storiesPrivacy posture

                                                Data-handling and privacy stories

                                                1. ai-native userChoose where my data is stored (region/residency)

                                                  weight 2 · round drawn
                                                  Google Authenticatornone0/10

                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                    Authynone0/10

                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                    • ai-native userPrevent my data from being used to train AI models

                                                      weight 3 · round drawn
                                                      Google Authenticatornone0/10

                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                        Authynone0/10

                                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                        • ai-native userControl data retention and deletion

                                                          weight 2 · round to Google Authenticator
                                                          Google Authenticatorpartialcommunity4/10

                                                          Google Authenticator lets users delete individual codes (swipe to delete), edit/reassign codes, and use the app without a Google account (avoiding cloud retention entirely), giving some control over what data is stored and removed. However, there is no documented account-level 'delete all my data' or data-export-to-file control, and community reports describe difficulty exporting/backing up codes and total data loss if a Google account is banned or deleted, undermining full user control over retention. missing for 10: explicit data export/portability controls, account-wide deletion/retention settings, and confirmation that deleting codes removes them from Google's backend, not just the local view.

                                                          • [claimed-docs] To delete an Authenticator code on Android, swipe right on any code to show the delete option.
                                                          • [claimed-docs] When you first open the app, tap Use without an account.
                                                          • [claimed-docs] For additional protection, you can turn on Privacy Screen in Google Authenticator. This requires a verification from your device, like a PIN…
                                                          • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                          • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…
                                                          • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                          Authynone0/10

                                                          No documentation shows Authy giving users control over data retention/export/deletion; instead multiple independent reports describe Twilio deliberately blocking data export ('no export option', 'extremely difficult to export your data') and forcing convoluted workarounds to extract keys, the opposite of user-controlled retention/deletion.

                                                          • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                          • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                          • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                                          • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                          • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                          • [community] I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…
                                                        • ai-native userOpt out of telemetry and usage tracking

                                                          weight 2 · round drawn
                                                          Google Authenticatornone0/10

                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                            Authynone0/10

                                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                            Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture

                                                            How it protects itself — app lock, E2EE design, audits, breach alerting

                                                            App lock

                                                            1. everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

                                                              weight 2 · round drawn
                                                              Google Authenticatorfullclaimed8/10

                                                              Google's own docs describe a 'Privacy Screen' feature requiring PIN, pattern, or biometric verification before the app can be used, directly matching the story. No community evidence contradicts this specific lock-screen feature (complaints focus on sync/backup, not app-lock). Missing for 10: independent hands-on confirmation of the Privacy Screen feature working reliably across devices.

                                                              • [claimed-docs] For additional protection, you can turn on Privacy Screen in Google Authenticator. This requires a verification from your device, like a PIN…

                                                              Twilio's official docs claim TouchID, PIN, and password protection guarding access to 2FA tokens, and a community user independently corroborates using Face ID to lock the entire app on their phone. This directly matches the story of biometric/PIN app-lock preventing exposure on a borrowed phone. Missing for 10: more independent hands-on verification of PIN-specific lock behavior and no detail on lockout/failure edge cases.

                                                              • [claimed-docs] Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.
                                                              • [community] I use Authy with Face ID protecting the entire app on my phone... they'd still need the 2FA codes from my phone [even if password manager co…

                                                            Audits

                                                            1. security engineerThe vendor publishes independent security audits of the app and its sync protocol

                                                              weight 2 · round drawn
                                                              Google Authenticatornone0/10

                                                              No evidence of any independent security audit of the app or its cloud sync protocol; a notable 2023 independent security researcher analysis found the sync data was unencrypted, but no formal published audit exists in the evidence pack, only community complaints about sync/backup reliability and trust concerns.

                                                                Authynone0/10

                                                                The evidence pack contains no vendor claim of independent third-party security audits of the app or its sync protocol; documentation focuses on feature descriptions (SDKs, sync, backup) with no audit reports or security whitepapers cited. Community evidence discusses a data breach and a slow-to-fix vulnerability, but these do not substitute for published audit evidence and there's no vendor claim to dispute.

