Skip to content

Authenticator Apps Arena

Microsoft Authenticator vs Proton Pass

Proton Pass wins · 428 (14 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    Microsoft Authenticatornone0/10

    Probes show no llms.txt, no markdown docs, and no OpenAPI spec available for Microsoft Authenticator's documentation site; there is no evidence of agent-oriented documentation format.

    • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
    • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
    Proton Passnone0/10

    No llms.txt or agent-oriented docs found; probes explicitly return 404 for llms.txt and docs.md endpoints, and no evidence mentions agent-readable documentation formats.

    • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Proton Pass
    Microsoft Authenticatornone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Proton Passpartialprobed6/10

      Proton Pass ships an official CLI documented as designed for scripts, deployments, and CI/CD pipelines, supporting CRUD on vaults and items — a clear headless/automation capability. However, evidence is limited to vendor blog docs with no independent/hands-on corroboration of CI usage, no details on authentication flow for non-interactive/headless environments, and no community validation of real-world CI deployment. Missing for 10: independent hands-on CI usage reports, details on non-interactive auth/session handling for automation, and broader ecosystem examples (e.g., GitHub Actions integration).

      • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
      • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
      • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
      • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
    • ai-native userConnect an agent via an official MCP server

      weight 3 · round drawn
      Microsoft Authenticatornone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Proton Passnone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        • ai-native userUse an official CLI

          weight 2 · round to Proton Pass
          Microsoft Authenticatornone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            Proton Passfullprobed7/10

            Proton Pass has an official CLI documented in a first-party blog post that supports CRUD on vaults and items (including SSH keys) and secret retrieval for scripts/CI/CD pipelines, which is directly relevant to AI-native/agentic automation workflows. Missing for 10: independent/hands-on corroboration of the CLI's reliability, no mention of AI-agent-specific integrations or MCP-style tooling, and no detail on scripting API depth or language bindings.

            • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
            • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
            • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
            • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
          • ai-native userDrive the product through a documented public API

            weight 3 · round to Proton Pass
            Microsoft Authenticatornone0/10

            Microsoft Authenticator is a consumer mobile app with no evidence of a documented public API for programmatic/AI-driven control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404s.

            • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
            • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
            • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
            Proton Passpartialprobed5/10

            Proton Pass offers a CLI for CRUD operations on vaults and items (passwords, notes, SSH keys, etc.) usable in scripts/CI pipelines, which provides programmatic access, but this is a CLI wrapper rather than a documented public REST/GraphQL API with SDKs, and llms.txt/docs.md probes both 404. missing for 10: a formal public API specification (REST/GraphQL/SDK), API reference docs, and independent developer corroboration of programmatic/agentic use beyond the CLI.

            • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
            • [claimed-docs] Create, read, update, and delete vaults
            • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
            • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
            • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
            • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
            • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
          • ai-native userIssue scoped/least-privilege API credentials for an agent

            weight 2 · round drawn
            Microsoft Authenticatornone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              Proton Passnone0/10

              Proton Pass CLI supports retrieving secrets/items for CI/CD and vault-level CRUD, but there is no evidence of issuing scoped or least-privilege API credentials/tokens specifically for an AI agent (e.g., fine-grained scopes, agent-specific permission tiers). Vaults provide organizational grouping, not credential scoping mechanisms for automated agents.

              • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
              • [claimed-docs] Create, read, update, and delete vaults
              • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
              • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
            • ai-native userBuild against official SDKs

              weight 2 · round drawn
              Microsoft Authenticatornone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Proton Passnone0/10

                Evidence shows only a CLI tool for secrets retrieval in CI/CD pipelines, not a developer SDK for building applications; no mention of SDKs, API libraries, or language bindings for programmatic integration exists in the evidence pack.

                Agentic features

                1. ai-native userSet up automations that run autonomously in the background

                  weight 2 · round drawn
                  Microsoft Authenticatornone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Proton Passnone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    • ai-native userOperate the product with natural-language commands

                      weight 2 · round drawn
                      Microsoft Authenticatornone0/10

                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        Proton Passnone0/10

                        Proton Pass offers a CLI for scripted secret retrieval and CRUD operations, but there is no evidence of natural-language command support, AI assistant integration, or conversational interface anywhere in the docs or community discussion. Missing for 10: any NL command parsing, chat/AI interface, or agentic natural-language control.

                        Api quality

                        1. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                          weight 2 · round drawn
                          Microsoft Authenticatornone0/10

                          Microsoft Authenticator is a consumer mobile app for authentication, not an API product, and no OpenAPI/machine-readable spec is offered; probes for openapi.json, llms.txt, and docs-md endpoints all returned 404.

                          • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                          • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                          • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                          Proton Passnone0/10

                          No evidence of a machine-readable API spec (OpenAPI or similar); only a CLI tool for scripts/CI/CD is documented, and probes for llms.txt and docs-md endpoints both returned 404.

                          • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
                          • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
                          • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                        2. ai-native userRely on versioned APIs with a documented deprecation policy

                          weight 2 · round drawn
                          Microsoft Authenticatornone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                            Proton Passnone0/10

                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                            Automation depth — how much of the product can run unattendedAutomation depth

                            How much of the product can run unattended

                            1. ai-native userPerform bulk operations across many items at once

                              weight 2 · round to Proton Pass
                              Microsoft Authenticatornone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                Proton Passpartialclaimed5/10

                                The official CLI supports scripted CRUD on vaults and items (passwords, notes, SSH keys, etc.) which could be used to script bulk operations, and the import/export tools allow migrating many items at once. However, there is no documented explicit 'bulk edit/delete/tag' feature or batch API, and no community evidence of anyone actually scripting bulk operations at scale. Missing for 10: dedicated bulk-action API/UI, documented batch limits, and independent confirmation of large-scale scripted use.

                                • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                • [claimed-docs] Create, read, update, and delete vaults
                                • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.
                                • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file

                              Openness — open source, data portability, and self-hosting storiesOpenness

                              Open source, data portability, and self-hosting stories

                              1. ai-native userDo everything through the API that I can do in the UI

                                weight 2 · round to Proton Pass
                                Microsoft Authenticatornone0/10

                                Microsoft Authenticator is a consumer mobile app with no evidence of any public API for programmatic control of authentication actions; probes for API/docs endpoints all 404. No evidence supports API parity with UI functionality.

                                • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                Proton Passpartialprobed5/10

                                Proton Pass ships a CLI/API that supports CRUD on vaults and items (passwords, notes, cards, identities, SSH keys, custom items), enabling scripted/CI access similar to core UI functions. However, there's no evidence the CLI/API exposes other UI capabilities like vault sharing, TOTP generation, Pass Monitor/Sentinel checks, alias management, or emergency access. Missing for 10: API coverage for sharing, TOTP/2FA, monitoring, aliases, emergency access, and any independent confirmation of API completeness.

