Skip to content

Authenticator Apps Arena

Google Authenticator vs Microsoft Authenticator

Google Authenticator wins · 85 (32 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    Google Authenticatornone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Microsoft Authenticatornone0/10

      Probes show no llms.txt, no markdown docs, and no OpenAPI spec available for Microsoft Authenticator's documentation site; there is no evidence of agent-oriented documentation format.

      • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
      • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
      • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
    • ai-native userRun the product headlessly / in CI for automation

      weight 2 · round drawn
      Google Authenticatornone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Microsoft Authenticatornone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        • ai-native userConnect an agent via an official MCP server

          weight 3 · round drawn
          Google Authenticatornone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            Microsoft Authenticatornone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            • ai-native userUse an official CLI

              weight 2 · round drawn
              Google Authenticatornone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Microsoft Authenticatornone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                • ai-native userDrive the product through a documented public API

                  weight 3 · round drawn
                  Google Authenticatornone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Microsoft Authenticatornone0/10

                    Microsoft Authenticator is a consumer mobile app with no evidence of a documented public API for programmatic/AI-driven control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404s.

                    • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                    • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                    • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                  • ai-native userIssue scoped/least-privilege API credentials for an agent

                    weight 2 · round drawn
                    Google Authenticatornone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                      Microsoft Authenticatornone0/10

                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                      • ai-native userBuild against official SDKs

                        weight 2 · round drawn
                        Google Authenticatornone0/10

                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          Microsoft Authenticatornone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          Agentic features

                          1. ai-native userSet up automations that run autonomously in the background

                            weight 2 · round drawn
                            Google Authenticatornone0/10

                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              Microsoft Authenticatornone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              • ai-native userOperate the product with natural-language commands

                                weight 2 · round drawn
                                Google Authenticatornone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Microsoft Authenticatornone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Api quality

                                  1. ai-native userRely on versioned APIs with a documented deprecation policy

                                    weight 2 · round drawn
                                    Google Authenticatornone0/10

                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Microsoft Authenticatornone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Automation depth — how much of the product can run unattendedAutomation depth

                                      How much of the product can run unattended

                                      1. ai-native userPerform bulk operations across many items at once

                                        weight 2 · round drawn
                                        Google Authenticatornone0/10

                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                          Microsoft Authenticatornone0/10

                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                          Openness — open source, data portability, and self-hosting storiesOpenness

                                          Open source, data portability, and self-hosting stories

                                          1. ai-native userDo everything through the API that I can do in the UI

                                            weight 2 · round drawn
                                            Google Authenticatornone0/10

                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                              Microsoft Authenticatornone0/10

                                              Microsoft Authenticator is a consumer mobile app with no evidence of any public API for programmatic control of authentication actions; probes for API/docs endpoints all 404. No evidence supports API parity with UI functionality.

                                              • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                              • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                              • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                            • ai-native userExport all of my data in open formats and leave

                                              weight 3 · round to Microsoft Authenticator
                                              Google Authenticatordisputedcontradicted3/10

                                              Docs show a QR-code based transfer/export feature for moving codes between devices (docs-3, docs-11, comm-9, comm-18), but this is a proprietary re-import-only format tied to Google Authenticator itself, not an open, portable format usable elsewhere. Community evidence explicitly contradicts any 'open format export' claim: users report Google 'makes it stupendously difficult to just get a simple text export to a file' and that 'Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted,' with data tied to a Google Account that can vanish if banned. Missing for 10: any documented open/standard export format (e.g., plain TOTP URI list, CSV, encrypted portable file), and evidence of true account-independent data portability.

                                              • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                              • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                              • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                              • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…
                                              • [community] Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels s…
                                              • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                              • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                              • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                              Microsoft Authenticatorpartialcommunity3/10

                                              Microsoft documents an 'Export Passwords' feature for autofill data, but this covers only saved passwords, not the OTP/account seeds this app is centrally used for; TOTP/account data is only preserved via proprietary encrypted 'Cloud Backup' tied to a Microsoft account, not an open, portable format. Community evidence goes further, describing non-standard QR codes that other TOTP clients reject and users switching to open-source alternatives (Aegis) specifically because Authenticator lacks true open-format export/backup. missing for 10: open-format export of TOTP secrets/accounts, documented data-portability/leave workflow, independent confirmation that exported data works outside Microsoft's ecosystem.

                                              • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                              • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                              • [claimed-docs] Scroll down to the Autofill section and select Export Passwords... Import your passwords.
                                              • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                              • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                            • ai-native userRead the product's source under an open license

                                              weight 2 · round to Google Authenticator
                                              Google Authenticatorpartialclaimed4/10

                                              The official GitHub repo (google/google-authenticator) publicly hosts source for HOTP/TOTP implementations across platforms and a PAM module, suggesting some source is open, but the evidence never states an explicit open-source license nor confirms the current mobile app's source is included/maintained there. missing for 10: explicit license text (e.g., Apache 2.0) confirmation, evidence the current Android/iOS app source (not just legacy PAM/CLI code) is published, and any independent corroboration of license terms.

                                              • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                              • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                              • [github] Pluggable Authentication Module, aka PAM.
                                              Microsoft Authenticatornone0/10

                                              Microsoft Authenticator is closed-source proprietary software; no evidence of any open-license source availability, and probes for docs/API artifacts also failed.

