Leaving Authy
Authy has no export, so this is the honest version: what works, what doesn't, and how long it takes.
Short version: No export. Re-enrol each account, or use a community tool on a desktop.
Steps
- Write down what you have
Open Authy and list every account. You'll re-enrol these one at a time. Twenty accounts is an evening; a hundred is a weekend.
- Install Vault2FA, keep Authy for now
Don't delete Authy until the last account is moved and you've made a Vault2FA backup. Both apps producing codes at once is fine.
- Re-enrol each account
Sign in to the service, go to its security settings, turn two-factor off and back on. It shows a new QR code — scan it with Vault2FA (+ → Scan QR code). Confirm with the code Vault2FA shows. Save the new recovery codes.
- Or: the desktop route
If you have Authy Desktop still installed (it was discontinued in 2024), community tools can pull the seeds out through its debugger and produce a list of
otpauth://links. Save that list as a text file and open it in Vault2FA via + → Import from another app. Treat any tool that asks for your Authy password or backup password with suspicion — the legitimate ones don't. - Make a backup
Settings → Backup → Export encrypted backup. Choose a passphrase you'll remember and store the file somewhere that isn't the phone.
- Delete Authy
Uninstall it, then in each service's settings remove any lingering Authy/SMS fallback you no longer want.
Worth knowing
- Authy's multi-device sync kept your seeds on Twilio's servers. Re-enrolling rotates every one of them, which is a good thing after the 2024 breach that exposed 33 million phone numbers.
- Vault2FA has no server, so nothing like that can happen here — and there's also no sync. Use the encrypted backup to move to a new phone.
Afterwards
Make an encrypted backup (Settings → Backup) before you delete the old app, and check the support page if a code is rejected — it is nearly always the phone's clock.
Stuck? [email protected]. Never send a secret or a backup file by email.