Where Does Google Authenticator Store Codes?
Google Authenticator syncs to your Google account when signed in. Export QR codes as the offline backup.
Last updated
Google Authenticator keeps codes in its sandbox and optionally in your Google account. Signed-in sync survives phone loss. Device-only mode does not.
The QR export predates sync and still works as the offline route. Run it before wipes regardless of sync state. Two minutes of caution beats account recovery everywhere.
Where Google Authenticator stores this, by platform
/data/data/com.google.android.apps.authenticator2
Encrypted codes plus sync state. Needs root to browse. Sync and QR export are the migration routes.
/var/mobile/Containers/Data/Application/<guid>/ (Authenticator container)
Per-install container. Same sync and QR options as Android. No file copies involved.
Frequently asked questions
How do I move Google Authenticator codes?
Sign into the same Google account on the new phone and let it sync. Without sync enabled, transfer accounts with the in-app QR export before wiping.
How does QR transfer work?
Open Transfer accounts, then Export, and scan the QRs with the new phone. Keep the old phone until every code verifies on the new one.
Does Google Authenticator back up online?
Yes since cloud sync launched. Unsigned use keeps codes device-only. Sign in to cover phone loss.
Notice an outdated path? Let us know.