                                              • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                              • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                              • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                            • ai-native userSelf-host the core product

                                              weight 3 · round drawn
                                              Google Authenticatornone0/10

                                              Google Authenticator's core mobile app is closed-source and tied to Google account infrastructure for sync (docs-1, docs-4); the only open-source artifacts on GitHub are OTP-generator libraries and a PAM module, not the actual app users run, and there's no documented way to self-host the core product. Community threads reinforce this, complaining about lack of control over codes and dependency on Google's cloud (comm-6, comm-7, comm-12).

                                              • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                              • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                              • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                              • [github] Pluggable Authentication Module, aka PAM.
                                              • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                              • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                              • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                              Microsoft Authenticatornone0/10

                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                              Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support

                                              Passkeys in the vault — storage, sign-in, cross-ecosystem sync

                                              Storage

                                              1. everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes

                                                weight 3 · round drawn
                                                Google Authenticatornone0/10

                                                All evidence describes Google Authenticator solely as a TOTP/HOTP code generator with cloud sync of codes; there is no mention of passkey storage or passkey-based sign-in anywhere in the docs, GitHub description, or community discussion.

                                                • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                Microsoft Authenticatornone0/10

                                                The evidence pack describes password-based sign-in removal, TOTP codes, push notifications, and password autofill/export, but nowhere mentions passkeys (FIDO2/WebAuthn credentials) being stored or used to sign into websites/apps. Missing for 10: any documentation of passkey creation, storage, or sign-in via Authenticator, and any independent confirmation of passkey support.

                                                • [claimed-docs] Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…
                                                • [claimed-docs] As the only way to sign in - just tap an approval on your phone to sign in. This is called going passwordless.
                                                • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…

                                              Sync

                                              1. power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

                                                weight 2 · round drawn
                                                Google Authenticatornone0/10

                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                  Microsoft Authenticatornone0/10

                                                  The evidence pack covers Microsoft Authenticator's TOTP codes, push-notification MFA, cloud backup, and password autofill (now being discontinued), but contains no mention of passkey creation, storage, or cross-platform/cross-vendor passkey syncing across iOS, Android, Windows, Linux, or browsers. Passkey sync is a fair axis for an authenticator app, but nothing in the pack demonstrates it.

                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                  • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…

                                                Portability — your secrets stay yours — open export, bulk import, device migrationPortability

                                                Your secrets stay yours — open export, bulk import, device migration

                                                Export

                                                1. power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

                                                  weight 3 · round to Google Authenticator
                                                  Google Authenticatordisputedcontradicted3/10

                                                  Docs and community posts confirm a QR-code 'export' exists, but it is a proprietary migration QR built for transferring to another Google Authenticator instance, not an open/readable text format, and users explicitly report Google 'makes it stupendously difficult to just get a simple text export to a file' and that codes cannot be included in backups. This directly contradicts the story's requirement of an open, readable, portable export for switching apps freely. Missing for 10: an official plain-text/otpauth-URI export, documented compatibility with third-party apps, and confirmation the QR format is standardized/open rather than proprietary.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                  • [community] Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels s…
                                                  • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                                  • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                  • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…
                                                  Microsoft Authenticatornone0/10

                                                  Docs describe cloud backup/restore and password export/import, but none of this covers exporting TOTP secrets in an open format for use in another app; community evidence explicitly states Microsoft issues non-standard QR codes that other TOTP clients reject, indicating deliberate lock-in rather than portability.

                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                  • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                                  • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                  • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…

                                                Import

                                                1. power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

                                                  weight 2 · round drawn
                                                  Google Authenticatornone0/10

                                                  Evidence only covers transferring/syncing Google Authenticator codes between devices running Google Authenticator itself (QR export/import, Google Account sync), not bulk import of tokens originating in other authenticator apps (e.g., Authy, Microsoft Authenticator). No documentation or community report describes cross-app bulk import.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                  • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                  • [community] Google Authenticator has a feature to allow export of all saved codes into one QR code for re-import into Google Authenticator running on an…
                                                  Microsoft Authenticatornone0/10

                                                  The evidence pack only covers backing up/restoring Authenticator's own accounts via cloud backup, exporting passwords, and standard account setup via QR/manual entry — there is no mention of any bulk-import feature for pulling tokens from other authenticator apps (e.g., Google Authenticator, Aegis) into Microsoft Authenticator. Community evidence even suggests the opposite direction problem (comm-6: MS's QR codes are non-standard so other apps reject them), reinforcing that cross-app portability isn't supported.

                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                  • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…

                                                Migration

                                                1. everyday userMoving to a new phone transfers all my tokens in one guided step

                                                  weight 2 · round to Microsoft Authenticator
                                                  Google Authenticatordisputedcontradicted4/10

                                                  Google's own docs describe a guided one-step transfer via signing into a Google Account (auto-sync) or scanning a QR export code between old/new devices, which matches the story closely. However, multiple hands-on community reports concretely contradict this working reliably in practice—users report app upgrades wiping all tokens, phone replacements losing TOTP keys despite expecting sync/backup, and account bans erasing synced codes entirely. missing for 10: independent verification that the guided transfer works consistently without data loss, and resolution of documented upgrade/sync failures.

                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                  • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                  • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.
                                                  • [community] Every time I upgraded to a new iOS 7 beta, it wiped my Google Authenticator account tokens... I can't log in to my CampBX account anymore.
                                                  • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                  Microsoft Authenticatordisputedcontradicted5/10

                                                  Docs describe a guided backup/restore flow (enable Cloud Backup, then restore accounts on a new device) via microsoft-authenticator-docs-9/13, which is the core mechanism for the story. However, hands-on community evidence reports the process failing catastrophically — one user's update wiped all data and locked them out of every account (microsoft-authenticator-comm-1), while another user reports no such issue (microsoft-authenticator-comm-2), showing the reliability of the 'one guided step' transfer is contested rather than confirmed. Missing for 10: independent verification that restore reliably works across devices/OS versions, and no acknowledgment/fix from Microsoft for the reported data-loss bug.

                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                  • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                  • [community] I've been using Microsoft's one for my work accounts... I've never gotten that dialog, and have not had any issues with the accounts I've ad…

                                                Privacy posture — data-handling and privacy storiesPrivacy posture

                                                Data-handling and privacy stories

                                                1. ai-native userChoose where my data is stored (region/residency)

                                                  weight 2 · round drawn
                                                  Google Authenticatornone0/10

                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                    Microsoft Authenticatornone0/10

                                                    No evidence Microsoft Authenticator offers any data residency/region selection controls for AI-native users; this is an authentication app, not a data-storage platform, but the story is arguably still applicable since it stores backups (cloud backup, account data) somewhere. No documentation mentions region choice or residency options.

                                                    • ai-native userPrevent my data from being used to train AI models

                                                      weight 3 · round drawn
                                                      Google Authenticatornone0/10

                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                        Microsoft Authenticatornone0/10

                                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                        • ai-native userControl data retention and deletion

                                                          weight 2 · round to Google Authenticator
                                                          Google Authenticatorpartialcommunity4/10

                                                          Google Authenticator lets users delete individual codes (swipe to delete), edit/reassign codes, and use the app without a Google account (avoiding cloud retention entirely), giving some control over what data is stored and removed. However, there is no documented account-level 'delete all my data' or data-export-to-file control, and community reports describe difficulty exporting/backing up codes and total data loss if a Google account is banned or deleted, undermining full user control over retention. missing for 10: explicit data export/portability controls, account-wide deletion/retention settings, and confirmation that deleting codes removes them from Google's backend, not just the local view.

                                                          • [claimed-docs] To delete an Authenticator code on Android, swipe right on any code to show the delete option.
                                                          • [claimed-docs] When you first open the app, tap Use without an account.
                                                          • [claimed-docs] For additional protection, you can turn on Privacy Screen in Google Authenticator. This requires a verification from your device, like a PIN…
                                                          • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                          • [community] Google Authenticator does not allow you to include your codes in your backup, even when it's encrypted. So due to Google Authenticator, losi…
                                                          • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                          Microsoft Authenticatorpartialcommunity3/10

                                                          The app offers a toggle for sharing non-personal usage data and lets users enable/disable cloud backup or export/delete stored passwords, giving some control over what data is retained, but there is no documented account/data deletion policy, retention period, or explicit 'delete my data' feature, and community reports note unexpected data loss/location tracking rather than user-controlled retention. missing for 10: explicit data retention/deletion policy, dedicated 'delete my account data' control, independent verification that deletion actually removes backend data.

                                                          • [claimed-docs] You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…
                                                          • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                          • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                          • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]
                                                          • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                        • ai-native userOpt out of telemetry and usage tracking

                                                          weight 2 · round to Microsoft Authenticator
                                                          Google Authenticatornone0/10

                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                            Microsoft Authenticatordisputedcontradicted4/10

                                                            Microsoft's own docs mention an opt-in 'Usage Data' toggle that lets users control sharing of additional non-personal usage data, suggesting some telemetry control (microsoft-authenticator-docs-16). However, independent community reporting citing an Exodus Privacy audit says the app 'tracks your position all the time,' contradicting the notion that users can fully opt out of tracking (microsoft-authenticator-comm-5), and there is no documentation of a comprehensive telemetry/diagnostics opt-out beyond that single toggle. Missing for 10: explicit documentation of a full telemetry/diagnostics opt-out, first-party clarification of the location-tracking discrepancy, and independent verification that the toggle actually stops all usage tracking.

                                                            • [claimed-docs] You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…
                                                            • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]

                                                          Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture

                                                          How it protects itself — app lock, E2EE design, audits, breach alerting

                                                          App lock

                                                          1. everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

                                                            weight 2 · round drawn
                                                            Google Authenticatorfullclaimed8/10

                                                            Google's own docs describe a 'Privacy Screen' feature requiring PIN, pattern, or biometric verification before the app can be used, directly matching the story. No community evidence contradicts this specific lock-screen feature (complaints focus on sync/backup, not app-lock). Missing for 10: independent hands-on confirmation of the Privacy Screen feature working reliably across devices.

                                                            • [claimed-docs] For additional protection, you can turn on Privacy Screen in Google Authenticator. This requires a verification from your device, like a PIN…
                                                            Microsoft Authenticatorfullclaimed8/10

                                                            Docs explicitly describe App Lock requiring device PIN or biometric authentication every time Authenticator is opened, directly matching the story. Missing for 10: independent/hands-on confirmation of App Lock reliability and default-on status.

                                                            • [claimed-docs] When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.
                                                            • [claimed-docs] Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…

                                                          Audits

                                                          1. security engineerThe vendor publishes independent security audits of the app and its sync protocol

                                                            weight 2 · round drawn
                                                            Google Authenticatornone0/10

                                                            No evidence of any independent security audit of the app or its cloud sync protocol; a notable 2023 independent security researcher analysis found the sync data was unencrypted, but no formal published audit exists in the evidence pack, only community complaints about sync/backup reliability and trust concerns.

                                                              Microsoft Authenticatornone0/10

                                                              No evidence of any published independent security audit of Microsoft Authenticator or its sync protocol; documentation only covers feature descriptions, and community threads discuss bugs, privacy concerns, and forced adoption but never an audit report. Missing for 10: any third-party audit report, pen-test disclosure, or vendor reference to an independent security assessment of the app or backup/sync protocol.

                                                              • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                              • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                              • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                                              • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]

                                                            Monitoring

                                                            1. power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

                                                              weight 2 · round drawn
                                                              Google Authenticatornone0/10

                                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                Microsoft Authenticatornone0/10

                                                                No evidence that Microsoft Authenticator monitors for breached services or evaluates stored credentials for weakness/reuse/exposure; its password autofill feature is even being discontinued rather than expanded with security scanning. Missing for 10: breach monitoring, weak/reused password detection, exposed credential alerts.

                                                                • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…

                                                              Push

                                                              1. it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

                                                                weight 2 · round to Microsoft Authenticator
                                                                Google Authenticatornone0/10

                                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                  Microsoft Authenticatorpartialcommunity5/10

                                                                  Evidence confirms admin-enforced push MFA policies (docs-3, comm-8, comm-9) and location-based context checks (docs-15), but there is no explicit mention of number matching as a phishing-resistant feature anywhere in the pack, and community threads focus on other issues (backup bugs, forced adoption) rather than validating anti-phishing controls. Missing for 10: number matching feature documentation, independent verification of phishing-resistance efficacy, and conditional access/policy configuration details for admins.

                                                                  • [claimed-docs] You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.
                                                                  • [claimed-docs] You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.
                                                                  • [community] IME some MS shops enforce use of it for 2fa to access company resources like vpn and etc. - for eg, the only reason this app exists on my ph…
                                                                  • [community] My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…

                                                                Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting

                                                                Running it yourself — self-hosted servers, open-source clients

                                                                Server

                                                                1. it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter

                                                                  weight 2 · round drawn
                                                                  Google Authenticatornone0/10

                                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                    Microsoft Authenticatornone0/10

                                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                    Source

                                                                    1. security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed

                                                                      weight 2 · round to Google Authenticator
                                                                      Google Authenticatorpartialclaimed4/10

                                                                      The GitHub repo (google/google-authenticator) documents open-source implementations of HOTP/TOTP and a PAM module, giving some basis for code review, but the evidence pack has no confirmation that the current shipped Android/iOS apps (which now handle cloud sync of seeds) actually correspond to this repo or receive active community review. missing for 10: evidence that the live mobile app source matches the published repo, evidence of active maintenance/community audits of the seed-handling code, and independent confirmation of code correctness.

                                                                      • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                      • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                      • [github] Pluggable Authentication Module, aka PAM.
                                                                      Microsoft Authenticatornone0/10

                                                                      No evidence that Microsoft Authenticator's client code is open source; it is a closed, proprietary Microsoft product with no public repository or community code review mentioned anywhere in the evidence pack.

                                                                      Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces

                                                                      Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

                                                                      Automation

                                                                      1. ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

                                                                        weight 2 · round drawn
                                                                        Google Authenticatornone0/10

                                                                        Google Authenticator is a mobile/PAM app with no documented CLI or API for programmatic TOTP retrieval; evidence only covers manual app UI actions (sync, QR export, editing codes) and community complaints about backup/sync issues, none of which show agent-accessible code fetching.

                                                                          Microsoft Authenticatornone0/10

                                                                          Microsoft Authenticator is a mobile app with no documented CLI or API for programmatic TOTP retrieval; evidence even indicates its QR codes are non-standard and reject other TOTP clients, and probes confirm no API/OpenAPI surface exists. No evidence of any automation-friendly access to codes.

                                                                          • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                                          • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                                          • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                                        • ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

                                                                          weight 1 · round drawn
                                                                          Google Authenticatornone0/10

                                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                            Microsoft Authenticatornone0/10

                                                                            No evidence of any local API, CLI, or programmatic endpoint for querying codes/secrets; probes confirm no llms.txt, docs-md, or OpenAPI endpoints exist, and the app is designed as a closed mobile experience with screen-capture disabled by default.

