Microsoft Authenticator vs Authy
Authy wins · 4–11 (31 drawn)
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
Agent access
ai-native userPoint an agent at llms.txt or agent-oriented docs
weight 2 · round drawnMicrosoft Authenticatornone0/10Probes show no llms.txt, no markdown docs, and no OpenAPI spec available for Microsoft Authenticator's documentation site; there is no evidence of agent-oriented documentation format.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
ai-native userRun the product headlessly / in CI for automation
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userConnect an agent via an official MCP server
weight 3 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userUse an official CLI
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userDrive the product through a documented public API
weight 3 · round to AuthyMicrosoft Authenticatornone0/10Microsoft Authenticator is a consumer mobile app with no evidence of a documented public API for programmatic/AI-driven control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404s.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
Authydisputedcontradicted2/10Twilio's own docs describe an SDK/API for integrating Authy (authy-docs-1, authy-docs-13), but a direct probe of the same page shows the Authy API is deprecated and 'closed to new customers' with 'no programmatic surface remains open to new integrations' (authy-probe-rt-1), meaning an AI-native user cannot actually drive Authy via a documented public API today. Missing for 10: an open, actively maintained public API for new integrations, migration path documentation usable by AI agents, and independent confirmation of working programmatic access.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [claimed-docs] “So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
ai-native userIssue scoped/least-privilege API credentials for an agent
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userBuild against official SDKs
weight 2 · round to AuthyMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Authydisputedcontradicted3/10Twilio's docs claim official SDKs for common web languages to integrate Authy 2FA (authy-docs-1, authy-docs-13), but the same docs page also states the Authy API is closed to new customers and being deprecated in favor of Verify v2, meaning no new AI-native integration can actually be built against it. Missing for 10: evidence of an actively maintained, open-to-new-customers SDK, and any agentic/AI-specific tooling or examples.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [claimed-docs] “So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
Agentic features
ai-native userSet up automations that run autonomously in the background
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userOperate the product with natural-language commands
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Api quality
ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)
weight 2 · round drawnMicrosoft Authenticatornone0/10Microsoft Authenticator is a consumer mobile app for authentication, not an API product, and no OpenAPI/machine-readable spec is offered; probes for openapi.json, llms.txt, and docs-md endpoints all returned 404.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
Authynone0/10Evidence only mentions SDKs and API docs (Verify/Authy), with no mention of a downloadable OpenAPI/Swagger spec or other machine-readable API definition; the Authy API is also noted as deprecated with no new integrations possible.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [claimed-docs] “So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
ai-native userRely on versioned APIs with a documented deprecation policy
weight 2 · round to AuthyMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Twilio's docs do carry an explicit deprecation notice for the Authy API, stating it is closed to new customers and pointing to a migration guide toward Verify v2, which is a documented deprecation policy of sorts. However there is no evidence of a broader versioning scheme (e.g., v1/v2 semantics, changelogs, sunset timelines) beyond this one-time 'this API is dying' notice, and it applies to abandonment rather than an ongoing API lifecycle policy. missing for 10: evidence of a formal API versioning scheme, sunset/timeline commitments, changelog practices, and confirmation that Verify (the successor) itself has a documented deprecation policy.
- [claimed-docs] “For more information about migration, see Migrating from Authy to Verify for SMS”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
ai-native userPerform bulk operations across many items at once
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
ai-native userDo everything through the API that I can do in the UI
weight 2 · round drawnMicrosoft Authenticatornone0/10Microsoft Authenticator is a consumer mobile app with no evidence of any public API for programmatic control of authentication actions; probes for API/docs endpoints all 404. No evidence supports API parity with UI functionality.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
Authynone0/10Authy's API (the Twilio Authy API) is explicitly deprecated and closed to new customers per Twilio's own docs, and community reports confirm there is no way to export/manage 2FA data programmatically outside the mobile/desktop UI—users describe hacky workarounds just to extract seeds. There is no evidence of a supported API that mirrors the app's UI capabilities (device management, backup, sync, disabling installs, etc.).
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
ai-native userExport all of my data in open formats and leave
weight 3 · round to Microsoft AuthenticatorMicrosoft documents an 'Export Passwords' feature for autofill data, but this covers only saved passwords, not the OTP/account seeds this app is centrally used for; TOTP/account data is only preserved via proprietary encrypted 'Cloud Backup' tied to a Microsoft account, not an open, portable format. Community evidence goes further, describing non-standard QR codes that other TOTP clients reject and users switching to open-source alternatives (Aegis) specifically because Authenticator lacks true open-format export/backup. missing for 10: open-format export of TOTP secrets/accounts, documented data-portability/leave workflow, independent confirmation that exported data works outside Microsoft's ecosystem.
