SMS codes vs authenticator app (TOTP) vs passkeys: which one should you use?
SHORT ANSWER
Is a passkey better than an authenticator app, and is either better than SMS?
For most accounts, yes: passkeys resist phishing, authenticator apps (TOTP) are the next best and work offline, and SMS codes are the weakest because phone numbers can be hijacked and codes can be phished. Use the strongest method each site offers, and keep a recovery route for when you lose the phone.
Key takeaways
- Order of preference: passkey, then authenticator app, then SMS as a last resort.
- SMS depends on your phone number, which can be moved to another SIM without your phone. TOTP and passkeys do not.
- TOTP codes can still be typed into a fake page and relayed. Passkeys cannot, because the signature includes the real site address.
- Whatever you choose, set up recovery before you need it. The strongest method is useless if losing the phone locks you out.
The three methods in one line each
- SMS code: the site texts you a code. Convenient, needs no app, depends on your phone number and network.
- Authenticator app (TOTP): an app on your phone makes a 6-digit code from a secret you shared once. Works offline. See how TOTP works.
- Passkey: your phone signs a challenge with a private key it never reveals, after a fingerprint or face check. See passkeys from first principles.
What each one stops
| Attack | SMS code | Authenticator app (TOTP) | Passkey |
|---|---|---|---|
| Someone guesses or reuses your password | Stopped | Stopped | Stopped (no password to guess) |
| SIM swap: your number is moved to another SIM | Not stopped: the attacker receives the code | Stopped | Stopped |
| Code intercepted on the phone network or by malware reading texts | Not stopped | Stopped (the code never travels) | Stopped |
| Fake sign-in page relays your code in real time | Not stopped | Not stopped | Stopped: the signature is bound to the real site |
| Site's database is breached | Codes are one-time, so little to steal | The site holds the shared secret: a breach could expose it | Site holds only public keys, which are useless to a thief |
| You lose or reset your phone | Recover by moving the number to a new SIM | Gone unless you have a backup or recovery codes | Gone for a device-bound passkey; a synced passkey comes back through its cloud account |
| No signal or roaming | Fails | Works | Works |
Why SMS is the weakest
A text message proves you control a phone number, not a phone. Numbers can be moved to a new SIM through the carrier, and the message itself is not end-to-end protected. Standards bodies treat this channel with caution: NIST's digital identity guidelines classify SMS as a restricted authenticator, to be used only with extra risk checks. It is still better than no second factor, and sometimes the only option a site offers.
Why TOTP is the practical middle
An authenticator app is supported almost everywhere, needs no network, and removes the phone-number risks. Its weaknesses are the shared secret and phishing: whoever copies the secret from a setup QR code or a backup can make your codes forever, and a convincing fake page can ask for the current code and pass it on within its 30-second window.
Why passkeys are the strongest, and where they fall short
A passkey is origin-bound: the browser signs data that includes the real site address, so a lookalike site gets nothing usable. There is no shared secret to steal from the site. The costs are coverage (not every site supports them yet) and recovery: a device-bound passkey, such as the ones HostSpica Passkey makes, cannot be backed up by design, so you need another way to sign in if the phone is lost.
A sensible setup
- Use a passkey wherever the site offers one.
- Otherwise use an authenticator app, not SMS.
- Use SMS only where nothing else exists, and protect your mobile account with a PIN with your carrier.
- Save each site's recovery codes somewhere offline, and keep an encrypted backup of your authenticator accounts. See what to do if you lose your phone.
Frequently asked questions
Should I turn off SMS once I add an authenticator app?
If the site lets you, yes. Otherwise an attacker can still choose the SMS route. Keep SMS only if it is your recovery option and you accept that risk.
Can I use a passkey and an authenticator app together?
Yes. Many sites allow several methods. Use the passkey day to day and keep the authenticator app as a backup.
Is an authenticator app on the same phone as my passkey a single point of failure?
For loss of the phone, yes. That is why recovery codes and a second sign-in method matter more than which one is strongest.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED