Rank the three by raw security and it isn't close: a passkey beats an authenticator app, which beats an SMS code. Rank them by who can actually use them, on any phone, anywhere, and the order flips. SMS wins on reach. That tension is the whole story. Picking one method for everything is the wrong instinct. Match the method to what the account is worth.
I run a service built on SMS codes, so treat this as a comparison from someone biased who will name the limits anyway.
The three methods at a glance
| Method | How it works | Main weakness | Best for |
|---|---|---|---|
| SMS code (OTP) | A one-time code texted to your number | SIM swaps, interception, phishing, shared-number exposure | Low-stakes sign-ups, universal fallback |
| Authenticator app | A rotating code generated on your device | Phishable if you type it into a fake site; device loss | Most important accounts |
| Passkey | A device-bound credential opened by biometrics or a PIN | Adoption and recovery still maturing | Your highest-value accounts |
SMS was never built for this
Text messaging was made to deliver messages, not to guard your bank account. The weaknesses are well documented: SIM swapping, network-level interception, and plain old phishing. An attacker who talks you into reading a code aloud has already won, the trap we cover in our piece on OTP scams. NIST guidance now treats SMS one-time passwords as a restricted authenticator, and big platforms are quietly steering people toward something better.
A shared public number carries one problem your own SIM does not: the code lands in an inbox anyone can read. Fine for a throwaway account. Disqualifying for anything you would hate to lose.
Authenticator apps close the biggest holes
An authenticator app builds the code on your device. Nothing travels over the network to intercept, and no SIM to hijack at the carrier. One weakness survives, and it is phishing: type the code into a convincing fake login page and an attacker can relay it in real time. Even so, it is a big jump up from SMS, and the sensible default for the email, social, and financial accounts you keep.
Passkeys remove the secret entirely
A passkey has no shared code to steal. The credential sits on your device, released only by your fingerprint, face, or PIN. It is also tied to the real site's address, so it cannot hand itself to a lookalike of your bank. Nothing to read out, nothing to intercept, nothing to leak. Adoption is still climbing, and recovery flows get less clumsy every year. For the logins you cannot afford to lose, a passkey is the best option an ordinary person has today.
The one thing SMS still does best
Reach. No app to install, no account to create, no setup screen to squint at. It works on a fifteen-year-old handset and a brand-new one alike. That universality is why temporary numbers exist at all. Plenty of services still demand a phone number before they let you in, and a temporary number gets you a code without spending your real one.
So where do temporary numbers actually belong?
Picture a ladder. At the bottom sit the low-stakes accounts: a forum, a free trial, a sign-up you will forget by next week. A temporary number catching an SMS code is convenient and private enough down there. Climb higher and the stakes rise, so the method should too. Your own number, then an authenticator app, then a passkey at the top.
A temporary number is a privacy convenience, not a security control. Use it for the low rungs, and let passkeys carry the accounts that would ruin your month if someone else got in.
Frequently asked questions
Are SMS codes being phased out?
Slowly. Standards bodies now class SMS one-time codes as a weaker "restricted" method, and major platforms are moving toward passkeys as the default. But SMS still works almost everywhere and will stay common for years, because it needs no app and no setup.
What is a passkey?
A passkey is a login credential stored on your device that signs you in with your fingerprint, face, or PIN instead of a code. There is no shared secret to intercept or phish, and that is what makes it far stronger than an SMS code.
Should I stop using SMS 2FA?
For high-value accounts, prefer an authenticator app or a passkey. For low-stakes sign-ups, an SMS code is fine and fast. Match the method to what the account is worth rather than banning SMS across the board.
Where do temporary numbers fit in?
They suit the low-stakes end: quick sign-ups and trials where you would rather not share your real number. They are not a security upgrade, so for accounts that matter, move to a passkey and keep the number private.
Try it yourself
Receive an SMS code on a free public number in seconds — no sign-up required.