- [claimed-docs] “Scroll down to the Autofill section and select Export Passwords.”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [claimed-docs] “Scroll down to the Autofill section and select Export Passwords... Import your passwords.”
- [community] “Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
Authydisputedcontradicted2/10Authy provides no official open-format export tool; community reports (authy-comm-3, authy-comm-4, authy-comm-10, authy-comm-18) describe deliberately obstructed migration, requiring hacky Electron debug-mode QR dumps (authy-comm-14) rather than any documented export feature, directly contradicting any implicit claim of open portability. missing for 10: any first-party documentation of a data export feature or open format, evidence of a supported 'leave the platform' workflow, and confirmation that TOTP seeds/secrets can be retrieved without workarounds.
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…”
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
ai-native userRead the product's source under an open license
weight 2 · round drawnMicrosoft Authenticatornone0/10Microsoft Authenticator is closed-source proprietary software; no evidence of any open-license source availability, and probes for docs/API artifacts also failed.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
ai-native userSelf-host the core product
weight 3 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support
Passkeys in the vault — storage, sign-in, cross-ecosystem sync
Storage
everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes
weight 3 · round drawnMicrosoft Authenticatornone0/10The evidence pack describes password-based sign-in removal, TOTP codes, push notifications, and password autofill/export, but nowhere mentions passkeys (FIDO2/WebAuthn credentials) being stored or used to sign into websites/apps. Missing for 10: any documentation of passkey creation, storage, or sign-in via Authenticator, and any independent confirmation of passkey support.
- [claimed-docs] “Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…”
- [claimed-docs] “As the only way to sign in - just tap an approval on your phone to sign in. This is called going passwordless.”
- [claimed-docs] “As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…”
Authynone0/10Evidence only shows Twilio's separate Verify API service listing 'Passkeys' as one of many verification factors developers can integrate (authy-docs-2), not that the Authy consumer app itself stores user passkeys or lets users sign into websites/apps with them. All Authy app feature docs (docs-3 through docs-12) describe only TOTP/2FA sync, backups, and device management — no passkey storage or autofill capability is mentioned, and community evidence never discusses passkey sign-in via Authy.
- [claimed-docs] “Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.”
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.”
- [claimed-docs] “Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.”
Sync
power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor
weight 2 · round drawnMicrosoft Authenticatornone0/10The evidence pack covers Microsoft Authenticator's TOTP codes, push-notification MFA, cloud backup, and password autofill (now being discontinued), but contains no mention of passkey creation, storage, or cross-platform/cross-vendor passkey syncing across iOS, Android, Windows, Linux, or browsers. Passkey sync is a fair axis for an authenticator app, but nothing in the pack demonstrates it.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…”
Authynone0/10Authy's own docs describe syncing TOTP/2FA tokens across mobile/tablet devices (authy-docs-3, authy-docs-4), not passkeys; the only 'Passkeys' mention is in Twilio Verify API docs, which is a separate developer verification service, not evidence Authy itself stores or syncs WebAuthn passkeys across iOS/Android/Windows/Linux/browsers. No evidence shows Authy functioning as a cross-platform passkey manager.
- [claimed-docs] “Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.”
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “On any device. Your phone, tablet, even your Apple Watch.”
- [claimed-docs] “It's available for iOS, Android, macOS, Windows, and Linux.”
Portability — your secrets stay yours — open export, bulk import, device migrationPortability
Your secrets stay yours — open export, bulk import, device migration
Export
power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in
weight 3 · round to AuthyMicrosoft Authenticatornone0/10Docs describe cloud backup/restore and password export/import, but none of this covers exporting TOTP secrets in an open format for use in another app; community evidence explicitly states Microsoft issues non-standard QR codes that other TOTP clients reject, indicating deliberate lock-in rather than portability.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [claimed-docs] “Scroll down to the Autofill section and select Export Passwords.”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
- [community] “Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…”
Authydisputedcontradicted2/10Authy provides no official export feature for TOTP secrets, and community reports (authy-comm-3, authy-comm-4, authy-comm-10, authy-comm-18) confirm the app deliberately blocks migration/export, with users resorting to hacky workarounds like extracting keys via a deprecated Chrome extension debug mode (authy-comm-13, authy-comm-14). Docs never claim an export feature exists — only backup/sync within Authy's own ecosystem (authy-docs-5, authy-docs-3). missing for 10: any documented open/standard export format, first-party export tool, official migration path preserving secrets, and evidence contradicting the well-documented lock-in behavior.
