All tools / Compare sign-in methods Compare login methods Choose two methods to compare First method Application codes (TOTP) Passkey synced FIDO2 Hardware Key Confirmation in application SMS code
Second method Application codes (TOTP) Passkey synced FIDO2 Hardware Key Confirmation in application SMS code
Show all methods You compare: Application Codes (TOTP) and Passkey synchronized.
Application codes (TOTP) The application generates a short-lived code that you enter after entering the password.
Resistance to phishing No, a fake page can extort and pass on the current code.
What is needed Authentication application. The self-generation of codes usually does not require the Internet.
Before losing the device Prepare the backup codes and check how the application is transferred or copied.
What to watch out for Only enter the code when logging in, which you start on your own. Do not share the configuration secret or QR code. How to turn on 2FA → Passkey synced A key saved from a supplier that synchronizes it between your devices.
Resistance to phishing Yes, for FIDO2/WebAuthn login. The key is related to the right service, instead of the code being copied to the page.
What is needed Supported service, device and provider of passkeys. You confirm the use of e.g. screen lock.
Before losing the device Check synchronization, access from the second device and recover the supplier's account.
What to watch out for Secure your devices and sync account. Passkey does not protect you from any threat or affected session. How to start with passkeys → FIDO2 Hardware Key A separate device confirms cryptographic login by USB, NFC or supported connection.
Resistance to phishing Yes, using FIDO2/WebAuthn. The key confirms the login for the right service.
What is needed A compatible key, device and supported service. Not every hardware token is a FIDO2 key.
Before losing the device Add and test the second key or other recovery method available in the service.
What to watch out for Store your spare separately. The key can be used as a second component or passkey carrier, depending on the service. How to prepare the hardware key → Confirmation in application The service sends to the device a request for confirmation of the login started.
Resistance to phishing Regular push confirmation is not a phishing-resistant method. Matching the number limits random acceptances.
What is needed Registered app or device and usually internet access.
Before losing the device Configure the backup method offered by the service.
What to watch out for Refuse requests you don't start, check the details instead of approving under pressure. What to do with an unexpected request → SMS code A one-time code comes in on a phone number assigned to the account.
Resistance to phishing No. The code can be defrauded; the additional risk involves taking over a SIM number or card.
What is needed Current number and ability to receive messages.
Before losing the device Check the actuality of the number and add another method if the service offers it.
What to watch out for If a stronger method is available, consider changing. Do not disable the only working ingredient before preparing a new one. How to choose the second ingredient → The choice depends on the service. Passkey can replace the password, and the hardware key can store passkey or act as a second component. Not every option is available on each account. Test login and emergency method before changing.How do you understand resistance to phishing? The comparison concerns logging on a fake page that tries to take over the code or confirmation. FIDO2/WebAuthn binds authentication to the right service. It does not replace device protection, session and account recovery.
This is educational material without testing your account. The choice of methods is not saved or sent.
Without JavaScript you can see all five methods. Compare the ones your service offers.
Account recovery plan Passkey readiness 2FA backup codes