                                                                Monitoring

                                                                1. power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

                                                                  weight 2 · round drawn
                                                                  Google Authenticatornone0/10

                                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                    Authynone0/10

                                                                    No evidence Authy monitors for breached services, weak/reused/exposed credentials, or provides any security-posture alerts; evidence only covers 2FA sync, backup, device management, and separate breach news about Authy itself (not a feature it offers users).

                                                                    Push

                                                                    1. it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

                                                                      weight 2 · round drawn
                                                                      Google Authenticatornone0/10

                                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                        Authynone0/10

                                                                        Evidence only shows generic Push and Silent Device Approval support (authy-docs-2, authy-docs-15) with no mention of number matching, location context, or admin-enforced MFA policy controls; the Authy API itself is also noted as deprecated for new integrations (authy-probe-rt-1). Missing for 10: any documentation of number matching, location-based risk signals, or admin policy enforcement for push sign-in.

                                                                        • [claimed-docs] Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.
                                                                        • [claimed-docs] Push and Silent Device Approval (iOS, Android, Web)
                                                                        • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…

                                                                      Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting

                                                                      Running it yourself — self-hosted servers, open-source clients

                                                                      Server

                                                                      1. it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter

                                                                        weight 2 · round drawn
                                                                        Google Authenticatornone0/10

                                                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                          Authynone0/10

                                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                          Source

                                                                          1. security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed

                                                                            weight 2 · round to Google Authenticator
                                                                            Google Authenticatorpartialclaimed4/10

                                                                            The GitHub repo (google/google-authenticator) documents open-source implementations of HOTP/TOTP and a PAM module, giving some basis for code review, but the evidence pack has no confirmation that the current shipped Android/iOS apps (which now handle cloud sync of seeds) actually correspond to this repo or receive active community review. missing for 10: evidence that the live mobile app source matches the published repo, evidence of active maintenance/community audits of the seed-handling code, and independent confirmation of code correctness.

                                                                            • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                            • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                            • [github] Pluggable Authentication Module, aka PAM.
                                                                            Authynone0/10

                                                                            There is no evidence Authy's client apps are open source; evidence instead shows closed, proprietary apps with deliberately obstructed export/migration paths and hacky reverse-engineering required to extract seeds. This directly contradicts the premise of community-reviewable open-source code handling seeds.

                                                                            • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                                            • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                                            • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                                                            • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                            • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…

                                                                          Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces

                                                                          Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

                                                                          Automation

                                                                          1. ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

                                                                            weight 2 · round drawn
                                                                            Google Authenticatornone0/10

                                                                            Google Authenticator is a mobile/PAM app with no documented CLI or API for programmatic TOTP retrieval; evidence only covers manual app UI actions (sync, QR export, editing codes) and community complaints about backup/sync issues, none of which show agent-accessible code fetching.

                                                                              Authynone0/10

                                                                              Authy is a consumer authenticator app; there is no documented CLI/API for a user or agent to programmatically fetch their own current TOTP code, and Twilio's docs confirm the Authy API is deprecated and closed to new customers with no successor for this use case. Community evidence further shows Authy intentionally blocks exporting secrets/codes, requiring hacky workarounds (deprecated Chrome extension, debug-mode Electron hacks) rather than any supported programmatic access.

                                                                              • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                              • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                                              • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                                              • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                              • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                                            • ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

                                                                              weight 1 · round drawn
                                                                              Google Authenticatornone0/10

                                                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                Authynone0/10

                                                                                No evidence Authy offers any local programmatic endpoint for agents to query codes/secrets; its API is closed to new customers and deprecated, and community reports describe the vault as deliberately hard to export via any means other than hacky manual extraction.

                                                                                • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                                • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                                • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                                                • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…

                                                                              Browser

                                                                              1. everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

                                                                                weight 2 · round drawn
                                                                                Google Authenticatornone0/10

                                                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                  Authynone0/10

                                                                                  Evidence pack shows no current Authy browser extension for autofilling TOTP or passkeys; the only extension mentioned is a deprecated Chrome extension used via hacky workarounds to extract keys, not autofill. Authy's own product is a mobile/desktop authenticator app, and passkey support referenced is for Twilio Verify (a separate API product), not the Authy app/extension.