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…”
Import
power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand
weight 2 · round drawnMicrosoft Authenticatornone0/10The evidence pack only covers backing up/restoring Authenticator's own accounts via cloud backup, exporting passwords, and standard account setup via QR/manual entry — there is no mention of any bulk-import feature for pulling tokens from other authenticator apps (e.g., Google Authenticator, Aegis) into Microsoft Authenticator. Community evidence even suggests the opposite direction problem (comm-6: MS's QR codes are non-standard so other apps reject them), reinforcing that cross-app portability isn't supported.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
Authynone0/10Evidence shows Authy lets users add individual accounts via QR code capture (authy-docs-12) but nothing indicates a bulk import feature that pulls multiple existing tokens/accounts from other authenticator apps at once. Community evidence instead focuses on Authy making it hard to export data out, which is the opposite direction from what the story asks about.
- [claimed-docs] “Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
Migration
everyday userMoving to a new phone transfers all my tokens in one guided step
weight 2 · round to AuthyMicrosoft Authenticatordisputedcontradicted5/10Docs describe a guided backup/restore flow (enable Cloud Backup, then restore accounts on a new device) via microsoft-authenticator-docs-9/13, which is the core mechanism for the story. However, hands-on community evidence reports the process failing catastrophically — one user's update wiped all data and locked them out of every account (microsoft-authenticator-comm-1), while another user reports no such issue (microsoft-authenticator-comm-2), showing the reliability of the 'one guided step' transfer is contested rather than confirmed. Missing for 10: independent verification that restore reliably works across devices/OS versions, and no acknowledgment/fix from Microsoft for the reported data-loss bug.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…”
- [community] “I've been using Microsoft's one for my work accounts... I've never gotten that dialog, and have not had any issues with the accounts I've ad…”
Authy's own docs describe encrypted cloud backup, multi-device sync, and 'add new device with SMS/voice/existing device approval' as the guided path to move 2FA tokens to a new phone, which directly matches this story (authy-docs-3,4,5,10). Community comments about difficulty exporting data are about moving to a *different app*, not the in-ecosystem new-phone transfer, so they don't contradict this specific flow. Missing for 10: independent/hands-on confirmation that the new-phone restore process itself is smooth and single-step (most community friction reports concern cross-app export, not device-to-device transfer).
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “On any device. Your phone, tablet, even your Apple Watch.”
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
- [claimed-docs] “Add new devices with SMS, voice or existing device approval.”
- [community] “I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).”
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
ai-native userChoose where my data is stored (region/residency)
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence Microsoft Authenticator offers any data residency/region selection controls for AI-native users; this is an authentication app, not a data-storage platform, but the story is arguably still applicable since it stores backups (cloud backup, account data) somewhere. No documentation mentions region choice or residency options.
ai-native userPrevent my data from being used to train AI models
weight 3 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userControl data retention and deletion
weight 2 · round to Microsoft AuthenticatorThe app offers a toggle for sharing non-personal usage data and lets users enable/disable cloud backup or export/delete stored passwords, giving some control over what data is retained, but there is no documented account/data deletion policy, retention period, or explicit 'delete my data' feature, and community reports note unexpected data loss/location tracking rather than user-controlled retention. missing for 10: explicit data retention/deletion policy, dedicated 'delete my account data' control, independent verification that deletion actually removes backend data.
- [claimed-docs] “You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [community] “It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]”
- [community] “This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…”
Authynone0/10No documentation shows Authy giving users control over data retention/export/deletion; instead multiple independent reports describe Twilio deliberately blocking data export ('no export option', 'extremely difficult to export your data') and forcing convoluted workarounds to extract keys, the opposite of user-controlled retention/deletion.
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…”
ai-native userOpt out of telemetry and usage tracking
weight 2 · round to Microsoft AuthenticatorMicrosoft Authenticatordisputedcontradicted4/10Microsoft's own docs mention an opt-in 'Usage Data' toggle that lets users control sharing of additional non-personal usage data, suggesting some telemetry control (microsoft-authenticator-docs-16). However, independent community reporting citing an Exodus Privacy audit says the app 'tracks your position all the time,' contradicting the notion that users can fully opt out of tracking (microsoft-authenticator-comm-5), and there is no documentation of a comprehensive telemetry/diagnostics opt-out beyond that single toggle. Missing for 10: explicit documentation of a full telemetry/diagnostics opt-out, first-party clarification of the location-tracking discrepancy, and independent verification that the toggle actually stops all usage tracking.
- [claimed-docs] “You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…”
- [community] “It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]”
Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture
How it protects itself — app lock, E2EE design, audits, breach alerting
App lock
everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes
weight 2 · round drawnDocs explicitly describe App Lock requiring device PIN or biometric authentication every time Authenticator is opened, directly matching the story. Missing for 10: independent/hands-on confirmation of App Lock reliability and default-on status.
- [claimed-docs] “When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.”