                                                                            • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                                            • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                                                            • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                                            • [claimed-docs] To see your OTP codes in screenshots or allow other apps to capture the Authenticator screen, turn on Screen Capture in Authenticator's Sett…

                                                                          Browser

                                                                          1. everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

                                                                            weight 2 · round drawn
                                                                            Google Authenticatornone0/10

                                                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                              Microsoft Authenticatornone0/10

                                                                              Evidence shows Microsoft Authenticator is a mobile app generating OTP codes and offering an in-app password Autofill feature, but there is no mention of a browser extension that autofills TOTP codes or passkeys, and community evidence indicates the password autofill feature itself is being discontinued entirely (comm-11), not extended to TOTP/passkey autofill.

                                                                              • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                                                              • [claimed-docs] Scroll down to the Autofill section and select Export Passwords... Import your passwords.
                                                                              • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…

                                                                            Desktop

                                                                            1. power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile

                                                                              weight 2 · round drawn
                                                                              Google Authenticatornone0/10

                                                                              No evidence of a desktop application; Google Authenticator is documented and discussed only as a mobile app with QR-based transfer/sync between phones, not a desktop client or vault.

                                                                              • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                              • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                              • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                              Microsoft Authenticatornone0/10

                                                                              All evidence describes Microsoft Authenticator as a mobile app (phone/wearable), with no mention of a desktop application for codes or vault access; the product is explicitly mobile-only.

                                                                              Watch

                                                                              1. everyday userRead my codes from my smartwatch without pulling out my phone

                                                                                weight 1 · round to Microsoft Authenticator
                                                                                Google Authenticatornone0/10

                                                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                  Microsoft Authenticatorpartialclaimed4/10

                                                                                  Docs confirm Authenticator notifications can be mirrored to a wearable device, which implies some code/approval visibility without pulling out the phone, but there's no explicit confirmation that time-based OTP codes themselves are readable on a smartwatch screen, nor any hands-on/community corroboration of this specific wearable experience. missing for 10: explicit documentation that OTP codes (not just approval notifications) display on smartwatch, independent/hands-on confirmation of the wearable experience.

                                                                                  • [claimed-docs] you can mirror Authenticator notifications from your phone to your wearable device.

                                                                                Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup

                                                                                Not losing your accounts — encrypted backup, multi-device sync, recovery

                                                                                Backup

                                                                                1. security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

                                                                                  weight 3 · round drawn
                                                                                  Google Authenticatornone0/10

                                                                                  Docs only describe syncing codes via a Google Account (google-authenticator-docs-1,4) with no mention of end-to-end encryption or a vendor-blind key, and community reports explicitly note that storing codes in 'google cloud doesn't satisfy me' and that losing access to the Google account means losing all 2FA data, implying no such E2E encryption exists.

                                                                                  • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                  • [community] Storing it in the google cloud doesn't satisfy me. I just simply want the codes under my control... google still makes it stupendously diffi…
                                                                                  • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                  • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                                                  Microsoft Authenticatornone0/10

                                                                                  Docs confirm a Cloud Backup feature exists (microsoft-authenticator-docs-9, -13) but provide no description of end-to-end encryption or a vendor-inaccessible key, and no encryption design documentation is cited anywhere. Community commentary even contrasts Microsoft's backup with an alternative app that explicitly offers 'encrypted backups' (microsoft-authenticator-comm-4), implying this property isn't established for Microsoft Authenticator.

                                                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                                                  • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…

                                                                                Multi device

                                                                                1. everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

                                                                                  weight 2 · round to Google Authenticator
                                                                                  Google Authenticatorpartialcommunity5/10

                                                                                  Google's docs confirm automatic cross-device sync via Google Account sign-in, works offline, and supports multiple accounts (docs-1,4,5,10), but Authenticator is a mobile-only app with no native desktop/computer client, so the 'computer' leg of the story is unsupported. Community reports also cite historical sync/backup failures and account-loss risk tying codes to a Google Account (comm-1, comm-7, comm-12, comm-13), showing real caveats even if not disproving the current sync feature outright. Missing for 10: a computer/desktop client, independent hands-on confirmation the modern sync feature works reliably across all device types without data loss.

                                                                                  • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                  • [claimed-docs] Authenticator can sync codes for multiple Google Accounts and display them from the same mobile device.
                                                                                  • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                  • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                                                  • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                  • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                                                  • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.
                                                                                  Microsoft Authenticatordisputedcontradicted4/10

                                                                                  Docs describe Cloud Backup that lets you restore accounts to a new device (docs-9, docs-13), but this is backup/restore rather than true simultaneous multi-device sync across phone, tablet, and computer — there's no evidence of a tablet or desktop client. Community reports directly contradict reliability of this backup: users report Authenticator updates wiping all account data and causing lockouts (comm-1, comm-3), undermining the claim that data stays reliably available across devices. Missing for 10: evidence of simultaneous real-time sync across phone/tablet/desktop clients, and resolution of documented data-loss/backup failure reports.

                                                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                                                  • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                                                  • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…

                                                                                Recovery

                                                                                1. everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

                                                                                  weight 3 · round drawn
                                                                                  Google Authenticatordisputedcontradicted5/10

                                                                                  Google's own docs describe two documented recovery paths — signing into your Google Account to auto-sync codes across devices, or scanning a QR-code export to transfer codes to a new device (google-authenticator-docs-1/3/4/11) — which is exactly the story's ask. However, multiple hands-on community reports concretely contradict reliability of this recovery: users report app upgrades wiping all tokens with no recovery (comm-13, comm-14), phone backups explicitly excluding Authenticator data (comm-1, comm-8), and losing all codes permanently if the tied Google Account is banned/deleted (comm-7, comm-12). Missing for 10: independent verification that account-sync recovery works consistently across real device-loss scenarios, and resolution of the backup-exclusion/account-ban failure modes.