                                • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                • [claimed-docs] Create, read, update, and delete vaults
                                • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                              2. ai-native userExport all of my data in open formats and leave

                                weight 3 · round to Proton Pass
                                Microsoft Authenticatorpartialcommunity3/10

                                Microsoft documents an 'Export Passwords' feature for autofill data, but this covers only saved passwords, not the OTP/account seeds this app is centrally used for; TOTP/account data is only preserved via proprietary encrypted 'Cloud Backup' tied to a Microsoft account, not an open, portable format. Community evidence goes further, describing non-standard QR codes that other TOTP clients reject and users switching to open-source alternatives (Aegis) specifically because Authenticator lacks true open-format export/backup. missing for 10: open-format export of TOTP secrets/accounts, documented data-portability/leave workflow, independent confirmation that exported data works outside Microsoft's ecosystem.

                                • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                • [claimed-docs] Scroll down to the Autofill section and select Export Passwords... Import your passwords.
                                • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                Proton Passfullclaimed7/10

                                Proton Pass supports data export in multiple open, portable formats (unencrypted ZIP, CSV, PGP-encrypted JSON) allowing users to leave with their data, and also offers an import tool for migrating in from other managers. Missing for 10: independent hands-on verification of export completeness/fidelity, and no evidence of bulk API/CLI-based export for programmatic 'leave' workflows beyond CLI CRUD operations.

                                • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                                • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.
                              3. ai-native userRead the product's source under an open license

                                weight 2 · round to Proton Pass
                                Microsoft Authenticatornone0/10

                                Microsoft Authenticator is closed-source proprietary software; no evidence of any open-license source availability, and probes for docs/API artifacts also failed.

                                • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                Proton Passpartialcommunity5/10

                                Community evidence confirms Proton Pass client apps are open source on GitHub (protonpass org), but users note this covers only the clients, not the full product/server-side, and there was confusion over whether it was truly open-sourced. No first-party docs in the pack mention a license or open-source repo at all. Missing for 10: official documentation citing the open-source license, confirmation that server/backend code is open, and clarity on license terms.

                                • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                                • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…
                                • [community] Please note that we do have encrypted notes... And it is open source: https://github.com/protonpass
                              4. ai-native userSelf-host the core product

                                weight 3 · round drawn
                                Microsoft Authenticatornone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Proton Passnone0/10

                                  No evidence anywhere in the docs pack of a self-hosted server option; Proton Pass is offered only as a hosted SaaS with client apps, and community comments confirm only the client apps are open source while the backend/server is closed ('only the clients are open source').

                                  • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                                  • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…

                                Passkey support — passkeys in the vault — storage, sign-in, cross-ecosystem syncPasskey support

                                Passkeys in the vault — storage, sign-in, cross-ecosystem sync

                                Storage

                                1. everyday userThe app stores passkeys and signs me into websites and apps with them, not just TOTP codes

                                  weight 3 · round to Proton Pass
                                  Microsoft Authenticatornone0/10

                                  The evidence pack describes password-based sign-in removal, TOTP codes, push notifications, and password autofill/export, but nowhere mentions passkeys (FIDO2/WebAuthn credentials) being stored or used to sign into websites/apps. Missing for 10: any documentation of passkey creation, storage, or sign-in via Authenticator, and any independent confirmation of passkey support.

                                  • [claimed-docs] Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…
                                  • [claimed-docs] As the only way to sign in - just tap an approval on your phone to sign in. This is called going passwordless.
                                  • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…
                                  Proton Passpartialclaimed6/10

                                  Docs confirm Proton Pass supports passkeys for passwordless authentication and separately supports TOTP code generation, indicating both capabilities coexist rather than TOTP-only. However, there is no detailed description of the sign-in autofill flow for passkeys or independent/hands-on confirmation that passkey sign-in works reliably across sites/apps. Missing for 10: hands-on/community validation of passkey autofill and sign-in success, cross-platform passkey sync confirmation, and detail on browser/app integration for passkey use.

                                  • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                                Sync

                                1. power userMy passkeys sync across ecosystems — iOS, Android, Windows, Linux, browsers — instead of being locked to one platform vendor

                                  weight 2 · round to Proton Pass
                                  Microsoft Authenticatornone0/10

                                  The evidence pack covers Microsoft Authenticator's TOTP codes, push-notification MFA, cloud backup, and password autofill (now being discontinued), but contains no mention of passkey creation, storage, or cross-platform/cross-vendor passkey syncing across iOS, Android, Windows, Linux, or browsers. Passkey sync is a fair axis for an authenticator app, but nothing in the pack demonstrates it.

                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                  • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…
                                  Proton Passpartialcommunity4/10

                                  Proton Pass confirms passkey support (proton-pass-docs-8) and offers apps across iOS, Android, browsers, and a desktop app (with offline access per proton-pass-docs-9), implying cross-platform sync of vault items including passkeys. However, there's no explicit documentation confirming passkeys specifically sync across all platforms (vs. just being stored), and community comments note desktop app limitations/lack thereof at the time (proton-pass-comm-2, proton-pass-comm-14), raising doubt about full ecosystem parity. Missing for 10: explicit cross-platform passkey sync confirmation, Linux/Windows native app evidence beyond browser extensions, and independent hands-on verification that passkeys created on one platform are usable on another.

                                  • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                                  • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                  • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                  • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…

                                Portability — your secrets stay yours — open export, bulk import, device migrationPortability

                                Your secrets stay yours — open export, bulk import, device migration

                                Export

                                1. power userExport all my TOTP secrets in an open, readable format and leave for another app whenever I choose — no lock-in

                                  weight 3 · round to Proton Pass
                                  Microsoft Authenticatornone0/10

                                  Docs describe cloud backup/restore and password export/import, but none of this covers exporting TOTP secrets in an open format for use in another app; community evidence explicitly states Microsoft issues non-standard QR codes that other TOTP clients reject, indicating deliberate lock-in rather than portability.

                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                  • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                  • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                  • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                  Proton Passpartialclaimed5/10

                                  Proton Pass docs confirm a general data-export feature with multiple output options (PGP-encrypted ZIP, unencrypted ZIP, CSV), which supports the 'open, readable format' portability need, but no evidence explicitly confirms that TOTP secrets/seeds specifically are included in these exports (as opposed to being locked to Proton's own TOTP display). No community or hands-on report verifies successful TOTP secret export and re-import elsewhere. missing for 10: explicit confirmation that TOTP seeds are included in CSV/JSON export, independent verification that exported TOTP secrets can be imported into another app.