- [claimed-docs] “Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…”
Twilio's official docs claim TouchID, PIN, and password protection guarding access to 2FA tokens, and a community user independently corroborates using Face ID to lock the entire app on their phone. This directly matches the story of biometric/PIN app-lock preventing exposure on a borrowed phone. Missing for 10: more independent hands-on verification of PIN-specific lock behavior and no detail on lockout/failure edge cases.
- [claimed-docs] “Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.”
- [community] “I use Authy with Face ID protecting the entire app on my phone... they'd still need the 2FA codes from my phone [even if password manager co…”
Audits
security engineerThe vendor publishes independent security audits of the app and its sync protocol
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence of any published independent security audit of Microsoft Authenticator or its sync protocol; documentation only covers feature descriptions, and community threads discuss bugs, privacy concerns, and forced adoption but never an audit report. Missing for 10: any third-party audit report, pen-test disclosure, or vendor reference to an independent security assessment of the app or backup/sync protocol.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…”
- [community] “It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]”
Authynone0/10The evidence pack contains no vendor claim of independent third-party security audits of the app or its sync protocol; documentation focuses on feature descriptions (SDKs, sync, backup) with no audit reports or security whitepapers cited. Community evidence discusses a data breach and a slow-to-fix vulnerability, but these do not substitute for published audit evidence and there's no vendor claim to dispute.
Monitoring
power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence that Microsoft Authenticator monitors for breached services or evaluates stored credentials for weakness/reuse/exposure; its password autofill feature is even being discontinued rather than expanded with security scanning. Missing for 10: breach monitoring, weak/reused password detection, exposed credential alerts.
- [community] “Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…”
Push
it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies
weight 2 · round to Microsoft AuthenticatorEvidence confirms admin-enforced push MFA policies (docs-3, comm-8, comm-9) and location-based context checks (docs-15), but there is no explicit mention of number matching as a phishing-resistant feature anywhere in the pack, and community threads focus on other issues (backup bugs, forced adoption) rather than validating anti-phishing controls. Missing for 10: number matching feature documentation, independent verification of phishing-resistance efficacy, and conditional access/policy configuration details for admins.
- [claimed-docs] “You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.”
- [claimed-docs] “You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.”
- [community] “IME some MS shops enforce use of it for 2fa to access company resources like vpn and etc. - for eg, the only reason this app exists on my ph…”
- [community] “My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…”
Authynone0/10Evidence only shows generic Push and Silent Device Approval support (authy-docs-2, authy-docs-15) with no mention of number matching, location context, or admin-enforced MFA policy controls; the Authy API itself is also noted as deprecated for new integrations (authy-probe-rt-1). Missing for 10: any documentation of number matching, location-based risk signals, or admin policy enforcement for push sign-in.
- [claimed-docs] “Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.”
- [claimed-docs] “Push and Silent Device Approval (iOS, Android, Web)”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting
Running it yourself — self-hosted servers, open-source clients
Server
it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter
weight 2 · round drawnMicrosoft Authenticatornone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Source
security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence that Microsoft Authenticator's client code is open source; it is a closed, proprietary Microsoft product with no public repository or community code review mentioned anywhere in the evidence pack.
Authynone0/10There is no evidence Authy's client apps are open source; evidence instead shows closed, proprietary apps with deliberately obstructed export/migration paths and hacky reverse-engineering required to extract seeds. This directly contradicts the premise of community-reviewable open-source code handling seeds.
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces
Where it meets your workflow — IDE, CLI, web, PR comments, CI checks
Automation
ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow
weight 2 · round drawnMicrosoft Authenticatornone0/10Microsoft Authenticator is a mobile app with no documented CLI or API for programmatic TOTP retrieval; evidence even indicates its QR codes are non-standard and reject other TOTP clients, and probes confirm no API/OpenAPI surface exists. No evidence of any automation-friendly access to codes.
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
Authynone0/10Authy is a consumer authenticator app; there is no documented CLI/API for a user or agent to programmatically fetch their own current TOTP code, and Twilio's docs confirm the Authy API is deprecated and closed to new customers with no successor for this use case. Community evidence further shows Authy intentionally blocks exporting secrets/codes, requiring hacky workarounds (deprecated Chrome extension, debug-mode Electron hacks) rather than any supported programmatic access.
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app
weight 1 · round drawnMicrosoft Authenticatornone0/10No evidence of any local API, CLI, or programmatic endpoint for querying codes/secrets; probes confirm no llms.txt, docs-md, or OpenAPI endpoints exist, and the app is designed as a closed mobile experience with screen-capture disabled by default.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
- [claimed-docs] “To see your OTP codes in screenshots or allow other apps to capture the Authenticator screen, turn on Screen Capture in Authenticator's Sett…”
Authynone0/10No evidence Authy offers any local programmatic endpoint for agents to query codes/secrets; its API is closed to new customers and deprecated, and community reports describe the vault as deliberately hard to export via any means other than hacky manual extraction.