                                                                                  • [claimed-docs] With Google Authenticator, you can synchronize your verification codes across all your devices, simply by signing in to your Google Account.
                                                                                  • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                                  • [claimed-docs] When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.
                                                                                  • [claimed-docs] To manually transfer Authenticator codes to a new device, you need: Your old device with Google Authenticator codes
                                                                                  • [community] I recently had a broken phone replaced and had depended on a backup to have my TOTP keys on my new phone. It was not a part of the phone bac…
                                                                                  • [community] Does that mean one can use adb to backup Google Authenticator's data as well? Last time I tried, the app data was explicitly marked as exclu…
                                                                                  • [community] Don't upgrade! I just had this unpleasant experience and warned everyone... Warning: Google Authenticator upgrade loses all accounts.
                                                                                  • [community] Every time I upgraded to a new iOS 7 beta, it wiped my Google Authenticator account tokens... I can't log in to my CampBX account anymore.
                                                                                  • [community] If Google ever decides to kick you out of your account, Authenticator data will be gone. Google has done this on several occasions in the pa…
                                                                                  • [community] Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part …
                                                                                  Microsoft Authenticatordisputedcontradicted5/10

                                                                                  Microsoft documents a Cloud Backup feature explicitly designed to restore accounts on a new device after phone loss (docs-9, docs-13), which matches the story's claim of a documented recovery path. However, a concrete hands-on community report describes the opposite outcome — an app update wiped all backed-up data and locked the user out of every account, with the poster citing it as a known reliability issue (comm-1, comm-3) — directly contradicting the documented recovery guarantee. missing for 10: independent verification that Cloud Backup restore reliably works, resolution of the reported wipe/lockout bug, and clarity on how backup interacts with app updates.

                                                                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                                                  • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                                                  • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…

                                                                                Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin

                                                                                Shared and managed use — shared vaults, org policies, programmatic provisioning

                                                                                Automation

                                                                                1. ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

                                                                                  weight 2 · round drawn
                                                                                  Google Authenticatornone0/10

                                                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                    Microsoft Authenticatornone0/10

                                                                                    No evidence of any API, CLI, or programmatic surface for creating/updating vault entries or TOTP secrets; Microsoft Authenticator is a manual mobile app with QR-based account addition, and probes for API/docs endpoints returned 404s. missing for 10: any documented API/SDK/CLI for programmatic vault management, evidence of agent-accessible interfaces, confirmation of automated secret seeding.

                                                                                    • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                                                    • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                                                                    • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                                                    • [claimed-docs] Scan the QR code or download and install Authenticator from the Apple app store.

                                                                                  Policy

                                                                                  1. it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

                                                                                    weight 1 · round drawn
                                                                                    Google Authenticatornone0/10

                                                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                      Microsoft Authenticatornone0/10

                                                                                      Evidence only hints that notifications may be gated 'if allowed by your administrator' and that location-sharing is required for conditional access, but there is no documentation of an admin console or policy set that lets IT enforce app lock, restrict export, or mandate strong master credentials across all org members. Community evidence even suggests admins lack granular control tools (comm-6), reinforcing the absence of such enterprise policy enforcement in this pack.

                                                                                      • [claimed-docs] You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.
                                                                                      • [claimed-docs] When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.
                                                                                      • [claimed-docs] You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.
                                                                                      • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…

                                                                                    Sharing

                                                                                    1. it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control

                                                                                      weight 2 · round drawn
                                                                                      Google Authenticatornone0/10

                                                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                                        Microsoft Authenticatornone0/10

                                                                                        Microsoft Authenticator is a personal/individual authenticator app with no evidence of shared vaults, collections, or per-member access control for teams; its passwords feature is even being discontinued. Missing for 10: shared vault/collection feature, per-member access control, admin sharing management console.

                                                                                        • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…
                                                                                        • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                                                        • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.

                                                                                      Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core

                                                                                      The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

                                                                                      Enrollment

                                                                                      1. everyday userScan a QR code and immediately start generating TOTP codes for a new account

                                                                                        weight 3 · round to Google Authenticator
                                                                                        Google Authenticatorfullclaimed8/10

                                                                                        Docs and GitHub evidence confirm the app scans QR codes to add accounts and generates RFC 6238 TOTP codes, including offline (docs-3, docs-10, gh-1). Community feedback criticizes backup/sync/loss issues, not the basic scan-and-generate flow, so the core story is undisputed. Missing for 10: independent hands-on confirmation of the exact scan-to-first-code experience and no first-party UX walkthrough beyond support docs.

