Recover Authy after losing your phone
Authy account registration, its local app PIN, and its encrypted-backup password are different protections. Regaining the account does not necessarily decrypt the tokens used to sign in elsewhere. Identify which layer is unavailable before reinstalling an app or resetting a device that still contains useful codes.
This guide covers your own Authy setup. The general two-factor recovery guide explains how to recover individual services when an authenticator cannot be restored. Do not assume Twilio can reset every account whose code previously appeared in Authy.
1. Check another supported Authy device
Twilio's Authy login-issues guide separates a new device, a changed number, disabled multi-device access, and other registration problems. Choose the situation that matches your account. An already configured supported mobile device may provide an easier route than starting recovery without any existing installation.
Keep that working installation available while following the official instructions. Check whether the same phone number is still yours and active. If both the device and number changed, use Twilio's number-change guidance linked from the login article instead of pretending you can receive messages at the old number.
Do not remove the last functioning app while testing a replacement. The ability to see a token and the ability to register another device are separate capabilities. Record which services you need to test, but keep their codes and setup secrets out of shared notes.
2. Follow the account-recovery route appropriate to your number
Authy's official login help links to recovery and phone-number-change processes. Use the current route it provides and complete the verification requested for your situation. If the detailed recovery page is unavailable, use Twilio's support from the Help Center rather than relying on an unofficial copy or a promised fixed turnaround.
Monitor the contact address used in the legitimate case and keep the case details together. A request to recover registration is not proof that backed-up tokens have already been decrypted. Wait for the actual account outcome and then check the token state in the replacement app.
If the old number is forgotten or no longer accessible, describe that accurately to Twilio. Do not ask the current holder of a reassigned number to forward a code. Account ownership and phone-service ownership must be established through their supported processes.
3. Unlock the encrypted backup with its own password
Twilio's backup-password explanation says that this password encrypts the backed-up tokens and is not sent to its servers. The local Protection PIN only unlocks a particular app installation. Remembering that PIN does not necessarily supply the password needed to decrypt synchronized tokens.
Use Authy's backup and sync instructions to inspect the configured backup. If you have the backup password, follow the supported restore and decrypt steps. Search your own secure records for that specifically labeled password rather than trying the online password of a service listed in the app.
If another Authy device still displays working codes, preserve it and follow Twilio's guidance before making changes. A forgotten backup password with no accessible device is a different and more serious situation from a forgotten local app PIN.
Twilio says that if all devices are lost and the backup password is forgotten, the backed-up tokens cannot be decrypted or recovered. Restoring account registration does not override that encryption. Each protected service may then need its own recovery process.
4. Do not rely on the discontinued desktop app
Twilio's Authy Desktop retirement notice says the Linux, macOS, and Windows desktop apps reached end of life on March 19, 2024. An old desktop tutorial is therefore not a supported plan for replacing a lost phone.
The notice also explains that Authy lacks a general token-export feature. Moving to another authenticator can require registering a new method at each service. Do that only after obtaining legitimate access through a working code or the service's recovery route; installing another app does not recreate the missing token secrets.
After you regain access
Test important tokens individually and verify the backup setup. Store the backup password independently of the phone, and keep service-specific recovery codes in secure storage. If the phone was stolen, review the affected services and revoke old authentication registrations through their own settings where appropriate.
Login.com's Authy alternatives guide can help you consider a supported setup once access is stable. Plan any migration before removing the old installation. A clear record of the Authy number, backup password, and each service's fallback route keeps three different recovery problems from becoming one unresolved lockout.
Instructions checked against vendor guidance on 24 September 2026.