                                                                                  • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                                  • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                                                  • [claimed-docs] Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.

                                                                                Desktop

                                                                                1. power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile

                                                                                  weight 2 · round to Authy
                                                                                  Google Authenticatornone0/10

                                                                                  No evidence of a desktop application; Google Authenticator is documented and discussed only as a mobile app with QR-based transfer/sync between phones, not a desktop client or vault.

                                                                                  • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                                  • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.

                                                                                  Twilio's docs list Authy as available on macOS, Windows, and Linux, suggesting first-class desktop apps, but hands-on community reports concretely contradict this, stating Authy is 'EOL'ing desktop apps' with 'near immediate deprecation' and no export path, leaving the desktop surface unreliable for power users. Missing for 10: no evidence of continued desktop app support with vault/code access, no independent confirmation the desktop client remains functional or maintained post-EOL announcement.

                                                                                  • [claimed-docs] It's available for iOS, Android, macOS, Windows, and Linux.
                                                                                  • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                                                                  • [community] I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…

                                                                                Watch

                                                                                1. everyday userRead my codes from my smartwatch without pulling out my phone

                                                                                  weight 1 · round to Authy
                                                                                  Google Authenticatornone0/10

                                                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                    Authy's own marketing page explicitly claims support on 'your phone, tablet, even your Apple Watch,' which directly matches the smartwatch-reading story, but this is a single first-party claim with no independent or hands-on confirmation of watch functionality (e.g., no community mention of using the watch app), and the API deprecation notice signals the product line is winding down. Missing for 10: independent/hands-on verification of the Apple Watch experience, detail on Wear OS or other smartwatch support, and confirmation the feature is still maintained post-deprecation.

                                                                                    • [claimed-docs] On any device. Your phone, tablet, even your Apple Watch.
                                                                                    • [claimed-docs] Sync 2FA across mobile and tablet.
                                                                                    • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…

                                                                                  Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup

                                                                                  Not losing your accounts — encrypted backup, multi-device sync, recovery

                                                                                  Backup

                                                                                  1. security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

                                                                                    weight 3 · round to Authy
                                                                                    Google Authenticatornone0/10

                                                                                    Docs only describe syncing codes via a Google Account (google-authenticator-docs-1,4) with no mention of end-to-end encryption or a vendor-blind key, and community reports explicitly note that storing codes in 'google cloud doesn't satisfy me' and that losing access to the Google account means losing all 2FA data, implying no such E2E encryption exists.

                                                                                    • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                    • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                    • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                                                    • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                    • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …

                                                                                    Authy's marketing page states backups are encrypted and 'only decrypt on the devices using a password only you know' (authy-docs-5), implying a vendor-can't-decrypt design, but there is no technical documentation of the encryption algorithm, key derivation, or threat model, and no independent audit confirming the vendor truly never holds the key. Community reports focus on account-takeover via device-add (authy-comm-15) and painful data export (authy-comm-13/14), not on breaking the underlying backup encryption, so this doesn't rise to a concrete dispute of the encryption claim itself. Missing for 10: a detailed whitepaper/spec of the E2E encryption scheme, key management details, and independent security audit or crypto review corroborating the zero-knowledge claim.

                                                                                    • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                                                                    • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                                    • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                                                    • [community] The Twilio exploit allowed the hackers to add a new device to existing Authy accounts. This allowed them to sync the keys between devices wi…

                                                                                  Multi device

                                                                                  1. everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

                                                                                    weight 2 · round to Google Authenticator
                                                                                    Google Authenticatorpartialcommunity5/10

                                                                                    Google's docs confirm automatic cross-device sync via Google Account sign-in, works offline, and supports multiple accounts (docs-1,4,5,10), but Authenticator is a mobile-only app with no native desktop/computer client, so the 'computer' leg of the story is unsupported. Community reports also cite historical sync/backup failures and account-loss risk tying codes to a Google Account (comm-1, comm-7, comm-12, comm-13), showing real caveats even if not disproving the current sync feature outright. Missing for 10: a computer/desktop client, independent hands-on confirmation the modern sync feature works reliably across all device types without data loss.