                                  • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                                  • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                                Import

                                1. power userImport tokens in bulk from other authenticator apps instead of re-enrolling every account by hand

                                  weight 2 · round to Proton Pass
                                  Microsoft Authenticatornone0/10

                                  The evidence pack only covers backing up/restoring Authenticator's own accounts via cloud backup, exporting passwords, and standard account setup via QR/manual entry — there is no mention of any bulk-import feature for pulling tokens from other authenticator apps (e.g., Google Authenticator, Aegis) into Microsoft Authenticator. Community evidence even suggests the opposite direction problem (comm-6: MS's QR codes are non-standard so other apps reject them), reinforcing that cross-app portability isn't supported.

                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                  • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                  Proton Passpartialclaimed4/10

                                  Proton Pass documents a general import tool that migrates passwords and other items from most major password managers, and it can generate TOTP codes for saved logins, but there is no explicit evidence of bulk import specifically from dedicated authenticator apps or of preserving TOTP secrets during that import process. missing for 10: explicit documentation of bulk TOTP import from authenticator apps, confirmation that the import tool carries over 2FA secrets rather than just passwords, independent or hands-on confirmation of successful token migration.

                                  • [claimed-docs] With our import tool, you can migrate passwords and other items from most major password managers in just a few minutes.
                                  • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                                Migration

                                1. everyday userMoving to a new phone transfers all my tokens in one guided step

                                  weight 2 · round to Proton Pass
                                  Microsoft Authenticatordisputedcontradicted5/10

                                  Docs describe a guided backup/restore flow (enable Cloud Backup, then restore accounts on a new device) via microsoft-authenticator-docs-9/13, which is the core mechanism for the story. However, hands-on community evidence reports the process failing catastrophically — one user's update wiped all data and locked them out of every account (microsoft-authenticator-comm-1), while another user reports no such issue (microsoft-authenticator-comm-2), showing the reliability of the 'one guided step' transfer is contested rather than confirmed. Missing for 10: independent verification that restore reliably works across devices/OS versions, and no acknowledgment/fix from Microsoft for the reported data-loss bug.

                                  • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                  • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                  • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                  • [community] I've been using Microsoft's one for my work accounts... I've never gotten that dialog, and have not had any issues with the accounts I've ad…
                                  Proton Passpartialclaimed3/10

                                  Proton Pass stores TOTP secrets in E2E-encrypted vaults that sync via the cloud (docs-5, docs-9, docs-16), which implies that logging into a new phone would pull down existing 2FA tokens, but no evidence explicitly documents a guided 'new device setup' or migration wizard for phones. The only explicit migration flows described are import/export between different password manager products (docs-3, docs-4, docs-11), not device-to-device transfer. missing for 10: explicit documentation of a phone-to-phone onboarding/migration step, confirmation that TOTP tokens sync automatically without manual re-entry, and any hands-on account of switching phones.

                                  • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                  • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                  • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.

                                Privacy posture — data-handling and privacy storiesPrivacy posture

                                Data-handling and privacy stories

                                1. ai-native userChoose where my data is stored (region/residency)

                                  weight 2 · round drawn
                                  Microsoft Authenticatornone0/10

                                  No evidence Microsoft Authenticator offers any data residency/region selection controls for AI-native users; this is an authentication app, not a data-storage platform, but the story is arguably still applicable since it stores backups (cloud backup, account data) somewhere. No documentation mentions region choice or residency options.

                                    Proton Passnone0/10

                                    No evidence pack item mentions data residency, regional data storage options, or any control over where user data is physically stored; Proton Pass docs cover encryption, vaults, CLI, and export but not region selection. Missing for 10: any documentation of data residency/region choice, EU-only or multi-region storage options, or admin controls for data location.

                                    • ai-native userPrevent my data from being used to train AI models

                                      weight 3 · round to Proton Pass
                                      Microsoft Authenticatornone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                        Proton Passpartialclaimed4/10

                                        Proton Pass's end-to-end encryption of all vault fields (docs-10) structurally means Proton cannot access plaintext user data, which would prevent it from being used to train AI models, but there is no explicit policy statement addressing AI training data use. Missing for 10: an explicit privacy policy or documentation statement about AI training opt-out/data usage, and independent confirmation of this claim.

                                        • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                      • ai-native userControl data retention and deletion

                                        weight 2 · round to Proton Pass
                                        Microsoft Authenticatorpartialcommunity3/10

                                        The app offers a toggle for sharing non-personal usage data and lets users enable/disable cloud backup or export/delete stored passwords, giving some control over what data is retained, but there is no documented account/data deletion policy, retention period, or explicit 'delete my data' feature, and community reports note unexpected data loss/location tracking rather than user-controlled retention. missing for 10: explicit data retention/deletion policy, dedicated 'delete my account data' control, independent verification that deletion actually removes backend data.

                                        • [claimed-docs] You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…
                                        • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                        • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                        • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]
                                        • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                        Proton Passpartialclaimed5/10

                                        Docs show users can create/read/update/delete vaults and items via the CLI/app, and can export or migrate data before deleting it, giving concrete control over stored data. However there is no explicit documentation on account-level data retention policies, deletion timelines, or how long Proton retains deleted data, which is central to a full 'control retention and deletion' story. Missing for 10: explicit retention-period/account-deletion policy documentation, independent confirmation that deleted data is purged.

                                        • [claimed-docs] Create, read, update, and delete vaults
                                        • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                        • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                                        • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                      • ai-native userOpt out of telemetry and usage tracking

                                        weight 2 · round to Proton Pass
                                        Microsoft Authenticatordisputedcontradicted4/10

                                        Microsoft's own docs mention an opt-in 'Usage Data' toggle that lets users control sharing of additional non-personal usage data, suggesting some telemetry control (microsoft-authenticator-docs-16). However, independent community reporting citing an Exodus Privacy audit says the app 'tracks your position all the time,' contradicting the notion that users can fully opt out of tracking (microsoft-authenticator-comm-5), and there is no documentation of a comprehensive telemetry/diagnostics opt-out beyond that single toggle. Missing for 10: explicit documentation of a full telemetry/diagnostics opt-out, first-party clarification of the location-tracking discrepancy, and independent verification that the toggle actually stops all usage tracking.

                                        • [claimed-docs] You can also allow the sharing of additional non-personal usage data by turning on the "Usage Data" toggle button on the app's Settings page…
                                        • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]
                                        Proton Passpartialcommunity4/10

                                        Community evidence confirms telemetry exists in the browser extension and can be disabled, but only via Proton account settings, not directly within the extension itself, indicating a real but limited opt-out mechanism (proton-pass-comm-13). No first-party documentation from Proton Pass describes a formal telemetry/opt-out policy or setting. missing for 10: official docs on telemetry settings, in-extension opt-out toggle, confirmation of no tracking by default.