                                                                                        • [claimed-docs] On your old device, create a QR code... On your new device, tap Scan QR code
                                                                                        • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                        • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                                        • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                                        Microsoft Authenticatordisputedcontradicted5/10

                                                                                        Microsoft's own docs confirm the app supports one-time-password codes for two-step verification (docs-12), implying QR-based account setup generates TOTP codes offline. However, hands-on community reports describe a known QR-scan bug that forces users to cancel the dialog and add accounts manually without the QR code (comm-3), and another user notes the QR codes Microsoft issues for its own accounts are non-standard and rejected by other TOTP clients (comm-6), directly contradicting a smooth 'scan and immediately generate' experience. missing for 10: no first-party doc walking through the exact 'add account via QR scan' flow, and no resolution/acknowledgment of the reported scan failures.

                                                                                        • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…
                                                                                        • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…
                                                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…

                                                                                      Offline

                                                                                      1. power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes

                                                                                        weight 2 · round to Google Authenticator
                                                                                        Google Authenticatorfullclaimed8/10

                                                                                        Docs explicitly state you can 'Use without an account' at setup and that codes generate 'without an internet connection or mobile service,' confirming fully offline, account-free TOTP generation (core RFC 6238 implementation per GitHub). Community discussion focuses on backup/sync/account-loss risks, not on offline generation failing, so no contradiction of this specific axis. Missing for 10: independent hands-on confirmation specifically testing offline-without-account code generation.

                                                                                        • [claimed-docs] When you first open the app, tap Use without an account.
                                                                                        • [claimed-docs] You can still generate codes without an internet connection or mobile service.
                                                                                        • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                                        Microsoft Authenticatordisputedcontradicted4/10

                                                                                        Microsoft's own docs claim codes work without an internet connection or phone service (microsoft-authenticator-docs-2), but hands-on community reports contradict this for real-world enterprise use: one user reports 'ms authenticator doesn't generate a code until I first log into the vpn using exchange creds' (microsoft-authenticator-comm-10), and another notes the app issues non-standard QR codes that lock users into the vendor's app rather than plain TOTP (microsoft-authenticator-comm-6), undermining the 'no vendor account required' and pure-offline claims for many real deployments. Missing for 10: independent technical verification of offline TOTP generation across account types, and confirmation that no Microsoft account/login is ever required to view codes.

                                                                                        • [claimed-docs] The codes don't require you to be on the internet or connected to data, so you don't need phone service to sign in.
                                                                                        • [community] it seems to be a push notification where the ms authenticator doesn't generate a code until I first log into the vpn using exchange creds.
                                                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                                                        • [community] My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…

                                                                                      Organization

                                                                                      1. power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

                                                                                        weight 2 · round drawn
                                                                                        Google Authenticatornone0/10

                                                                                        Evidence only shows basic manual reordering (drag-to-reorder), swipe-to-edit/delete, and username/account editing — there is no mention of search, folders/groups, or service icons for organizing many tokens. missing for 10: search functionality, folder/group organization, service icons, any at-scale organization feature for dozens of tokens.

                                                                                        • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option.
                                                                                        • [claimed-docs] To organize your Authenticator codes, touch and hold any code, then drag to reorder to a desired location.
                                                                                        • [claimed-docs] To delete an Authenticator code on Android, swipe right on any code to show the delete option.
                                                                                        • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option. You can update the username for the code or chan…
                                                                                        Microsoft Authenticatornone0/10

                                                                                        No evidence describes organizational features like search, folders/groups, or per-account service icons for managing many tokens; docs cover backup, passwordless sign-in, and notifications but not organization/search UX. Community evidence even suggests account list issues (duplicate/overwrite concerns) rather than robust organization tools. Missing for full credit: any mention of search, folder/grouping, or icon-based organization of accounts.

                                                                                        • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                                                        • [community] I have many accounts with the same user names, and they don't get overwritten. There might be some design flaw somewhere, but it's surely no…

                                                                                      Variants

                                                                                      1. power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

                                                                                        weight 2 · round to Google Authenticator
                                                                                        Google Authenticatorpartialclaimed3/10

                                                                                        The GitHub docs confirm the underlying library supports HOTP (RFC 4226) and TOTP (RFC 6238) algorithms, giving some basis for HOTP counter support, but there is no evidence anywhere in the pack that the consumer app exposes Steam Guard mode, custom periods, or custom digit lengths — the mobile app UI evidence only shows scanning QR codes, editing username, and deleting entries. missing for 10: Steam Guard token support, custom period configuration, custom digit-length configuration, and any UI/setting for manual HOTP counter entry.

                                                                                        • [github] These implementations support the HMAC-Based One-time Password (HOTP) algorithm specified in RFC 4226 and the Time-based One-time Password (…
                                                                                        • [github] The Google Authenticator project includes implementations of one-time passcode generators for several mobile platforms.
                                                                                        • [claimed-docs] To edit your Authenticator code on Android, swipe left on any code to show the edit option.
                                                                                        Microsoft Authenticatornone0/10

                                                                                        No evidence anywhere in the pack indicates Microsoft Authenticator supports HOTP counters, Steam Guard, or custom period/digit-length TOTP tokens; docs only describe standard push/OTP sign-in flows. Community evidence even suggests the opposite — its QR codes are non-standard TOTP and rejected by other clients, implying inflexibility rather than support for non-standard token types.

                                                                                        • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…
                                                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…

                                                                                      Not comparable on these axes

                                                                                      1. ai-native userPlug MCP servers into this product so it can use their tools

                                                                                        weight 3 · not comparable
                                                                                        Google Authenticatorn/a

                                                                                        Google Authenticator is a simple OTP code generator app with no plugin/tool ecosystem or agent-integration capability; MCP server integration is a category error for this product type.

