Skip to main content
PVAVRT
Google Authenticator Transfer to a New Phone Without Lockout

September 25, 2026

Google Authenticator Transfer to a New Phone Without Lockout

The two routes Google documents for moving Authenticator codes to a new handset, the export and import QR flow step by step, what signing the app in to a Google Account actually backs up, and the fallback order for Gmail, GitHub and X when the old phone is already gone.

Google Account2FAAccount SecurityRecoveryHow-To
Table of contents
  1. Google Authenticator transfer to new phone: pick your route first
  2. Transfer with the export and import QR codes
  3. Google Authenticator cloud sync: what signing in backs up
  4. Transfer Google Authenticator to new phone without old phone
  5. Fallback order for Gmail, GitHub and X
  6. Google Authenticator didn’t transfer to new phone: common causes
  7. Before the next phone change

Replacing a handset locks people out of their own accounts when the authenticator codes never move across. Transferring Google Authenticator to a new phone is a deliberate step inside the app itself. Google documents two clean routes, the app’s own export and import QR codes and signing the app in to a Google Account so codes sync, plus one messy situation where the old handset is already wiped, sold or lost. All three are below, with Google’s published steps quoted as they appear, and a per-service fallback order for Gmail, GitHub and X. Help pages checked on 25 September 2026.

Google Authenticator transfer to new phone: pick your route first

Everything downstream depends on one fact about your current setup, so establish it before touching either device.

Codes synced to a Google Account

Newer versions of the app can hold your codes against your Google identity. Google’s Authenticator help page says you “can synchronize your verification codes across all your devices, simply by signing in to your Google Account”. This route needs version 6.0 or above on Android, or 4.0 or above on iPhone and iPad.

Codes stored only on the old phone

Used without signing in, the app keeps its secrets on that one device and nowhere else. Google’s wording for this case is that you “manually transfer your codes to another device”, because codes “will not be available on your other devices”. Nothing outside that handset knows them.

Check which one you have before wiping anything

Open Authenticator on the old phone and look at the top of the screen for an account avatar or a sign-in prompt. If the app is signed in, sync is available to you. If it offers to sign you in, sync is off. While the old phone still works you have two options: sign in there so the codes sync, which also covers you the next time a handset changes, or use the export and import QR codes below. Either one beats recovering services one at a time.

Transfer with the export and import QR codes

This route works whether or not sync is in play, and it is the one to use when the two handsets are in front of you.

Google Authenticator export accounts on the old phone

On the old device: tap Menu, then Transfer accounts, then Export accounts. Select the accounts you want to transfer, then tap Next. Google adds a detail that trips people up: “If you transfer more than one account, your old device may create more than one QR code.” Treat it as a short series of images, not one picture.

Import accounts on the new phone

On the new device: tap Menu, then Transfer accounts, then Import accounts, then scan the codes the old phone is showing. Work through every image before you put the old phone down.

Confirm every code works before resetting the old phone

Do not factory reset anything yet. Sign in to each service with a code from the new phone, one at a time. A tile that exists on screen is not proof the underlying secret came across correctly, and the old handset is your only second chance until every login is confirmed.

What to do with the old phone afterwards

An export copies the accounts across; it does not clear them off the handset you are retiring. Once every login is confirmed from the new phone, open Authenticator on the old one and read the list of what is still there. Delete the entries you no longer want on that device, sign out of any Google Account inside the app, then factory reset the handset before it is sold, traded in or handed to someone else. Google documents removing codes by removing the device from your Google Account only for codes that are synced, so on a device that was never signed in this is a manual pass you make yourself.

Google Authenticator cloud sync: what signing in backs up

Sync is the route worth setting up in advance, because it removes the need for both phones to be present at all.

Signing the app in to a Google Account

Inside Authenticator, sign in with the Google Account you want the codes held against. From then on the codes are tied to that account rather than to the handset, which is what makes a lost phone survivable.

Codes on a new device after you sign in

Google states it directly: “When you sign in to your Google Account within Google Authenticator on a new device, your codes are automatically synced to this device.” If you wanted to transfer Google Authenticator to a new phone without a QR code, this is the only route Google documents.

Removing an old device from your Google Account

Once the new phone is working, cut the old one loose. Google’s step here is specific: where codes are synced you can remove codes by removing the device from your Google Account. That is a different action from ending the sessions on it, and only the removal stops that handset holding synced codes.