                                        • [community] There's still nothing about the telemetry in the browser extension?... telemetry data is anonymous, but it's always sent to the remote endpo…

                                      Security posture — how it protects itself — app lock, E2EE design, audits, breach alertingSecurity posture

                                      How it protects itself — app lock, E2EE design, audits, breach alerting

                                      App lock

                                      1. everyday userThe app itself locks behind biometrics or a PIN, so a borrowed phone doesn't expose my codes

                                        weight 2 · round to Microsoft Authenticator
                                        Microsoft Authenticatorfullclaimed8/10

                                        Docs explicitly describe App Lock requiring device PIN or biometric authentication every time Authenticator is opened, directly matching the story. Missing for 10: independent/hands-on confirmation of App Lock reliability and default-on status.

                                        • [claimed-docs] When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.
                                        • [claimed-docs] Microsoft Authenticator is a free app that helps you sign in to all your accounts without using a password - just use a fingerprint, face re…
                                        Proton Passnone0/10

                                        No evidence pack item mentions app-level biometric or PIN lock for Proton Pass; the closest related items cover offline vault access, 2FA/TOTP generation, and encryption, but none address a lock screen or app-level authentication gate. Missing for 10: any mention of biometric unlock, app PIN lock, or auto-lock timeout feature.

                                        Audits

                                        1. security engineerThe vendor publishes independent security audits of the app and its sync protocol

                                          weight 2 · round drawn
                                          Microsoft Authenticatornone0/10

                                          No evidence of any published independent security audit of Microsoft Authenticator or its sync protocol; documentation only covers feature descriptions, and community threads discuss bugs, privacy concerns, and forced adoption but never an audit report. Missing for 10: any third-party audit report, pen-test disclosure, or vendor reference to an independent security assessment of the app or backup/sync protocol.

                                          • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                          • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                          • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                          • [community] It also tracks your position all the time. That is the bigger problem to me. [exodus-privacy report on com.azure.authenticator]
                                          Proton Passnone0/10

                                          No evidence of any independent third-party security audit report, pentest, or audit of the sync protocol; evidence only covers feature docs (encryption claims, Sentinel, Monitor) and open-source status debates in community threads. Community comments even question whether the client is fully open source, but no audit report is cited or linked anywhere.

                                          Monitoring

                                          1. power userThe app warns me when a service I use is breached or a stored credential is weak, reused, or exposed

                                            weight 2 · round to Proton Pass
                                            Microsoft Authenticatornone0/10

                                            No evidence that Microsoft Authenticator monitors for breached services or evaluates stored credentials for weakness/reuse/exposure; its password autofill feature is even being discontinued rather than expanded with security scanning. Missing for 10: breach monitoring, weak/reused password detection, exposed credential alerts.

                                            • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…
                                            Proton Passfullclaimed8/10

                                            Pass Monitor explicitly scans the dark web for credential leaks (breach detection), checks password health (weak/reused detection), and flags accounts missing 2FA, directly matching the story; this is documented as a core built-in feature rather than a third-party tool. Missing for 10: independent hands-on verification of Pass Monitor's accuracy/coverage and detail on exposed-credential alerting granularity beyond docs claims.

                                            • [claimed-docs] Pass Monitor is a security feature in Proton Pass that scans the dark web for credential leaks, checks on the health of your passwords, and …
                                            • [claimed-docs] Pass Monitor is a security feature in Proton Pass that scans the dark web for credential leaks, checks on the health of your passwords, and …
                                            • [claimed-docs] Proton Sentinel uses AI and human analysis to make it much harder for an attacker to take over your account.
                                            • [claimed-docs] Proton Sentinel is an advanced account protection program that provides maximum security for those who need it. It mitigates security threat…

                                          Push

                                          1. it adminPush-based sign-in includes phishing defenses — number matching, location context, and admin-enforced MFA policies

                                            weight 2 · round to Microsoft Authenticator
                                            Microsoft Authenticatorpartialcommunity5/10

                                            Evidence confirms admin-enforced push MFA policies (docs-3, comm-8, comm-9) and location-based context checks (docs-15), but there is no explicit mention of number matching as a phishing-resistant feature anywhere in the pack, and community threads focus on other issues (backup bugs, forced adoption) rather than validating anti-phishing controls. Missing for 10: number matching feature documentation, independent verification of phishing-resistance efficacy, and conditional access/policy configuration details for admins.

                                            • [claimed-docs] You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.
                                            • [claimed-docs] You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.
                                            • [community] IME some MS shops enforce use of it for 2fa to access company resources like vpn and etc. - for eg, the only reason this app exists on my ph…
                                            • [community] My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…
                                            Proton Passnone0/10

                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                            Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting

                                            Running it yourself — self-hosted servers, open-source clients

                                            Server

                                            1. it adminSelf-host the sync server on my own infrastructure and keep every secret inside my perimeter

                                              weight 2 · round drawn
                                              Microsoft Authenticatornone0/10

                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                Proton Passnone0/10

                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                Source

                                                1. security engineerThe client apps are open source, so the code handling my seeds can be inspected and community-reviewed

                                                  weight 2 · round to Proton Pass
                                                  Microsoft Authenticatornone0/10

                                                  No evidence that Microsoft Authenticator's client code is open source; it is a closed, proprietary Microsoft product with no public repository or community code review mentioned anywhere in the evidence pack.

                                                    Proton Passpartialcommunity6/10

                                                    Community evidence confirms Proton Pass clients are open source with a public GitHub repo (github.com/protonpass), directly supporting inspectability of the code handling secrets. However, other community comments show confusion/skepticism about finding or verifying this ('haven't been able to find the repository', 'it seems only the clients are open source'), and there's no first-party doc in the pack explicitly stating open-source status or citing security audits. Missing for 10: first-party documentation confirming open-source licensing/repo, evidence of independent security audits or community code review of the seed-handling logic, and clarity on scope (client-only vs. broader).

                                                    • [community] Please note that we do have encrypted notes... And it is open source: https://github.com/protonpass
                                                    • [community] It seems only the clients are open source? https://github.com/orgs/protonpass/repositories
                                                    • [community] Am I correct in believing that they haven't open-sourced Proton Pass yet?... Their official announcement post says it's now open source, how…

                                                  Surfaces — where it meets your workflow — IDE, CLI, web, PR comments, CI checksSurfaces

                                                  Where it meets your workflow — IDE, CLI, web, PR comments, CI checks

                                                  Automation

                                                  1. ai-native userAn agent can fetch a current TOTP code programmatically — via CLI or API — to complete a 2FA login inside an automated workflow

                                                    weight 2 · round to Proton Pass
                                                    Microsoft Authenticatornone0/10

                                                    Microsoft Authenticator is a mobile app with no documented CLI or API for programmatic TOTP retrieval; evidence even indicates its QR codes are non-standard and reject other TOTP clients, and probes confirm no API/OpenAPI surface exists. No evidence of any automation-friendly access to codes.