                                                                                          Microsoft Authenticatorn/a

                                                                                          Microsoft Authenticator is a consumer authentication/MFA app, not an AI agent or platform with tool-use capability; plugging in MCP servers is a category error for this product type.

                                                                                          • ai-native userSubscribe to events via webhooks

                                                                                            weight 2 · not comparable
                                                                                            Google Authenticatorn/a

                                                                                            Google Authenticator is a standalone TOTP/HOTP code-generator app with no API or event system; webhook subscriptions are a wrong axis for this product category.

                                                                                              Microsoft Authenticatorn/a

                                                                                              Microsoft Authenticator is a consumer mobile authentication app, not a platform with an event/webhook subscription API; webhook subscriptions are a wrong axis for this product category.

                                                                                              • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                                                                weight 2 · not comparable
                                                                                                Google Authenticatorn/a

                                                                                                Google Authenticator is a single-purpose OTP code generator with no data analytics or AI-generated insights feature; this axis is a category error for this product type.

                                                                                                  Microsoft Authenticatorn/a

                                                                                                  Microsoft Authenticator is an authentication/security app with no data-analysis or AI-insights feature set; generating AI-driven insights from user data is outside its category.

                                                                                                  • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                                                                    weight 3 · not comparable
                                                                                                    Google Authenticatorn/a

                                                                                                    Google Authenticator is a 2FA code generator utility, not an AI-agent or assistant platform; delegating tasks to a built-in AI assistant is outside its product category entirely.

                                                                                                      Microsoft Authenticatorn/a

                                                                                                      Microsoft Authenticator is an authentication/security app, not an AI assistant platform; no evidence of any built-in AI assistant or agent delegation feature. This capability is entirely outside the product's category.

                                                                                                      • ai-native userExplore an interactive API reference with runnable examples

                                                                                                        weight 2 · not comparable
                                                                                                        Google Authenticatorn/a

                                                                                                        Google Authenticator is a mobile 2FA code-generator app, not a developer platform or API product; an interactive API reference with runnable examples is a category mismatch for this kind of product.

                                                                                                          Microsoft Authenticatorn/a

                                                                                                          Microsoft Authenticator is a consumer mobile authentication app, not a developer API/platform product; an interactive API reference with runnable examples is not a relevant axis for this product category.

                                                                                                          • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                                                                                                            weight 2 · not comparable
                                                                                                            Google Authenticatorn/a

                                                                                                            Google Authenticator is a consumer mobile 2FA app with no programmatic API surface; a machine-readable API spec is not a relevant axis for this product category.

                                                                                                              Microsoft Authenticatornone0/10

                                                                                                              Microsoft Authenticator is a consumer mobile app for authentication, not an API product, and no OpenAPI/machine-readable spec is offered; probes for openapi.json, llms.txt, and docs-md endpoints all returned 404.

                                                                                                              • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                                                                              • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                                                                                              • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                                                                            • ai-native userTest against a sandbox environment without touching production data

                                                                                                              weight 1 · not comparable
                                                                                                              Google Authenticatorn/a

                                                                                                              Google Authenticator is a simple TOTP/HOTP code generator app, not a developer platform or API service with a sandbox/testing environment concept; this axis is a category error for this product type.

                                                                                                                Microsoft Authenticatorn/a

                                                                                                                Microsoft Authenticator is a consumer/enterprise authentication app, not a developer platform or API product; there is no concept of a sandbox environment for testing against it. This is a category error for this product type.

                                                                                                                • ai-native userDefine rules that trigger actions automatically on events

                                                                                                                  weight 3 · not comparable
                                                                                                                  Google Authenticatorn/a

                                                                                                                  Google Authenticator is a static OTP-code generator app with no rules engine, event triggers, or automation/workflow capability; this axis is a category error for this product type.

                                                                                                                    Microsoft Authenticatorn/a

                                                                                                                    Microsoft Authenticator is an authentication/MFA app, not a rules-engine or automation platform; there is no concept of user-defined event-triggered rules in its feature set. This axis is a category error for this product type.

                                                                                                                    • ai-native userSchedule recurring jobs or workflows

                                                                                                                      weight 2 · not comparable
                                                                                                                      Google Authenticatorn/a

                                                                                                                      Google Authenticator is a 2FA code generator app with no workflow/job-scheduling capability; scheduling recurring automation is outside its product category entirely.

                                                                                                                        Microsoft Authenticatorn/a

                                                                                                                        Microsoft Authenticator is an identity/authentication app, not a workflow automation or job-scheduling tool; scheduling recurring jobs is outside its product category.

                                                                                                                        • ai-native userVersion, review, and roll back my automations

                                                                                                                          weight 1 · not comparable
                                                                                                                          Google Authenticatorn/a

                                                                                                                          Google Authenticator is a 2FA code generator, not an automation/workflow tool; versioning, reviewing, or rolling back automations is not a category concern for this product.

                                                                                                                            Microsoft Authenticatorn/a

                                                                                                                            Microsoft Authenticator is an authentication app, not an automation/workflow tool with versionable automations to review or roll back — this axis is a category error for this product type.