                                                                                    • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                    • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                    • [claimed-docs] Authenticator can sync codes for multiple Google Accounts and display them from the same mobile device.
                                                                                    • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                    • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                                                    • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                    • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                                                    • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.

                                                                                    Docs and community confirm sync across phone/tablet (and even Apple Watch) works well and is a headline feature (authy-docs-3, authy-docs-4, authy-docs-16, authy-comm-1), but the 'computer' part of the story is directly contradicted: community reports Authy EOL'd its desktop apps, breaking the phone/tablet/computer parity the docs still describe (authy-comm-10, authy-comm-18). Missing for 10: confirmation that desktop/computer sync still functions today, and resolution of the desktop deprecation vs docs claim.

                                                                                    • [claimed-docs] Sync 2FA across mobile and tablet.
                                                                                    • [claimed-docs] On any device. Your phone, tablet, even your Apple Watch.
                                                                                    • [claimed-docs] It's available for iOS, Android, macOS, Windows, and Linux.
                                                                                    • [community] I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).
                                                                                    • [community] They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…
                                                                                    • [community] I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…

                                                                                  Recovery

                                                                                  1. everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

                                                                                    weight 3 · round to Authy
                                                                                    Google Authenticatordisputedcontradicted5/10

                                                                                    Google's own docs describe two documented recovery paths — signing into your Google Account to auto-sync codes across devices, or scanning a QR-code export to transfer codes to a new device (google-authenticator-docs-1/3/4/11) — which is exactly the story's ask. However, multiple hands-on community reports concretely contradict reliability of this recovery: users report app upgrades wiping all tokens with no recovery (comm-13, comm-14), phone backups explicitly excluding Authenticator data (comm-1, comm-8), and losing all codes permanently if the tied Google Account is banned/deleted (comm-7, comm-12). Missing for 10: independent verification that account-sync recovery works consistently across real device-loss scenarios, and resolution of the backup-exclusion/account-ban failure modes.

                                                                                    • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                    • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                                    • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                    • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                                                    • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                                                    • [community] Does that mean one can use adb to backup Google Authenticator's data as well? Last time I tried, the app data was explicitly marked as exclu…
                                                                                    • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.
                                                                                    • [community] Every time I upgraded to a new iOS 7 beta, it wiped my Google Authenticator account tokens... I can't log in to my CampBX account anymore.
                                                                                    • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                    • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …

                                                                                    Authy's official docs describe an encrypted backup feature that restores 2FA tokens to a new device using a user-known password, plus multi-device sync and device management (authy-docs-3,4,5,8,10), and a community user confirms this recovery path works in practice after phone loss/SIM replacement (authy-comm-19). Some community friction exists around exporting data to competing apps, but that's a separate migration-away concern, not evidence the phone-loss recovery path itself fails. Missing for 10: a detailed first-party step-by-step restore walkthrough, and broader independent corroboration beyond a single community anecdote.

                                                                                    • [claimed-docs] Sync 2FA across mobile and tablet.
                                                                                    • [claimed-docs] On any device. Your phone, tablet, even your Apple Watch.
                                                                                    • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                                                                    • [claimed-docs] View information, rename, and remove lost/stolen devices.
                                                                                    • [claimed-docs] Add new devices with SMS, voice or existing device approval.
                                                                                    • [community] I've been using Authy as a backup for 1Password's 2FA since in a worst-case scenario I can get a replacement SIM card and get back into my 1…

                                                                                  Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin

                                                                                  Shared and managed use — shared vaults, org policies, programmatic provisioning

                                                                                  Automation

                                                                                  1. ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

                                                                                    weight 2 · round to Authy
                                                                                    Google Authenticatornone0/10

                                                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                      Docs mention an SDK for 'the Authy API' to integrate 2FA, but Twilio's own docs page (probe) states the Authy API is closed to new customers and being deprecated with no new integrations, and multiple community reports confirm there is no supported way to programmatically seed, export, or update vault entries — users describe extreme difficulty or hacky workarounds to even extract secrets. This directly contradicts any claim of a documented programmatic surface for agent-driven vault creation/updates. Missing for 10: any current API/SDK for creating or updating TOTP vault entries, official export/import endpoints, and first-party agent integration examples.