                                                    • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                    • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                    • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                    Proton Passpartialprobed4/10

                                                    Proton Pass ships an official CLI documented for scripting/CI-CD use that can 'securely retrieve secrets and other items' (docs-1/14) and lists item types it can read (docs-15), but TOTP/2FA codes are not explicitly named among the retrievable item types, and no docs or community evidence confirm a CLI/API command that outputs a live TOTP code for use in an automated login flow. missing for 10: explicit CLI/API command or output field for TOTP codes, hands-on confirmation of an agent successfully pulling a 2FA code programmatically.

                                                    • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                                    • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                                    • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                                    • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                    • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                                                  2. ai-native userExpose the vault through a local programmatic endpoint an agent can query for codes and secrets without screen-scraping the app

                                                    weight 1 · round to Proton Pass
                                                    Microsoft Authenticatornone0/10

                                                    No evidence of any local API, CLI, or programmatic endpoint for querying codes/secrets; probes confirm no llms.txt, docs-md, or OpenAPI endpoints exist, and the app is designed as a closed mobile experience with screen-capture disabled by default.

                                                    • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                    • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                                    • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                    • [claimed-docs] To see your OTP codes in screenshots or allow other apps to capture the Authenticator screen, turn on Screen Capture in Authenticator's Sett…
                                                    Proton Passpartialprobed6/10

                                                    Proton Pass ships an official CLI that allows secure programmatic retrieval of secrets, passwords, SSH keys, and other items across scripts and CI/CD pipelines, which functions as a local endpoint an agent could query instead of screen-scraping the app. However, the docs don't explicitly confirm TOTP/2FA code retrieval via the CLI (2FA generation is only described in the app itself), and there is no mention of an agent-specific or MCP-style interface, nor independent hands-on verification of CLI use by AI agents. Missing for 10: explicit CLI support for TOTP code retrieval, agent/MCP-oriented interface documentation, independent corroboration of CLI usage in agentic workflows.

                                                    • [claimed-docs] enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous delivery (CI/CD…
                                                    • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                                    • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                                    • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                    • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli

                                                  Browser

                                                  1. everyday userA browser extension autofills my TOTP codes and passkeys during login instead of making me retype them

                                                    weight 2 · round to Proton Pass
                                                    Microsoft Authenticatornone0/10

                                                    Evidence shows Microsoft Authenticator is a mobile app generating OTP codes and offering an in-app password Autofill feature, but there is no mention of a browser extension that autofills TOTP codes or passkeys, and community evidence indicates the password autofill feature itself is being discontinued entirely (comm-11), not extended to TOTP/passkey autofill.

                                                    • [claimed-docs] Scroll down to the Autofill section and select Export Passwords.
                                                    • [claimed-docs] Scroll down to the Autofill section and select Export Passwords... Import your passwords.
                                                    • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…
                                                    Proton Passfullcommunity8/10

                                                    Docs confirm TOTP code generation for saved logins and passkey support, and community evidence from an actual user confirms the browser extension autofills TOTP/2FA smoothly ('Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek'). Passkey autofill is documented but not independently corroborated with hands-on testing. Missing for 10: independent hands-on confirmation of passkey autofill specifically, and more detail on passkey UX in the extension.

                                                    • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                    • [claimed-docs] Passkeys allow you to authenticate yourself for online accounts without using passwords or passphrases.
                                                    • [community] I've been a Proton Unlimited subscriber... Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek.
                                                    • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…

                                                  Desktop

                                                  1. power userA first-class desktop app gives me codes and vault access on my computer, not just on mobile

                                                    weight 2 · round to Proton Pass
                                                    Microsoft Authenticatornone0/10

                                                    All evidence describes Microsoft Authenticator as a mobile app (phone/wearable), with no mention of a desktop application for codes or vault access; the product is explicitly mobile-only.

                                                      Proton Passdisputedcontradicted5/10

                                                      Proton's own support docs describe a dedicated desktop app with offline vault access and TOTP code generation (docs-9, docs-16, docs-5), suggesting a first-class desktop experience. However, community hands-on reports explicitly state there was no desktop app for Proton Pass ('And no desktop app for proton pass, maybe some day though?' and 'Pity it's only available on iOS and Android as apps and as browser extensions elsewhere'), directly contradicting the vendor's desktop-app documentation. Missing for 10: independent corroboration that the desktop app actually exists and works as described, and resolution of the timeline discrepancy between docs and community reports.

                                                      • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                                      • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                      • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                      • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                                      • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…

                                                    Watch

                                                    1. everyday userRead my codes from my smartwatch without pulling out my phone

                                                      weight 1 · round to Microsoft Authenticator
                                                      Microsoft Authenticatorpartialclaimed4/10

                                                      Docs confirm Authenticator notifications can be mirrored to a wearable device, which implies some code/approval visibility without pulling out the phone, but there's no explicit confirmation that time-based OTP codes themselves are readable on a smartwatch screen, nor any hands-on/community corroboration of this specific wearable experience. missing for 10: explicit documentation that OTP codes (not just approval notifications) display on smartwatch, independent/hands-on confirmation of the wearable experience.

                                                      • [claimed-docs] you can mirror Authenticator notifications from your phone to your wearable device.
                                                      Proton Passnone0/10

                                                      No evidence of a smartwatch app, watch companion, or complication for viewing TOTP codes; evidence only covers mobile, browser extension, and CLI surfaces, with community notes even lamenting lack of a desktop app. Missing for 10: any smartwatch app/companion, watch complication, or documentation of viewing codes without the phone.

                                                      • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                      • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…

                                                    Sync backup — not losing your accounts — encrypted backup, multi-device sync, recoverySync backup

                                                    Not losing your accounts — encrypted backup, multi-device sync, recovery

                                                    Backup

                                                    1. security engineerBackups are end-to-end encrypted with a key the vendor never holds, and the encryption design is documented

                                                      weight 3 · round to Proton Pass
                                                      Microsoft Authenticatornone0/10

                                                      Docs confirm a Cloud Backup feature exists (microsoft-authenticator-docs-9, -13) but provide no description of end-to-end encryption or a vendor-inaccessible key, and no encryption design documentation is cited anywhere. Community commentary even contrasts Microsoft's backup with an alternative app that explicitly offers 'encrypted backups' (microsoft-authenticator-comm-4), implying this property isn't established for Microsoft Authenticator.

                                                      • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                      • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                      • [community] Even for Microsoft accounts, use an alternative app for 2FA/MFA. Recently I switched to the open source Aegis, which allows encrypted backup…
                                                      Proton Passpartialclaimed5/10

                                                      Proton Pass documents that all vault data is end-to-end encrypted (docs-10) and offers a PGP-encrypted export option that could serve as a backup (docs-11), implying the vendor cannot read backed-up data. However, there is no dedicated 'backup' feature documentation (only export/import), and no detailed cryptographic architecture whitepaper or independent audit is cited to substantiate the zero-knowledge key design in depth. missing for 10: dedicated backup-feature docs, detailed encryption architecture/whitepaper, independent security audit confirming vendor never holds keys

                                                      • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                                      • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                                      • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.