Transfer Google Authenticator to new phone without old phone

This is the search that brings most people here, and the honest answer has two branches with very different amounts of work.

If your codes were synced

Install Authenticator on the new phone, sign in to the same Google Account, and wait for the tiles to populate. Then remove the old device from that account so nothing left on it keeps generating valid codes. If you are not sure where to look, our walkthrough of signing a lost phone out of your Google Account shows where the Your devices list sits under Security and sign-in.

If they weren’t: each service’s own recovery

Google does not soften this one. Where codes are not synced to your Google Account, it says you “need to visit every site that you have Google Authenticator set up on to remove the codes, and then relink your new device”. Every site means every site: each login gets recovered on its own terms, then set up fresh against the new phone.

Why there is no single reset for every service

The app never held anything on your behalf beyond a shared secret per account. Each service issued that secret and each service decides how you prove yourself without it, which is why the fallback order differs below and why no central button exists to reset them all.

Fallback order for Gmail, GitHub and X

Work top to bottom for each service. These are the methods each provider publishes; anything else is guesswork.

ServiceTry firstThenLast resort
GmailA backup codeAnother second step already on the accountGoogle’s account recovery flow
GitHubA recovery codePasskey, security key or fallback SMSEmail one-time password plus a recovery factor, reviewed by Support
XA backup codeA security key already enrolledX’s Problem with 2FA form

Gmail: backup codes, Google prompts and other second steps

Google’s backup codes page puts them under Security and sign-in, then 2-Step Verification, then Backup codes, in sets of ten. A used code becomes inactive, and creating a new set makes the old set inactive at once. The 2-Step Verification page lists the other second steps you may already hold: Google prompts, passkeys, security keys, an authenticator app, codes by text or voice call, and those backup codes. Any one of them gets you in without the retired phone.

GitHub: recovery codes, passkeys, security keys and account recovery

GitHub’s page on recovering your account lists a recovery code, a passkey, a security key, a fallback SMS number, or a one-time password sent to your verified email address combined with a recovery factor such as a verified device, an SSH key or a personal access token. It also sets the ceiling: “GitHub Support will not be able to restore access to accounts with two-factor authentication enabled if you lose your two-factor authentication credentials or lose access to your account recovery methods.” Where a request does go to review, GitHub says a member of Support will email you within three business days.

X: your backup code and security keys

X’s two-factor authentication help names three methods: text message, authentication app, or security key. It describes the backup code in the singular: one is generated for you when you turn two-factor authentication on in the iOS or Android app, and you can also generate a backup code on x.com while you are still signed in. Two limits catch people out. X says that if you try to log in with an inactive backup code, or use one out of order, you see an error message and need to generate a new backup code to log in. It also says a backup code works for signing in to X itself, not for a third-party application tied to your account. Without a working code or second step, X points you at its support forms, including one specifically for a problem with 2FA.

Google Authenticator didn’t transfer to new phone: common causes

If the new handset came up short, these are the practical checks to run, in this order. They are our own troubleshooting list rather than anything Google publishes as one.

Only some accounts were selected on export

The export screen is a picker, and unticked accounts stay where they are. If the old phone showed several QR codes and you scanned two of three, the missing logins are inside the one you skipped.

The app is signed in to a different Google Account

Sync only produces the codes held against the account you signed in with. On a handset that defaults to a personal address when the codes live under a work one, the app looks empty while nothing is actually lost.

The old phone was reset before codes were checked

This is the unrecoverable version of the mistake, and it is why the confirmation step above matters more than the transfer itself. Once the handset is wiped and the codes were never synced, you are on the per-service recovery path whether you like it or not.

Before the next phone change

Ten minutes of preparation now is worth more than any recovery article later.

Keep backup codes somewhere other than the phone

Download or print each service’s codes and keep them away from the device that generates codes. A password manager on a second device, or paper in a drawer, both beat a screenshot in the photo library of the phone you are about to replace.

Add a second verification method on each account

One method is a single point of failure. Add a passkey or a security key alongside the app so a lost handset is an inconvenience rather than a lockout. Use a mobile line you control for any number-based step. Google’s recovery phone page is explicit that a Google Voice number must not be your recovery phone, because that choice can lock you out of the account. A resold number is worse again, because its history belongs to someone else.