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
Browser
everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them
weight 2 · round drawnMicrosoft Authenticatornone0/10Evidence shows Microsoft Authenticator is a mobile app generating OTP codes and offering an in-app password Autofill feature, but there is no mention of a browser extension that autofills TOTP codes or passkeys, and community evidence indicates the password autofill feature itself is being discontinued entirely (comm-11), not extended to TOTP/passkey autofill.
- [claimed-docs] “Scroll down to the Autofill section and select Export Passwords.”
- [claimed-docs] “Scroll down to the Autofill section and select Export Passwords... Import your passwords.”
- [community] “Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…”
Authynone0/10Evidence pack shows no current Authy browser extension for autofilling TOTP or passkeys; the only extension mentioned is a deprecated Chrome extension used via hacky workarounds to extract keys, not autofill. Authy's own product is a mobile/desktop authenticator app, and passkey support referenced is for Twilio Verify (a separate API product), not the Authy app/extension.
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [claimed-docs] “Quickly verify users via SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, TOTP, Push, Silent Device Approval, and Email.”
Desktop
power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile
weight 2 · round to AuthyMicrosoft Authenticatornone0/10All evidence describes Microsoft Authenticator as a mobile app (phone/wearable), with no mention of a desktop application for codes or vault access; the product is explicitly mobile-only.
Authydisputedcontradicted4/10Twilio's docs list Authy as available on macOS, Windows, and Linux, suggesting first-class desktop apps, but hands-on community reports concretely contradict this, stating Authy is 'EOL'ing desktop apps' with 'near immediate deprecation' and no export path, leaving the desktop surface unreliable for power users. Missing for 10: no evidence of continued desktop app support with vault/code access, no independent confirmation the desktop client remains functional or maintained post-EOL announcement.
- [claimed-docs] “It's available for iOS, Android, macOS, Windows, and Linux.”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…”
Watch
everyday userRead my codes from my smartwatch without pulling out my phone
weight 1 · round to AuthyDocs confirm Authenticator notifications can be mirrored to a wearable device, which implies some code/approval visibility without pulling out the phone, but there's no explicit confirmation that time-based OTP codes themselves are readable on a smartwatch screen, nor any hands-on/community corroboration of this specific wearable experience. missing for 10: explicit documentation that OTP codes (not just approval notifications) display on smartwatch, independent/hands-on confirmation of the wearable experience.
- [claimed-docs] “you can mirror Authenticator notifications from your phone to your wearable device.”
Authy's own marketing page explicitly claims support on 'your phone, tablet, even your Apple Watch,' which directly matches the smartwatch-reading story, but this is a single first-party claim with no independent or hands-on confirmation of watch functionality (e.g., no community mention of using the watch app), and the API deprecation notice signals the product line is winding down. Missing for 10: independent/hands-on verification of the Apple Watch experience, detail on Wear OS or other smartwatch support, and confirmation the feature is still maintained post-deprecation.
- [claimed-docs] “On any device. Your phone, tablet, even your Apple Watch.”
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup
Not losing your accounts — encrypted backup, multi-device sync, recovery
Backup
security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented
weight 3 · round to AuthyMicrosoft Authenticatornone0/10Docs confirm a Cloud Backup feature exists (microsoft-authenticator-docs-9, -13) but provide no description of end-to-end encryption or a vendor-inaccessible key, and no encryption design documentation is cited anywhere. Community commentary even contrasts Microsoft's backup with an alternative app that explicitly offers 'encrypted backups' (microsoft-authenticator-comm-4), implying this property isn't established for Microsoft Authenticator.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…”
Authy's marketing page states backups are encrypted and 'only decrypt on the devices using a password only you know' (authy-docs-5), implying a vendor-can't-decrypt design, but there is no technical documentation of the encryption algorithm, key derivation, or threat model, and no independent audit confirming the vendor truly never holds the key. Community reports focus on account-takeover via device-add (authy-comm-15) and painful data export (authy-comm-13/14), not on breaking the underlying backup encryption, so this doesn't rise to a concrete dispute of the encryption claim itself. Missing for 10: a detailed whitepaper/spec of the E2E encryption scheme, key management details, and independent security audit or crypto review corroborating the zero-knowledge claim.