                                                    Multi device

                                                    1. everyday userMy tokens are available on my phone, tablet, and computer at the same time, kept in sync automatically

                                                      weight 2 · round to Proton Pass
                                                      Microsoft Authenticatordisputedcontradicted4/10

                                                      Docs describe Cloud Backup that lets you restore accounts to a new device (docs-9, docs-13), but this is backup/restore rather than true simultaneous multi-device sync across phone, tablet, and computer — there's no evidence of a tablet or desktop client. Community reports directly contradict reliability of this backup: users report Authenticator updates wiping all account data and causing lockouts (comm-1, comm-3), undermining the claim that data stays reliably available across devices. Missing for 10: evidence of simultaneous real-time sync across phone/tablet/desktop clients, and resolution of documented data-loss/backup failure reports.

                                                      • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                      • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                      • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                      • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…
                                                      Proton Passpartialcommunity5/10

                                                      Docs confirm cross-platform clients (mobile apps, browser extensions, and a desktop app referenced in the desktop-app guide) and offline access that presumably reconciles when back online, implying cloud sync of vault items including TOTP tokens. However, no first-party documentation explicitly describes the sync mechanism or guarantees real-time multi-device consistency, and community comments note a historical lack of a desktop app and inconsistent browser-extension availability (e.g., Firefox ESR incompatibility), suggesting platform coverage has been uneven over time. Missing for 10: explicit sync/consistency documentation, independent verification that sync is truly automatic and near-instant across phone/tablet/computer.

                                                      • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                                      • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                      • [community] If you are paying for Pass Plus or Proton Unlimited then you have integrated 2FA/TOTP which Bitwarden also makes you pay for... And no deskt…
                                                      • [community] Pity it's only available on iOS and Android as apps and as browser extensions elsewhere. I would've been interested to check out a desktop p…
                                                      • [community] Can't use the Firefox extension, FF 102 ESR is apparently too old

                                                    Recovery

                                                    1. everyday userLosing my phone doesn't lose my accounts — a documented recovery path restores my tokens on a new device

                                                      weight 3 · round to Proton Pass
                                                      Microsoft Authenticatordisputedcontradicted5/10

                                                      Microsoft documents a Cloud Backup feature explicitly designed to restore accounts on a new device after phone loss (docs-9, docs-13), which matches the story's claim of a documented recovery path. However, a concrete hands-on community report describes the opposite outcome — an app update wiped all backed-up data and locked the user out of every account, with the poster citing it as a known reliability issue (comm-1, comm-3) — directly contradicting the documented recovery guarantee. missing for 10: independent verification that Cloud Backup restore reliably works, resolution of the reported wipe/lockout bug, and clarity on how backup interacts with app updates.

                                                      • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                      • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                      • [community] This happened to me when I updated MS Authenticator after not updating it for a while. It wiped out all data, and I got locked out of all ac…
                                                      • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…
                                                      Proton Passpartialclaimed4/10

                                                      Proton Pass stores TOTP codes and other secrets inside end-to-end encrypted vaults that live on Proton's servers (docs-5, docs-10), and offers export (docs-4/11) and Emergency Access (docs-20) features that could serve as backup/recovery mechanisms, implying data isn't lost with a device. However, there is no explicit documentation in the pack describing a dedicated 'lost phone / new device' recovery flow, account recovery phrase, or step-by-step restoration of 2FA tokens after device loss. Missing for 10: explicit account-recovery/recovery-phrase documentation, explicit cross-device sync confirmation, and a stated process for restoring TOTP secrets specifically after losing a device.

                                                      • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                      • [claimed-docs] Unlike other password managers, Proton Pass uses end-to-end encryption on every field you fill for the items you create (usernames, website …
                                                      • [claimed-docs] If you want to use your passwords elsewhere or create a separate hardcopy, you can easily export your data from Proton Pass.
                                                      • [claimed-docs] You have three options for export: 1. A ZIP file containing a PGP-encrypted JSON file 2. An unencrypted ZIP file 3. A CSV file
                                                      • [claimed-docs] Emergency Access

                                                    Team admin — shared and managed use — shared vaults, org policies, programmatic provisioningTeam admin

                                                    Shared and managed use — shared vaults, org policies, programmatic provisioning

                                                    Automation

                                                    1. ai-native userAn agent can create and update vault entries — seeding new TOTP secrets, storing credentials — through documented programmatic surfaces

                                                      weight 2 · round to Proton Pass
                                                      Microsoft Authenticatornone0/10

                                                      No evidence of any API, CLI, or programmatic surface for creating/updating vault entries or TOTP secrets; Microsoft Authenticator is a manual mobile app with QR-based account addition, and probes for API/docs endpoints returned 404s. missing for 10: any documented API/SDK/CLI for programmatic vault management, evidence of agent-accessible interfaces, confirmation of automated secret seeding.

                                                      • [probe] PROBE llms.txt: HTTP 404 at https://support.microsoft.com/llms.txt
                                                      • [probe] PROBE docs-md: HTTP 404 at https://support.microsoft.com/en-us/authenticator/microsoft-authenticator-faqs.md
                                                      • [probe] PROBE openapi: all candidate paths 404 (https://support.microsoft.com/openapi.json, https://support.microsoft.com/swagger.json, https://supp…
                                                      • [claimed-docs] Scan the QR code or download and install Authenticator from the Apple app store.
                                                      Proton Passpartialprobed6/10

                                                      Proton Pass CLI documentation shows programmatic create/read/update/delete of items (including passwords, secure notes, SSH keys) and vaults, which an agent could invoke via scripts. However, there's no explicit mention of TOTP secret seeding via the CLI, and no dedicated agent/AI integration or API/SDK beyond the CLI is documented, and no independent confirmation of these CLI capabilities working reliably. Missing for 10: explicit TOTP-seeding support via CLI, broader API/SDK for agents, and independent hands-on verification of programmatic write operations.

                                                      • [claimed-docs] Create, read, update, and delete vaults
                                                      • [claimed-docs] View, create, update, and delete items including passwords, secure notes, credit cards, identities, WiFi entries, custom items, and stored S…
                                                      • [claimed-docs] the CLI enables you to securely retrieve secrets and other items across scripts, deployments, and continuous integration/ continuous deliver…
                                                      • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli

                                                    Policy

                                                    1. it adminEnforce org-wide policies — require app lock, restrict export, mandate strong master credentials — across every member's app

                                                      weight 1 · round drawn
                                                      Microsoft Authenticatornone0/10

                                                      Evidence only hints that notifications may be gated 'if allowed by your administrator' and that location-sharing is required for conditional access, but there is no documentation of an admin console or policy set that lets IT enforce app lock, restrict export, or mandate strong master credentials across all org members. Community evidence even suggests admins lack granular control tools (comm-6), reinforcing the absence of such enterprise policy enforcement in this pack.

