Alternatives to Google Authenticator
Google's mobile app that generates one-time verification codes for two-step verification. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Google Authenticator
Google's mobile app that generates one-time verification codes for two-step verification.
Replacements
Listings that take over the same core job as Google Authenticator.
Microsoft Authenticator
Microsoft's mobile authenticator app for multi-factor and passwordless sign-in to personal and work accounts.
Microsoft Authenticator is also a free closed-source mobile app, adding passwordless sign-in for Microsoft and work accounts rather than Google Account sync.
Bitwarden Authenticator
A standalone mobile app from Bitwarden that generates and stores two-step verification codes.
Bitwarden Authenticator is a free, standalone mobile app from a password manager vendor, with little published detail about import, export or backup.
FreeOTP
An open-source two-factor authentication app for Android and iOS that generates one-time codes.
FreeOTP is open source, available on F-Droid as well as Google Play and the App Store, and has no Google Account sync.
Also worth comparing
These listings name Google Authenticator as their own alternative, so the relationship runs both ways.
2FAS
Open-source authenticator app with browser-extension push approvals.
Google Authenticator syncs codes through a Google Account instead of your own cloud drive, is closed source and has no browser extension for push approvals.
Aegis Authenticator
An encrypted two-factor authentication app for Android with real backups and imports from every other authenticator.
Google Authenticator adds iOS and optional sync through a Google Account instead of backups you control, and it is closed source.
Authenticator
A GNOME desktop app that generates two-factor authentication codes using the TOTP and HOTP standards.
Google Authenticator moves your codes from the Linux desktop to an Android or iOS phone, is closed source, and offers optional sync through a Google Account.
Authy
Mobile two-factor authenticator with encrypted cloud backup.
Google Authenticator also syncs codes across devices, through a Google Account rather than a phone number, and is likewise closed source and mobile only.
Duo Mobile
Enterprise multi-factor authentication app with push approvals.
Google Authenticator generates TOTP codes offline with optional Google Account sync, without the push approvals of an organisation's Duo deployment.
Ente Auth
Open-source two-factor authenticator with end-to-end encrypted backups.
Google Authenticator is closed source and mobile only, and its optional sync ties your codes to a Google Account.
Proton Authenticator
A free two-factor authentication app from Proton with end-to-end encrypted sync between your devices and no advertising.
Google Authenticator is closed source and mobile only, with optional sync tied to a Google Account instead of a Proton account.
Step Two
A two-step verification code app for iPhone, iPad, Apple Watch and Mac with iCloud backup.
Google Authenticator is free on iOS and Android, is closed source and mobile only, and syncs codes through a Google Account instead of iCloud.
Stratum
A free and open-source two-factor authentication app for Android with encrypted backups and Wear OS support.
Google Authenticator is closed source on Android and iOS, with optional code sync through a Google Account instead of local encrypted backups.
Yubico Authenticator
An app that shows two-factor codes from OATH credentials stored on a YubiKey.
Google Authenticator stores codes on an Android or iOS phone rather than hardware, with optional Google Account sync, and has no desktop app.
Similar software
Related functionality, not a direct replacement.
privacyIDEA
Open-source, self-hosted multi-factor authentication server that manages OTP and other token types.
Authelia
Self-hosted single sign-on and two-factor portal for reverse proxies.
Have I Been Pwned
A service that checks whether your email address or password appeared in known data breaches.