For years, Google Authenticator was where 2FA codes went to become unmovable: no export button, no backup, and a lost phone meant re-enrolling every account by hand. That's no longer true. The app now has a built-in transfer tool that packs your entire vault into a few QR codes, and most modern authenticator apps can read them. The whole move takes minutes.
There's one catch worth understanding before you tap anything: those export QR codes contain your actual secret keys, in a form anyone can decode. Handled carelessly, the export becomes the single most dangerous image on your phone. Here's how the mechanism works, how to import cleanly, and the mistakes to avoid.
What the export actually is
In Google Authenticator, open the menu and choose Transfer accounts, then Export accounts. The app renders your selected accounts as one or more QR codes, batching roughly ten accounts per code. Each QR encodes a special migration payload that bundles, for every account, the issuer name, your account name, and the raw TOTP secret key.
Two things follow from that design. First, the QR is not a link or a reference to something in Google's cloud; the secrets themselves are in the image. Anything that can decode a QR code can extract them. Second, exporting is a copy, not a move. Nothing is deleted from Google Authenticator, and both the old and new app will generate identical, equally valid codes until you clean up.
Step by step: exporting your accounts
- On the phone that has your codes, open Google Authenticator and confirm every account you expect is listed. Note the total count.
- Open the menu and choose Transfer accounts, then Export accounts.
- Select the accounts to move. Selecting everything is usually right; you can prune later in the new app.
- The app shows the first QR code. If you have more than about ten accounts, there will be several; the screen tells you which batch you're on.
- Leave this screen open and pick up your other device. The QR should only ever be scanned directly from this screen.
Importing into the new app, and why on-device matters
On the receiving side the flow is generic across good authenticator apps: find the import or add-account option, choose to scan a QR code (many apps have an explicit "import from Google Authenticator" entry), and point the camera at the old phone's screen. Scan each batch in turn, and the accounts appear with their issuer and account names intact. If you're moving phone-to-phone within Google Authenticator itself, the mirror-image Import accounts option does the same job.
Where the import happens matters more than people realize. Because the QR contains live secrets, the decoding must happen on your device, inside the app, with nothing sent anywhere. Never use a website or online converter that asks you to upload a picture of your export QR; you'd be handing your entire 2FA vault to an unknown server. Authenticator by Vidus6 imports a full Google Authenticator export on-device: the QR is parsed locally on your phone, and if you sync across devices, the vault travels end-to-end encrypted with a key that never leaves your hardware. Whatever app you choose (our comparison of authenticator apps covers the field honestly), the on-device rule is non-negotiable.
The gotchas that can burn you
Never screenshot, email, or message the export QR
A screenshot of the export is your master keys as a JPEG. Worse, screenshots often auto-upload to Google Photos or iCloud Photos the moment they're taken, putting your 2FA secrets in a cloud library, its trash folder, and every device that syncs it. Scan screen-to-screen instead. If you ever did capture one, delete it and purge it from the cloud service's trash too; then consider re-enrolling your most sensitive accounts with fresh secrets.
Exporting disables nothing
After a successful import, the copy in Google Authenticator keeps working. That can be a feature during a careful migration, but an authenticator you've mentally abandoned on an old device is a liability, especially if that device is about to be sold or recycled. Decide deliberately: either keep the old copy as a conscious backup on hardware you control, or delete the accounts from it once you've verified the new app.
Cloud sync can outlive the app
Google Authenticator can also sync codes to your Google Account. If that sync is on, deleting the app from your phone does not remove the secrets from your account, and this sync historically hasn't end-to-end encrypted them by default. If your reason for leaving is keeping secrets off third-party servers, check your sync status and Google's current documentation as part of the move.
Verify the count, then verify logins
Compare the number of accounts in the new app against the count you noted before exporting. Then do the real test: because both apps derive codes from the same secrets, old and new should display identical codes at the same moment. Finally, sign out of two or three important accounts and back in using only the new app. Before you retire anything, make sure your recovery codes are current; they're your safety net if a batch was missed.
If an account won't import
A few apps can't read Google's batched export format and only accept one-account-at-a-time QR codes. The fallback is re-enrollment: log in to the service, open its security or two-factor settings, remove the existing authenticator, and set it up again by scanning a fresh QR with the new app. It's slower but perfectly safe, and it has the side benefit of issuing brand-new secrets. Our per-service setup guides cover the setup flow for over 2,000 services if you go this route.
FAQ
Does exporting delete my codes from Google Authenticator?
No. Export is a copy. Every account stays in Google Authenticator and keeps generating valid codes until you delete it there yourself.
Can any authenticator app read the export QR?
Many can, since the migration format is widely understood, but not all. Look for an import or "transfer from Google Authenticator" option in the receiving app; Authenticator by Vidus6 supports the full vault import. If your chosen app can't read it, use the re-enrollment fallback above.
Is the export QR encrypted or password-protected?
No. Anyone who scans it gets working secrets for every account in the batch. Treat the export screen like a page of written-down master passwords: display it only as long as the scan takes, only to your own device.
Wrap-up
Google Authenticator's export is genuinely good: batched QR codes, minutes of work, no accounts touched. The discipline is all in the handling. Scan screen-to-screen, import on-device, verify counts and logins, then deliberately retire the old copies. If this move is part of a full device upgrade, fold it into the larger checklist for moving your authenticator to a new phone, and back the result with a proper 2FA backup strategy so the next migration is a non-event.