                                                      • [claimed-docs] You can set up notifications for your work or school account (if allowed by your administrator) or for your personal Microsoft account.
                                                      • [claimed-docs] When App Lock is enabled, you'll be asked to authenticate using your device PIN or biometric every time you open Authenticator.
                                                      • [claimed-docs] You'll need to share your location once every hour to ensure you're still within a country where you are allowed to access the resource.
                                                      • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                      Proton Passnone0/10

                                                      No evidence of org-wide admin policy controls (enforced app lock, export restrictions, mandated master password strength) for organization members; docs cover vaults, CLI, export, 2FA, sharing but nothing about admin-enforced policies across a team.

                                                      Sharing

                                                      1. it adminMy team can share TOTP-protected logins through shared vaults or collections with per-member access control

                                                        weight 2 · round to Proton Pass
                                                        Microsoft Authenticatornone0/10

                                                        Microsoft Authenticator is a personal/individual authenticator app with no evidence of shared vaults, collections, or per-member access control for teams; its passwords feature is even being discontinued. Missing for 10: shared vault/collection feature, per-member access control, admin sharing management console.

                                                        • [community] Microsoft Authenticator--a mobile app that provides 2FA--is discontinuing its password autofill feature and the passwords stored/used with t…
                                                        • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                        • [claimed-docs] Turn on the Cloud Backup toggle. Select a Microsoft personal account where the backup will be stored.
                                                        Proton Passpartialclaimed5/10

                                                        Evidence confirms Proton Pass supports TOTP/2FA generation for saved logins (docs-5) and secure vault sharing plus vault-based organization of items (docs-16, docs-17), which together imply TOTP items can be shared via vaults. However, there is no documentation of granular per-member access control (roles/permissions) or 'collections' as a distinct sharing unit, and no team-admin console evidence for managing member access levels within shared vaults. Missing for 10: explicit permission-level (viewer/editor/admin) documentation for shared vaults, evidence of 'collections' as an admin feature, and any IT-admin console showing per-member access management.

                                                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                        • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                        • [claimed-docs] Secure vault sharing

                                                      Totp core — the TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokensTotp core

                                                      The TOTP fundamentals — QR enrollment, organization, offline codes, non-standard tokens

                                                      Enrollment

                                                      1. everyday userScan a QR code and immediately start generating TOTP codes for a new account

                                                        weight 3 · round to Proton Pass
                                                        Microsoft Authenticatordisputedcontradicted5/10

                                                        Microsoft's own docs confirm the app supports one-time-password codes for two-step verification (docs-12), implying QR-based account setup generates TOTP codes offline. However, hands-on community reports describe a known QR-scan bug that forces users to cancel the dialog and add accounts manually without the QR code (comm-3), and another user notes the QR codes Microsoft issues for its own accounts are non-standard and rejected by other TOTP clients (comm-6), directly contradicting a smooth 'scan and immediately generate' experience. missing for 10: no first-party doc walking through the exact 'add account via QR scan' flow, and no resolution/acknowledgment of the reported scan failures.

                                                        • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…
                                                        • [community] using microsoft authenticator I just ran into this recently... it's a known issue that microsoft has no announced plan of fixing... I knew t…
                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                        Proton Passpartialcommunity5/10

                                                        Docs confirm Proton Pass generates TOTP codes for saved logins (proton-pass-docs-5) and community reports use it as their default 2FA tool (proton-pass-comm-12), but no evidence explicitly describes scanning a QR code to add a new TOTP secret and instantly getting codes. Missing for 10: explicit QR-code scanning workflow documentation, mobile camera scan support evidence, and independent hands-on confirmation of the scan-to-code flow.

                                                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                        • [community] I've been a Proton Unlimited subscriber... Proton Pass is my default for all 2FA. I love the browser extension, so easy and sleek.

                                                      Offline

                                                      1. power userCodes generate fully offline — no network, no vendor account required just to see my TOTP codes

                                                        weight 2 · round to Microsoft Authenticator
                                                        Microsoft Authenticatordisputedcontradicted4/10

                                                        Microsoft's own docs claim codes work without an internet connection or phone service (microsoft-authenticator-docs-2), but hands-on community reports contradict this for real-world enterprise use: one user reports 'ms authenticator doesn't generate a code until I first log into the vpn using exchange creds' (microsoft-authenticator-comm-10), and another notes the app issues non-standard QR codes that lock users into the vendor's app rather than plain TOTP (microsoft-authenticator-comm-6), undermining the 'no vendor account required' and pure-offline claims for many real deployments. Missing for 10: independent technical verification of offline TOTP generation across account types, and confirmation that no Microsoft account/login is ever required to view codes.

                                                        • [claimed-docs] The codes don't require you to be on the internet or connected to data, so you don't need phone service to sign in.
                                                        • [community] it seems to be a push notification where the ms authenticator doesn't generate a code until I first log into the vpn using exchange creds.
                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                        • [community] My company used to allow TOTP so many TOTP apps could be used instead of Microsoft Authenticator but my company disabled that a while ago. N…
                                                        Proton Passnone0/10

                                                        Proton Pass is fundamentally an account-based, encrypted-vault service — using it at all requires creating and logging into a Proton account, and TOTP codes are stored as fields within account-synced vaults. Evidence only shows that once logged in, offline access to already-synced vaults works (proton-pass-docs-9), but nothing supports generating/viewing TOTP codes without ever creating or authenticating a vendor account, which the story explicitly requires.

                                                        • [claimed-docs] You don’t need to do anything to access Proton Pass offline. Everything in your vaults is accessible whether you’re connected to the interne…
                                                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                                                      Organization

                                                      1. power userKeep dozens of tokens organized — search, folders or groups, and service icons — so the right code is always two taps away

                                                        weight 2 · round to Proton Pass
                                                        Microsoft Authenticatornone0/10

                                                        No evidence describes organizational features like search, folders/groups, or per-account service icons for managing many tokens; docs cover backup, passwordless sign-in, and notifications but not organization/search UX. Community evidence even suggests account list issues (duplicate/overwrite concerns) rather than robust organization tools. Missing for full credit: any mention of search, folder/grouping, or icon-based organization of accounts.

                                                        • [claimed-docs] This article describes how to back up information on all the accounts you have in Authenticator so that if you lose your mobile or get a new…
                                                        • [community] I have many accounts with the same user names, and they don't get overwritten. There might be some design flaw somewhere, but it's surely no…
                                                        Proton Passpartialcommunity4/10

                                                        Proton Pass supports TOTP generation tied to saved logins and vaults for organizing items into groups (e.g., personal vs. work), but there is no evidence of search functionality or service icons, and a community report explicitly notes the browser popup overlay was inadequate for managing hundreds of logins, suggesting scaling friction for power users. Missing for 10: dedicated TOTP search/filter feature, service icon display, and evidence of smooth navigation across dozens of tokens.

