Twitter now lets users set up third-party apps, such as 1Password or Authy, for two-factor authentication as an alternative to SMS
Twitter has announced an important change to how it handles two-factor authentication for new logins on its service. Twitter now lets you use third-party apps …
Context & Ripple Effects
Twitter's two-factor story had been stuck on SMS since it first shipped two-step verification, with the only adjacent move being its own Digits login service back in 2015. This change finally opens the second factor to third-party authenticator apps — and the timing is no accident: 1Password had shipped a one-time-password tool for iOS in January 2015, so the credential-manager ecosystem was already built out and waiting for platforms like Twitter to accept it.
The arc continues after this piece: Twitter added physical USB security keys such as YubiKey in mid-2018, then in late 2019 let users enroll in 2FA entirely without a phone number and drop SMS as the default. Each step peels another layer of dependence on the carrier channel.
First-order effects
- Users who already run 1Password or Authy can now protect Twitter logins without relying on SMS delivery, removing the SIM-swap and interception risks tied to text-message codes.
- 1Password and Authy gain direct distribution inside Twitter's security settings, turning their existing one-time-password features into a default recommendation for millions of accounts.
Second-order effects
- SMS loses its position as Twitter's default second factor, shrinking the role carriers play in account security and pushing other consumer platforms to offer app-based alternatives or look behind the curve.
- Credential managers become stickier: once a user's Twitter codes live in 1Password or Authy, those apps anchor more of the login workflow and raise switching costs against standalone SMS.
Third-order effects
- If the pattern holds — apps, then hardware keys, then phone-number-free enrollment — account security consolidates around dedicated authenticators and password managers rather than the phone number itself, shifting access-layer power toward whoever holds the user's credentials.
- Phone numbers fade from their role as both identity anchor and recovery channel, which regulators and platforms would eventually have to treat as a structural change rather than a feature toggle.
The trend: Consumer platforms are migrating two-factor authentication off carrier-controlled SMS and toward third-party authenticator apps and hardware keys, moving control of the login layer away from phone numbers.