                                                                                      • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                                                                                      • [claimed-docs] So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…
                                                                                      • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                                      • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                                                      • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…
                                                                                      • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…

                                                                                    Policy

                                                                                    1. it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

                                                                                      weight 1 · round drawn
                                                                                      Google Authenticatornone0/10

                                                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                        Authynone0/10

                                                                                        Authy's evidence pack shows only consumer-facing features (per-device PIN/TouchID lock, backup password, device management) with no mention of any organization/admin console, centralized policy enforcement, or IT-admin controls across a team of users. The product is also being deprecated in favor of Verify, with no admin management surface described anywhere.

                                                                                        • [claimed-docs] Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.
                                                                                        • [claimed-docs] View information, rename, and remove lost/stolen devices.
                                                                                        • [claimed-docs] Disable future Authy app installations for improved security.
                                                                                        • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…

                                                                                      Sharing

                                                                                      1. it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control

                                                                                        weight 2 · round drawn
                                                                                        Google Authenticatornone0/10

                                                                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                          Authynone0/10

                                                                                          Authy is a personal authenticator app with no evidence of shared vaults, collections, or per-member access control for team/admin management; evidence only covers individual multi-device sync and backup features. Community evidence even highlights difficulty exporting/sharing data at all, reinforcing the lack of team-sharing capability.

                                                                                          • [claimed-docs] Sync 2FA across mobile and tablet.
                                                                                          • [claimed-docs] Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.
                                                                                          • [community] Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
                                                                                          • [community] I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…

                                                                                        Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core

                                                                                        The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

                                                                                        Enrollment

                                                                                        1. everyday userScan a QR code and immediately start generating TOTP codes for a new account

                                                                                          weight 3 · round to Google Authenticator
                                                                                          Google Authenticatorfullclaimed8/10

                                                                                          Docs and GitHub evidence confirm the app scans QR codes to add accounts and generates RFC 6238 TOTP codes, including offline (docs-3, docs-10, gh-1). Community feedback criticizes backup/sync/loss issues, not the basic scan-and-generate flow, so the core story is undisputed. Missing for 10: independent hands-on confirmation of the exact scan-to-first-code experience and no first-party UX walkthrough beyond support docs.

                                                                                          • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                                          • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                          • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                                          • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.

                                                                                          Authy's own product page states it can capture 2FA QR codes from major providers and lists TOTP as a supported authentication method, directly matching the scan-and-generate story, and community comments confirm ongoing everyday use of the app for this purpose. Missing for 10: a first-person hands-on account of the exact scan-to-code flow and more detailed onboarding documentation beyond the marketing feature list.

                                                                                          • [claimed-docs] Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.
                                                                                          • [claimed-docs] TOTP (Authenticator Apps)
                                                                                          • [community] I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).
                                                                                          • [community] I've been using Authy as a backup for 1Password's 2FA since in a worst-case scenario I can get a replacement SIM card and get back into my 1…

                                                                                        Offline

                                                                                        1. power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes

                                                                                          weight 2 · round to Google Authenticator
                                                                                          Google Authenticatorfullclaimed8/10

                                                                                          Docs explicitly state you can 'Use without an account' at setup and that codes generate 'without an internet connection or mobile service,' confirming fully offline, account-free TOTP generation (core RFC 6238 implementation per GitHub). Community discussion focuses on backup/sync/account-loss risks, not on offline generation failing, so no contradiction of this specific axis. Missing for 10: independent hands-on confirmation specifically testing offline-without-account code generation.

                                                                                          • [claimed-docs] When you first open the app, tap Use without an account.
                                                                                          • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                          • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…

                                                                                          Authy's own docs claim codes can be viewed without internet ('access secured websites without internet access on your phone'), but the product fundamentally requires creating a Twilio/Authy account tied to a phone number before any TOTP codes can be generated or viewed, and codes are further gated behind an app password — directly contradicting the 'no vendor account required' part of the story. Community evidence confirms this account-centric architecture (phone-number-as-username, multi-device sync tied to account, extraction of underlying seeds required hacky workarounds via a deprecated debug mode rather than a supported offline export).