Accounts your team manages need the same care

Shared logins are where this goes wrong at scale, because nobody owns the second step. If the real problem is several people reaching one mailbox, Gmail’s delegate access hands out inbox rights without passing a password around, and Google Workspace puts mailboxes under the organization’s control instead of one employee’s, which is the sanctioned fix for a handover problem. Price that route first. Where a project genuinely needs its own separate consumer accounts for testing, QA or account-management work, PVAVRT lists Gmail account grades, GitHub account grades and X account grades. Whichever route you take, the rule is the same one this whole page rests on: set up each account’s own second step the day it arrives and keep those codes where the phone is not. A recovery route you did not set up yourself is not a recovery route, which is the same lesson as Yahoo recovery without a phone number teaches on the mail side.

If you need more accounts than you have

If you manage Gmail, GitHub or X logins for a team and need more accounts for a legitimate job, ask PVAVRT on Telegram @pvavrt which grade fits, and set up each account’s second step yourself on arrival. Buying accounts breaks the terms Gmail, GitHub and X each publish, and any of them can close an account at any time.

Got questions about your specific use case?

We answer pre-sales questions on Telegram in minutes — no form, no funnel.

Chat on Telegram

FAQ

FAQ

Do I have to move the codes myself?
Treat it as a step you take deliberately rather than something the new handset arranges for you. Google documents two routes: the export and import QR codes inside the app, and signing the app in to a Google Account so codes sync across devices. Used without a Google Account, Google says codes will not be available on your other devices and you have to manually transfer your codes to another device. One of those routes has to happen while the old phone still works, or you fall back to each service's own recovery.
Where is the export option in Google Authenticator?
On the old device, tap Menu, then Transfer accounts, then Export accounts. Pick the accounts you want to move and tap Next. Google notes that if you transfer more than one account, the old device may create more than one QR code, so expect to advance through a short series rather than a single image. On the new device the mirror route is Menu, then Transfer accounts, then Import accounts, and you scan each code that the old phone displays.
Can I move my codes without scanning a QR code?
Yes, if both devices can reach the sync feature. Google states that you can synchronize verification codes across all your devices simply by signing in to your Google Account inside Authenticator, and that signing in on a new device syncs your codes to it automatically. That is the only route Google documents that involves no scanning. It needs app version 6.0 or above on Android, or 4.0 or above on iPhone and iPad.
My old phone is already wiped. What now?
It depends entirely on whether the app was signed in to a Google Account. If it was, install Authenticator on the new phone, sign in to the same account, and the codes come back. If it was not, Google is blunt about the outcome: you need to visit every site where Authenticator was set up, remove the codes there, and relink your new device. That means recovering each service one at a time using whatever second step or recovery route it offers.
Why did only some of my accounts appear on the new phone?
The export screen asks you to select which accounts to move, and anything left unticked stays behind. If the old device produced several QR codes and one was skipped, the accounts inside it never arrived either. Check the old phone while you still have it, run the export again, and scan every code the app shows. Compare the two lists side by side rather than counting entries, because names on the tiles are set by each service.
How many Google backup codes do I get, and do they run out?
Google issues a set of ten backup codes, reachable from your Google Account under Security and sign-in, then 2-Step Verification, then Backup codes. Each code works once: Google says that after you use a backup code to sign in, that code becomes inactive. Generating a fresh set makes the whole previous set inactive at the same moment, so replace the copy you keep whenever you generate new ones. Keep them somewhere other than the phone that holds the codes.
Can GitHub support let me back in if I lose everything?
GitHub says plainly that Support will not be able to restore access to accounts with two-factor authentication enabled if you lose your two-factor credentials or lose access to your account recovery methods. Before that point you have several options: a recovery code, a passkey, a security key, a fallback SMS number, or a one-time password sent to your verified email alongside a recovery factor such as a verified device, an SSH key or a personal access token. Requests that need review get an email within three business days.
Should I use a bought phone number as my recovery method?
No. Google's recovery phone page is explicit that a Voice number must not serve as your recovery phone, because that choice can lock you out of the account, and a resold number carries the same risk with someone else's history attached. Use a mobile line you control, and prefer a second method that does not depend on a number at all: a passkey, a security key, or a printed set of backup codes held outside the phone.

Added to cart

Order confirmed