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “The Twilio exploit allowed the hackers to add a new device to existing Authy accounts. This allowed them to sync the keys between devices wi…”
Multi device
everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically
weight 2 · round drawnMicrosoft Authenticatordisputedcontradicted4/10Docs describe Cloud Backup that lets you restore accounts to a new device (docs-9, docs-13), but this is backup/restore rather than true simultaneous multi-device sync across phone, tablet, and computer — there's no evidence of a tablet or desktop client. Community reports directly contradict reliability of this backup: users report Authenticator updates wiping all account data and causing lockouts (comm-1, comm-3), undermining the claim that data stays reliably available across devices. Missing for 10: evidence of simultaneous real-time sync across phone/tablet/desktop clients, and resolution of documented data-loss/backup failure reports.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…”
- [community] “using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…”
Authydisputedcontradicted4/10Docs and community confirm sync across phone/tablet (and even Apple Watch) works well and is a headline feature (authy-docs-3, authy-docs-4, authy-docs-16, authy-comm-1), but the 'computer' part of the story is directly contradicted: community reports Authy EOL'd its desktop apps, breaking the phone/tablet/computer parity the docs still describe (authy-comm-10, authy-comm-18). Missing for 10: confirmation that desktop/computer sync still functions today, and resolution of the desktop deprecation vs docs claim.
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “On any device. Your phone, tablet, even your Apple Watch.”
- [claimed-docs] “It's available for iOS, Android, macOS, Windows, and Linux.”
- [community] “I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).”
- [community] “They intentionally make it really hard to migrate your data off their app under the premise of 'security'. Now they are EOL'ing desktop apps…”
- [community] “I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will…”
Recovery
everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device
weight 3 · round to AuthyMicrosoft Authenticatordisputedcontradicted5/10Microsoft documents a Cloud Backup feature explicitly designed to restore accounts on a new device after phone loss (docs-9, docs-13), which matches the story's claim of a documented recovery path. However, a concrete hands-on community report describes the opposite outcome — an app update wiped all backed-up data and locked the user out of every account, with the poster citing it as a known reliability issue (comm-1, comm-3) — directly contradicting the documented recovery guarantee. missing for 10: independent verification that Cloud Backup restore reliably works, resolution of the reported wipe/lockout bug, and clarity on how backup interacts with app updates.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
- [community] “This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…”
- [community] “using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…”
Authy's official docs describe an encrypted backup feature that restores 2FA tokens to a new device using a user-known password, plus multi-device sync and device management (authy-docs-3,4,5,8,10), and a community user confirms this recovery path works in practice after phone loss/SIM replacement (authy-comm-19). Some community friction exists around exporting data to competing apps, but that's a separate migration-away concern, not evidence the phone-loss recovery path itself fails. Missing for 10: a detailed first-party step-by-step restore walkthrough, and broader independent corroboration beyond a single community anecdote.
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “On any device. Your phone, tablet, even your Apple Watch.”
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
- [claimed-docs] “View information, rename, and remove lost/stolen devices.”
- [claimed-docs] “Add new devices with SMS, voice or existing device approval.”
- [community] “I've been using Authy as a backup for 1Password's 2FA since in a worst-case scenario I can get a replacement SIM card and get back into my 1…”
Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin
Shared and managed use — shared vaults, org policies, programmatic provisioning
Automation
ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces
weight 2 · round to AuthyMicrosoft Authenticatornone0/10No evidence of any API, CLI, or programmatic surface for creating/updating vault entries or TOTP secrets; Microsoft Authenticator is a manual mobile app with QR-based account addition, and probes for API/docs endpoints returned 404s. missing for 10: any documented API/SDK/CLI for programmatic vault management, evidence of agent-accessible interfaces, confirmation of automated secret seeding.
- [probe] “PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…”
- [claimed-docs] “Scan the QR code or download and install Authenticator from the Apple app store.”
Authydisputedcontradicted2/10Docs mention an SDK for 'the Authy API' to integrate 2FA, but Twilio's own docs page (probe) states the Authy API is closed to new customers and being deprecated with no new integrations, and multiple community reports confirm there is no supported way to programmatically seed, export, or update vault entries — users describe extreme difficulty or hacky workarounds to even extract secrets. This directly contradicts any claim of a documented programmatic surface for agent-driven vault creation/updates. Missing for 10: any current API/SDK for creating or updating TOTP vault entries, official export/import endpoints, and first-party agent integration examples.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [claimed-docs] “So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
Policy
it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app
weight 1 · round drawnMicrosoft Authenticatornone0/10Evidence only hints that notifications may be gated 'if allowed by your administrator' and that location-sharing is required for conditional access, but there is no documentation of an admin console or policy set that lets IT enforce app lock, restrict export, or mandate strong master credentials across all org members. Community evidence even suggests admins lack granular control tools (comm-6), reinforcing the absence of such enterprise policy enforcement in this pack.
- [claimed-docs] “You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.”
- [claimed-docs] “When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.”
- [claimed-docs] “You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
Authynone0/10Authy's evidence pack shows only consumer-facing features (per-device PIN/TouchID lock, backup password, device management) with no mention of any organization/admin console, centralized policy enforcement, or IT-admin controls across a team of users. The product is also being deprecated in favor of Verify, with no admin management surface described anywhere.
