Transfer Authenticator Codes Before a Household Phone Handoff
A verification-first phone handoff that prevents household account lockouts without exposing authentication secrets.
Transfer authenticator codes and test them before an old phone is erased, traded in, or given to another household member. Keep both phones available, inventory the household services protected by the app, and verify each critical sign-in from the new phone. A successful phone setup does not prove every authentication secret moved.
Inventory codes without recording secrets
Open the authenticator app and list account labels, not the rotating numbers or setup QR codes. Mark each service as personal, work, or legitimately shared household access. Common shared examples include utilities, a router account, home security, cloud backups, and a property-management portal.
Some labels are cryptic or duplicated. Sign in to the service to confirm which username each entry protects. Remove obsolete entries only after confirming the related account is closed or has another factor. Never screenshot setup QR codes into a shared photo album. Those images can contain the secret needed to generate future codes.
Also identify services that use a push prompt, passkey, security key, SMS, or an app-specific approval instead of authenticator codes. They need their own transfer check. The existing household two-factor backup guide can help households avoid leaving one resident as the sole recovery route.
Transfer, then test account by account
Follow the authenticator provider's current method. For example, Google's official Authenticator instructions describe synced codes and a manual transfer flow for codes used without account sync. In the manual flow, the old device creates one or more export QR codes that the new device scans. Treat those codes like passwords and keep other cameras out of view.
After transfer, do not settle for seeing matching six-digit numbers. Open a private browser window, enter the service's known address yourself, and complete a fresh sign-in with the new phone. Check the most consequential accounts first: primary email, password manager, carrier, bank, cloud storage, and smart-home administrator.
Record “tested” beside each account. If a code fails, use a recovery code or another already enrolled factor, then replace the authenticator registration from inside the account. Do not search the web for a support phone number and hand over a one-time code to a caller.
Separate access before erasing the old phone
A handed-down phone should not become a silent second factor for the next resident. Review enrolled devices and sign-in methods inside each service. Remove the old handset where appropriate, confirm recovery email and phone details, and store fresh backup codes in a private location controlled by the account owner.
Shared household accounts still need individual boundaries. When a service permits multiple members or administrators, invite each person's own account rather than synchronizing one resident's entire authenticator collection to everyone. If a service only offers one login, document an agreed custodian and a recovery route that does not expose unrelated personal codes.
Keep the old phone intact through a short verification period. Then sign out of personal cloud accounts, disable device-finding or activation protections as the manufacturer requires, remove payment cards and digital IDs, and perform a factory reset. The recipient should see the initial setup screen, not the former owner's home screen.
How HomeCo helps
Create a HomeCo handoff with one task per service, labeled personal or household. Track transfer, fresh-login test, old-device removal, and backup-code storage as separate checks. Never paste an authenticator secret, rotating code, QR image, recovery code, or password into a HomeCo task.
Assign verification to the actual account owner. A household coordinator may see that “internet account tested” is complete without gaining access to the internet account. Add the factory reset as the final blocked task so nobody wipes the phone while earlier checks remain open.
FAQ
Can matching codes on both phones prove the transfer worked?
They are encouraging, but a real sign-in verifies that the service accepts the new setup and that you know the correct username and password.
Should we delete codes from the old phone immediately?
Wait until critical accounts have been tested and alternative recovery methods confirmed. Then remove access and reset the old device according to its maker's instructions.
Is SMS a good temporary fallback?
It may be the only fallback a service offers, but protect the carrier account and phone number. Prefer stronger options supported by the service, such as passkeys or security keys.