Two-factor authentication center
Compare authenticator apps, security keys, passkeys and SMS with clear attention to phishing resistance and device-loss recovery.
How to use this section
Use the Two-factor authentication center directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
The strongest available method is not always the most resilient setup. Compare phishing resistance with device-loss recovery, enroll a backup and avoid keeping every factor and recovery code on one phone.
How to Choose a Two-Factor Authentication Method
Match passkeys, security keys, authenticator apps, push prompts or SMS to risk and recovery needs.
Open guide →Authenticator App vs SMS Codes
Compare authenticator apps, text-message codes, push prompts and hardware security keys.
Open guide →Hardware Security Key Guide
Understand FIDO security keys, backups, enrollment and recovery planning.
Open guide →What to Do If You Lose Your Authenticator Phone
Recover safely using trusted devices, backup codes and official service processes.
Open guide →Recovery Codes Explained
Learn how one-time recovery codes work, where to store them and when to replace them.
Open guide →SIM Swaps and SMS Two-Factor Authentication
Understand phone-number takeover risk and when to choose stronger authentication.
Open guide →TOTP Authenticator App Guide
Learn how time-based one-time password apps work and how to protect the shared secret.
Open guide →Transfer an Authenticator App Safely
Move TOTP accounts to a new phone without exposing seeds or locking yourself out.
Open guide →What Is Two-Factor Authentication?
Understand authentication factors, one-time codes, security keys and why a second factor reduces password-only risk.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.