- [claimed-docs] “Use TouchID, PIN protection and passwords to protect access to your 2FA tokens.”
- [claimed-docs] “View information, rename, and remove lost/stolen devices.”
- [claimed-docs] “Disable future Authy app installations for improved security.”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
Sharing
it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control
weight 2 · round drawnMicrosoft Authenticatornone0/10Microsoft Authenticator is a personal/individual authenticator app with no evidence of shared vaults, collections, or per-member access control for teams; its passwords feature is even being discontinued. Missing for 10: shared vault/collection feature, per-member access control, admin sharing management console.
- [community] “Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…”
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [claimed-docs] “Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.”
Authynone0/10Authy is a personal authenticator app with no evidence of shared vaults, collections, or per-member access control for team/admin management; evidence only covers individual multi-device sync and backup features. Community evidence even highlights difficulty exporting/sharing data at all, reinforcing the lack of team-sharing capability.
- [claimed-docs] “Sync 2FA across mobile and tablet.”
- [claimed-docs] “Use our backup feature incase you lose your phone. We encrypt your data, and only decrypt on the devices using a password only you know.”
- [community] “Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?”
- [community] “I just migrated off of Authy last week... Never liked it but they make it extremely difficult to export your data. Twilio really doesn't wan…”
Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core
The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens
Enrollment
everyday userScan a QR code and immediately start generating TOTP codes for a new account
weight 3 · round to AuthyMicrosoft Authenticatordisputedcontradicted5/10Microsoft's own docs confirm the app supports one-time-password codes for two-step verification (docs-12), implying QR-based account setup generates TOTP codes offline. However, hands-on community reports describe a known QR-scan bug that forces users to cancel the dialog and add accounts manually without the QR code (comm-3), and another user notes the QR codes Microsoft issues for its own accounts are non-standard and rejected by other TOTP clients (comm-6), directly contradicting a smooth 'scan and immediately generate' experience. missing for 10: no first-party doc walking through the exact 'add account via QR scan' flow, and no resolution/acknowledgment of the reported scan failures.
- [claimed-docs] “As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…”
- [community] “using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
Authy's own product page states it can capture 2FA QR codes from major providers and lists TOTP as a supported authentication method, directly matching the scan-and-generate story, and community comments confirm ongoing everyday use of the app for this purpose. Missing for 10: a first-person hands-on account of the exact scan-to-code flow and more detailed onboarding documentation beyond the marketing feature list.
- [claimed-docs] “Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.”
- [claimed-docs] “TOTP (Authenticator Apps)”
- [community] “I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).”
- [community] “I've been using Authy as a backup for 1Password's 2FA since in a worst-case scenario I can get a replacement SIM card and get back into my 1…”
Offline
power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes
weight 2 · round drawnMicrosoft Authenticatordisputedcontradicted4/10Microsoft's own docs claim codes work without an internet connection or phone service (microsoft-authenticator-docs-2), but hands-on community reports contradict this for real-world enterprise use: one user reports 'ms authenticator doesn't generate a code until I first log into the vpn using exchange creds' (microsoft-authenticator-comm-10), and another notes the app issues non-standard QR codes that lock users into the vendor's app rather than plain TOTP (microsoft-authenticator-comm-6), undermining the 'no vendor account required' and pure-offline claims for many real deployments. Missing for 10: independent technical verification of offline TOTP generation across account types, and confirmation that no Microsoft account/login is ever required to view codes.
- [claimed-docs] “The codes don't require you to be on the internet or connected to data, so you don't need phone service to sign in.”
- [community] “it seems to be a push notification where the ms authenticator doesn't generate a code until I first log into the vpn using exchange creds.”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
- [community] “My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…”
Authydisputedcontradicted4/10Authy's own docs claim codes can be viewed without internet ('access secured websites without internet access on your phone'), but the product fundamentally requires creating a Twilio/Authy account tied to a phone number before any TOTP codes can be generated or viewed, and codes are further gated behind an app password — directly contradicting the 'no vendor account required' part of the story. Community evidence confirms this account-centric architecture (phone-number-as-username, multi-device sync tied to account, extraction of underlying seeds required hacky workarounds via a deprecated debug mode rather than a supported offline export).
- [claimed-docs] “You can still access secured websites without internet access on your phone.”
- [community] “I started using Authy long ago because it supports multiple devices and isn't linked to any other account (Google/Microsoft).”