                                                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.
                                                        • [claimed-docs] Vaults can be used to organize items — in the example above, we have a vault for personal items and one for work items.
                                                        • [community] Would like to see web/desktop clients for this. When I used it recently I found the unexpandable pop-up overlay in the browser to not be ade…

                                                      Variants

                                                      1. power userNon-standard tokens work too — Steam Guard, HOTP counters, custom periods and digit lengths

                                                        weight 2 · round drawn
                                                        Microsoft Authenticatornone0/10

                                                        No evidence anywhere in the pack indicates Microsoft Authenticator supports HOTP counters, Steam Guard, or custom period/digit-length TOTP tokens; docs only describe standard push/OTP sign-in flows. Community evidence even suggests the opposite — its QR codes are non-standard TOTP and rejected by other clients, implying inflexibility rather than support for non-standard token types.

                                                        • [claimed-docs] As a way to sign in every time, by using a one-time password code to increase account security. This is called two-step verification or mult…
                                                        • [community] people pick MS Authenticator - it's because microsoft basically forces it on you, uses dark patterns to avoid letting you use any other stan…
                                                        Proton Passnone0/10

                                                        Evidence only confirms basic TOTP code generation for saved logins; no mention of Steam Guard tokens, HOTP counters, or custom period/digit length support anywhere in the docs or community discussion. Missing for 10: any documentation of Steam Guard support, HOTP counter-based tokens, or custom TOTP period/digit configuration.

                                                        • [claimed-docs] Proton Pass can securely generate TOTP codes for websites that you have saved login details for.

                                                      Not comparable on these axes

                                                      1. ai-native userPlug MCP servers into this product so it can use their tools

                                                        weight 3 · not comparable
                                                        Microsoft Authenticatorn/a

                                                        Microsoft Authenticator is a consumer authentication/MFA app, not an AI agent or platform with tool-use capability; plugging in MCP servers is a category error for this product type.

                                                          Proton Passn/a

                                                          Proton Pass is a password manager, not an AI agent or agent-serving platform; there is no evidence of MCP server functionality, and this axis is a category error for this product type.

                                                          • ai-native userSubscribe to events via webhooks

                                                            weight 2 · not comparable
                                                            Microsoft Authenticatorn/a

                                                            Microsoft Authenticator is a consumer mobile authentication app, not a platform with an event/webhook subscription API; webhook subscriptions are a wrong axis for this product category.

                                                              Proton Passnone0/10

                                                              No evidence of any webhook or event subscription mechanism; Proton Pass offers a CLI for CRUD operations but nothing about push/webhook notifications. Missing for 10: any webhook API, event subscription mechanism, or documentation referencing such a feature.

                                                              • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                                weight 2 · not comparable
                                                                Microsoft Authenticatorn/a

                                                                Microsoft Authenticator is an authentication/security app with no data-analysis or AI-insights feature set; generating AI-driven insights from user data is outside its category.

                                                                  Proton Passnone0/10

                                                                  Evidence only covers password/vault management, monitoring, and Sentinel's fraud-detection AI for account security — none of this provides AI-generated insights or suggestions derived from the user's stored data (e.g., summarization, pattern detection, recommendations beyond breach/weak-password alerts). No feature described as generating insights or suggestions from the data itself.

                                                                  • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                                    weight 3 · not comparable
                                                                    Microsoft Authenticatorn/a

                                                                    Microsoft Authenticator is an authentication/security app, not an AI assistant platform; no evidence of any built-in AI assistant or agent delegation feature. This capability is entirely outside the product's category.

                                                                      Proton Passn/a

                                                                      Proton Pass is a password manager; no built-in AI assistant for task delegation exists in the evidence, and this capability is outside the product's category (only AI-related mentions are Proton Sentinel's fraud-detection use of AI, not an assistant users can delegate tasks to).

                                                                      • ai-native userExplore an interactive API reference with runnable examples

                                                                        weight 2 · not comparable
                                                                        Microsoft Authenticatorn/a

                                                                        Microsoft Authenticator is a consumer mobile authentication app, not a developer API/platform product; an interactive API reference with runnable examples is not a relevant axis for this product category.

                                                                          Proton Passnone0/10

                                                                          No evidence of an interactive API reference or runnable examples; documentation covers CLI usage and product features only, and probes for docs/llms.txt endpoints returned 404. Missing for 10: interactive API reference, runnable code examples, developer API docs portal.

                                                                          • [probe] PROBE llms.txt: HTTP 404 at https://proton.me/llms.txt
                                                                          • [probe] PROBE docs-md: HTTP 404 at https://proton.me/support/pass.md
                                                                          • [probe] official CLI documented at https://proton.me/blog/proton-pass-cli
                                                                        • ai-native userTest against a sandbox environment without touching production data

                                                                          weight 1 · not comparable
                                                                          Microsoft Authenticatorn/a

                                                                          Microsoft Authenticator is a consumer/enterprise authentication app, not a developer platform or API product; there is no concept of a sandbox environment for testing against it. This is a category error for this product type.

                                                                            Proton Passn/a

                                                                            Proton Pass is a password manager, not a platform with sandbox/staging environments for testing against production-like data; this axis is a category error for its product type.

                                                                            • ai-native userDefine rules that trigger actions automatically on events

                                                                              weight 3 · not comparable
                                                                              Microsoft Authenticatorn/a

                                                                              Microsoft Authenticator is an authentication/MFA app, not a rules-engine or automation platform; there is no concept of user-defined event-triggered rules in its feature set. This axis is a category error for this product type.

                                                                                Proton Passn/a

                                                                                Proton Pass is a password manager; defining automation rules that trigger actions on events is outside its product category (no workflow/automation engine exists), so this axis does not apply.

                                                                                • ai-native userSchedule recurring jobs or workflows

                                                                                  weight 2 · not comparable
                                                                                  Microsoft Authenticatorn/a

                                                                                  Microsoft Authenticator is an identity/authentication app, not a workflow automation or job-scheduling tool; scheduling recurring jobs is outside its product category.

                                                                                    Proton Passn/a

                                                                                    Proton Pass is a password manager with a CLI for secret retrieval in scripts/CI, not a workflow/job scheduling platform; scheduling recurring jobs is outside its product category.

                                                                                    • ai-native userVersion, review, and roll back my automations

                                                                                      weight 1 · not comparable
                                                                                      Microsoft Authenticatorn/a

                                                                                      Microsoft Authenticator is an authentication app, not an automation/workflow tool with versionable automations to review or roll back — this axis is a category error for this product type.

                                                                                        Proton Passn/a

                                                                                        Proton Pass is a password manager, not an automation/workflow tool; versioning, reviewing, and rolling back 'automations' is not a concept that applies to its product category.