                                                                                          • [claimed-docs] You can still access secured websites without internet access on your phone.
                                                                                          • [community] I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).
                                                                                          • [community] This doesn't scare me because in Authy you also set a password which without you cannot access the codes. The phone number here just acts as…
                                                                                          • [community] After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…
                                                                                          • [community] Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…
                                                                                          • [community] services with Authy-integrated MFA (like Twitch) are 'managed' by Authy so it can regenerate the secret on the fly; your previously extracte…

                                                                                        Organization

                                                                                        1. power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

                                                                                          weight 2 · round drawn
                                                                                          Google Authenticatornone0/10

                                                                                          Evidence only shows basic manual reordering (drag-to-reorder), swipe-to-edit/delete, and username/account editing — there is no mention of search, folders/groups, or service icons for organizing many tokens. missing for 10: search functionality, folder/group organization, service icons, any at-scale organization feature for dozens of tokens.

                                                                                          • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option.
                                                                                          • [claimed-docs] To organize your Authenticator codes, touch and hold any code, then drag to reorder to a desired location.
                                                                                          • [claimed-docs] To delete an Authenticator code on Android, swipe right on any code to show the delete option.
                                                                                          • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option. You can update the username for the code or chan…
                                                                                          Authynone0/10

                                                                                          Evidence shows only basic token/QR capture (service icons implied) with no mention of search or folder/group organization; a community user explicitly complains 'can't we please have alphabetization?' indicating the app lacks even simple sorting, let alone search/folders for power users managing dozens of tokens.

                                                                                          • [claimed-docs] Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.
                                                                                          • [community] My guess is that most of the people who worked on Authy have fallen by the wayside after the Twilio acquisition. It's annoying every time I …

                                                                                        Variants

                                                                                        1. power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

                                                                                          weight 2 · round to Google Authenticator
                                                                                          Google Authenticatorpartialclaimed3/10

                                                                                          The GitHub docs confirm the underlying library supports HOTP (RFC 4226) and TOTP (RFC 6238) algorithms, giving some basis for HOTP counter support, but there is no evidence anywhere in the pack that the consumer app exposes Steam Guard mode, custom periods, or custom digit lengths — the mobile app UI evidence only shows scanning QR codes, editing username, and deleting entries. missing for 10: Steam Guard token support, custom period configuration, custom digit-length configuration, and any UI/setting for manual HOTP counter entry.

                                                                                          • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                                          • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                                          • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option.
                                                                                          Authynone0/10

                                                                                          No evidence anywhere in the pack mentions Steam Guard support, HOTP counter-based tokens, or custom period/digit configurations; documentation only references standard TOTP and QR-code capture from mainstream services. Absence of evidence for this applicable power-user axis yields 'none'.

                                                                                          Not comparable on these axes

                                                                                          1. ai-native userPlug MCP servers into this product so it can use their tools

                                                                                            weight 3 · not comparable
                                                                                            Google Authenticatorn/a

                                                                                            Google Authenticator is a simple OTP code generator app with no plugin/tool ecosystem or agent-integration capability; MCP server integration is a category error for this product type.

                                                                                              Authyn/a

                                                                                              Authy is a 2FA/authenticator app, not an agentic AI product or platform with a tool-use ecosystem; plugging MCP servers into it for tool use is a category error for this product type.

                                                                                              • ai-native userSubscribe to events via webhooks

                                                                                                weight 2 · not comparable
                                                                                                Google Authenticatorn/a

                                                                                                Google Authenticator is a standalone TOTP/HOTP code-generator app with no API or event system; webhook subscriptions are a wrong axis for this product category.

                                                                                                  Authynone0/10

                                                                                                  No evidence of any webhook subscription capability in Authy's docs or community reports; the product's API is deprecated with no new programmatic integrations mentioned. This is a fair axis for an authentication/API platform, but no support is documented.

                                                                                                  • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                                                                                                  • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                                                • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                                                                  weight 2 · not comparable
                                                                                                  Google Authenticatorn/a

                                                                                                  Google Authenticator is a single-purpose OTP code generator with no data analytics or AI-generated insights feature; this axis is a category error for this product type.

