AndroidiOS

Where Does Authy Store Tokens and Backups?

Authy keeps tokens in its app sandbox with cloud backup tied to your phone number. Desktop apps shut down in 2024.

Last updated

Authy stores tokens in the app sandbox and syncs them through Twilio servers behind your phone number. The local folder exists but is encrypted and root-gated, so it never serves as a practical backup.

The desktop shutdown changed the story. Old guides still point at Windows and Mac folders that no longer receive updates. On current versions, mobile plus the cloud backup password is the whole system.

Where Authy stores this, by platform

Android
/data/data/com.authy.authy

Encrypted sandbox, root needed to even list it. Enable Authenticator Backups inside the app with a strong password instead of touching files.

iOS
/var/mobile/Containers/Data/Application/<guid>/ (Authy container)

Per-install container ID. Multi-device approval happens in the app. Same advice: backups inside the app, not file copies.

Frequently asked questions

How do I move Authy to a new phone?

Install Authy on the new phone, verify the same number, and approve from an existing device. Without another device, account recovery takes the waiting period. Keep backup passwords written down.

Is Authy desktop still available?

Yes. Twilio ended Authy desktop in August 2024. Tokens now live on mobile only, so migrate before wiping any old phone that still holds them.

Can I copy Authy files with root?

You cannot. The sandbox at /data/data/com.authy.authy needs root, and tokens are encrypted anyway. The supported route is the in-app backup with a password you set.

Notice an outdated path? Let us know.