← All posts
Guides · 6 min · Sep 15, 2026

Moving authenticator codes without losing access

A checklist for exporting TOTP secrets, verifying codes, and retiring your old authenticator safely.

Phone showing an authenticator code on a dark desk

Before you leave an authenticator app, export or photograph every otpauth secret you still need. Codes stop working the moment the old app is wiped.

In LoginScout MFA, paste otpauth:// URIs or import a JSON export. Confirm each 6-digit code matches the old app before you remove anything.

Keep a printed or offline backup of recovery codes from the original services. TOTP apps fail; recovery codes are the spare key.

When migration checks out, retire the old authenticator. One source of truth beats two half-updated lists.

Steam Guard, Epic 2FA, and Roblox 2-step each have a spare-key moment. Photographing the code in a camera roll is how it disappears. Put recovery codes on the same library card as the password.

LoginScout will not auto-fill the Steam client. You copy the rotating code from the vault. That is the same “open on purpose” rule as the rest of the library.

If you cannot export from a vendor’s proprietary format, do not factory-reset the old phone until you still have matching codes somewhere. The authenticator product page is the feature list; this post is the move-without-lockout order of operations.

Questions people ask

What if I delete Google Authenticator before codes match?
The rotating codes stop. Export or photograph otpauth secrets first, confirm LoginScout matches, then retire the old app.
Where do Steam Guard backup codes go?
In vault notes next to that Steam login. TOTP is the live code; recovery codes are the spare key.
Is LoginScout an offline phone authenticator?
It is a web vault. Open it when you can reach the browser. The authenticator product page explains the limits.

Ready to try it?

Create a free vault and keep logins, mail, and MFA together.

Related: Authenticator · Organize gaming alt accounts · Security