- [community] “This doesn't scare me because in Authy you also set a password which without you cannot access the codes. The phone number here just acts as…”
- [community] “After a lot of trouble, I was able to extract my private keys from Authy by installing their deprecated Chrome extension and using some hack…”
- [community] “Note how insane the Authy export instructions are: 'Paste in a bunch of code to an Electron app running Authy in debug mode to dump the toke…”
- [community] “services with Authy-integrated MFA (like Twitch) are 'managed' by Authy so it can regenerate the secret on the fly; your previously extracte…”
Organization
power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence describes organizational features like search, folders/groups, or per-account service icons for managing many tokens; docs cover backup, passwordless sign-in, and notifications but not organization/search UX. Community evidence even suggests account list issues (duplicate/overwrite concerns) rather than robust organization tools. Missing for full credit: any mention of search, folder/grouping, or icon-based organization of accounts.
- [claimed-docs] “This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…”
- [community] “I have many accounts with the same user names, and they don't get overwritten. There might be some design flaw somewhere, but it's surely no…”
Authynone0/10Evidence shows only basic token/QR capture (service icons implied) with no mention of search or folder/group organization; a community user explicitly complains 'can't we please have alphabetization?' indicating the app lacks even simple sorting, let alone search/folders for power users managing dozens of tokens.
- [claimed-docs] “Easily capture 2FA QR codes from Facebook, Amazon, Google, Microsoft, Dropbox and many more.”
- [community] “My guess is that most of the people who worked on Authy have fallen by the wayside after the Twilio acquisition. It's annoying every time I …”
Variants
power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths
weight 2 · round drawnMicrosoft Authenticatornone0/10No evidence anywhere in the pack indicates Microsoft Authenticator supports HOTP counters, Steam Guard, or custom period/digit-length TOTP tokens; docs only describe standard push/OTP sign-in flows. Community evidence even suggests the opposite — its QR codes are non-standard TOTP and rejected by other clients, implying inflexibility rather than support for non-standard token types.
- [claimed-docs] “As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…”
- [community] “people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…”
Authynone0/10No evidence anywhere in the pack mentions Steam Guard support, HOTP counter-based tokens, or custom period/digit configurations; documentation only references standard TOTP and QR-code capture from mainstream services. Absence of evidence for this applicable power-user axis yields 'none'.
Not comparable on these axes
ai-native userPlug MCP servers into this product so it can use their tools
weight 3 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is a consumer authentication/MFA app, not an AI agent or platform with tool-use capability; plugging in MCP servers is a category error for this product type.
ai-native userSubscribe to events via webhooks
weight 2 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is a consumer mobile authentication app, not a platform with an event/webhook subscription API; webhook subscriptions are a wrong axis for this product category.
Authynone0/10No evidence of any webhook subscription capability in Authy's docs or community reports; the product's API is deprecated with no new programmatic integrations mentioned. This is a fair axis for an authentication/API platform, but no support is documented.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
ai-native userGet AI-generated insights and suggestions from my data inside the product
weight 2 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is an authentication/security app with no data-analysis or AI-insights feature set; generating AI-driven insights from user data is outside its category.
ai-native userDelegate tasks to a built-in AI assistant inside the product
weight 3 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is an authentication/security app, not an AI assistant platform; no evidence of any built-in AI assistant or agent delegation feature. This capability is entirely outside the product's category.
ai-native userExplore an interactive API reference with runnable examples
weight 2 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is a consumer mobile authentication app, not a developer API/platform product; an interactive API reference with runnable examples is not a relevant axis for this product category.
Authynone0/10No evidence of an interactive API reference with runnable examples for Authy; docs pack only describes SDKs and app features, and the Authy API itself is now closed/deprecated in favor of Verify, with no mention of interactive docs or runnable code samples.
- [claimed-docs] “we provide an SDK for common web languages. If your language is supported, it's the fastest way to get started.”
- [claimed-docs] “So you don't have to use the Authy API directly to integrate two-factor authentication into your app, we provide an SDK for common web langu…”
- [probe] “PROBE runtime (recorded 2026-09-15): Twilio's own docs page carries the deprecation notice verbatim — 'The Authy API is now closed to new cu…”
ai-native userTest against a sandbox environment without touching production data
weight 1 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is a consumer/enterprise authentication app, not a developer platform or API product; there is no concept of a sandbox environment for testing against it. This is a category error for this product type.
ai-native userDefine rules that trigger actions automatically on events
weight 3 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is an authentication/MFA app, not a rules-engine or automation platform; there is no concept of user-defined event-triggered rules in its feature set. This axis is a category error for this product type.
ai-native userSchedule recurring jobs or workflows
weight 2 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is an identity/authentication app, not a workflow automation or job-scheduling tool; scheduling recurring jobs is outside its product category.
ai-native userVersion, review, and roll back my automations
weight 1 · not comparableMicrosoft Authenticatorn/aMicrosoft Authenticator is an authentication app, not an automation/workflow tool with versionable automations to review or roll back — this axis is a category error for this product type.