                                                                                                    Authyn/a

                                                                                                    Authy is a 2FA/authenticator product; AI-generated insights or suggestions from user data is a category mismatch, not something a 2FA app category would ship.

                                                                                                    • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                                                                      weight 3 · not comparable
                                                                                                      Google Authenticatorn/a

                                                                                                      Google Authenticator is a 2FA code generator utility, not an AI-agent or assistant platform; delegating tasks to a built-in AI assistant is outside its product category entirely.

                                                                                                        Authyn/a

                                                                                                        Authy is a 2FA/authentication app; delegating tasks to a built-in AI assistant is a wrong-axis question for this product category, with no evidence it ships any AI assistant feature.

                                                                                                        • ai-native userExplore an interactive API reference with runnable examples

                                                                                                          weight 2 · not comparable
                                                                                                          Google Authenticatorn/a

                                                                                                          Google Authenticator is a mobile 2FA code-generator app, not a developer platform or API product; an interactive API reference with runnable examples is a category mismatch for this kind of product.

                                                                                                            Authynone0/10

                                                                                                            No evidence of an interactive API reference with runnable examples for Authy; docs pack only describes SDKs and app features, and the Authy API itself is now closed/deprecated in favor of Verify, with no mention of interactive docs or runnable code samples.

                                                                                                            • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                                                                                                            • [claimed-docs] So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…
                                                                                                            • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                                                          • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                                                                                                            weight 2 · not comparable
                                                                                                            Google Authenticatorn/a

                                                                                                            Google Authenticator is a consumer mobile 2FA app with no programmatic API surface; a machine-readable API spec is not a relevant axis for this product category.

                                                                                                              Authynone0/10

                                                                                                              Evidence only mentions SDKs and API docs (Verify/Authy), with no mention of a downloadable OpenAPI/Swagger spec or other machine-readable API definition; the Authy API is also noted as deprecated with no new integrations possible.

                                                                                                              • [claimed-docs] we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.
                                                                                                              • [claimed-docs] So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…
                                                                                                              • [probe] PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…
                                                                                                            • ai-native userTest against a sandbox environment without touching production data

                                                                                                              weight 1 · not comparable
                                                                                                              Google Authenticatorn/a

                                                                                                              Google Authenticator is a simple TOTP/HOTP code generator app, not a developer platform or API service with a sandbox/testing environment concept; this axis is a category error for this product type.

                                                                                                                Authyn/a

                                                                                                                Authy is a consumer 2FA app/service, not an AI-native developer tool with sandbox/test environments for agentic testing; no evidence pack content addresses sandbox vs production environments for AI agent testing, making this axis a category error for this product.

                                                                                                                • ai-native userDefine rules that trigger actions automatically on events

                                                                                                                  weight 3 · not comparable
                                                                                                                  Google Authenticatorn/a

                                                                                                                  Google Authenticator is a static OTP-code generator app with no rules engine, event triggers, or automation/workflow capability; this axis is a category error for this product type.

                                                                                                                    Authyn/a

                                                                                                                    Authy is a 2FA authenticator app/service, not an automation or workflow-rules platform; defining event-triggered rules is outside its product category and there is no evidence of such a feature.

                                                                                                                    • ai-native userSchedule recurring jobs or workflows

                                                                                                                      weight 2 · not comparable
                                                                                                                      Google Authenticatorn/a

                                                                                                                      Google Authenticator is a 2FA code generator app with no workflow/job-scheduling capability; scheduling recurring automation is outside its product category entirely.

                                                                                                                        Authyn/a

                                                                                                                        Authy is a 2FA/authenticator app; scheduling recurring jobs or workflows is not a relevant capability for this product category.

                                                                                                                        • ai-native userVersion, review, and roll back my automations

                                                                                                                          weight 1 · not comparable
                                                                                                                          Google Authenticatorn/a

                                                                                                                          Google Authenticator is a 2FA code generator, not an automation/workflow tool; versioning, reviewing, or rolling back automations is not a category concern for this product.

                                                                                                                            Authyn/a

                                                                                                                            Authy is a 2FA/authentication app, not an automation-building tool; versioning, reviewing, and rolling back 'automations' is not a concept that applies to this product category.