Back to all companies
Sign in
Back to all companies
Authy logo

Authy

Winter 2012Acquired

Authy is a Two-Factor Authentication platform for developers

Save
Authy logo

Authy

Winter 2012Acquired

Authy is a Two-Factor Authentication platform for developers

Save
Company details

Authy provides strong authentication for the connected world, protecting people and the enterprise against malicious attacks. Our two-factor authentication (2FA) security solution enables organizations to minimize risk while enhancing the user experience.

Authy 2FA provides a fast-to-implement, highly scalable and proven 99.999 % reliable alternative to passwords. Used by 11,000+ websites serving 2 million consumers worldwide, it's designed to give users the ability to self-service or easily manage their own 2FA experience. Coinbase, CloudFlare, Humble Bundle and Twitch.tv are just some Authy clients.

Authy is a Twilio company. Follow us on: Twitter at @Authy Facebook at https://www.facebook.com/authysec Google+ at https://plus.google.com/+Authy GitHub at https://github.com/authy

Location
San Francisco, CA, USA
Founded
2011
Category
Security
YC profileauthy.com
Founders
  • DP
    Daniel Palacio
    Founder/CEO
    LinkedIn
  • GC
    Gleb Chuvpilo
    Founder
    X / TwitterLinkedIn

Authy provides strong authentication for the connected world, protecting people and the enterprise against malicious attacks. Our two-factor authentication (2FA) security solution enables organizations to minimize risk while enhancing the user experience.

Authy 2FA provides a fast-to-implement, highly scalable and proven 99.999 % reliable alternative to passwords. Used by 11,000+ websites serving 2 million consumers worldwide, it's designed to give users the ability to self-service or easily manage their own 2FA experience. Coinbase, CloudFlare, Humble Bundle and Twitch.tv are just some Authy clients.

Authy is a Twilio company. Follow us on: Twitter at @Authy Facebook at https://www.facebook.com/authysec Google+ at https://plus.google.com/+Authy GitHub at https://github.com/authy

Location
San Francisco, CA, USA
Founded
2011
Category
Security
YC profileauthy.com
Founders
  • DP
    Daniel Palacio
    Founder/CEO
    LinkedIn
  • GC
    Gleb Chuvpilo
    Founder
    X / TwitterLinkedIn

Pressure-test this opportunity

Explore the risks and possibilities with a prompt for ChatGPT, Claude, or your agent.

On this page
  • Overview
  • Founding Story
  • Timeline
  • What They Built
  • Market Position
  • Target Customers
  • Market Size
  • Competition
  • Business Model
  • Traction
  • Post-Mortem
  • Convenience concentrated recovery risk
  • The product moved inside a broader platform
  • Authentication standards moved forward
  • Key Lessons
  • Sources

AI-researched. Check the sources before making a decision.

Found a mistake? Let @oscrhong know.

Startups.RIP — Good ideas. Better timing.
PricingContactPrivacyGot feedback? DM @oscrhong

Authy (W12) at a glance

  1. Recovery was the wedge. Device loss and migration made ordinary authenticators brittle; solving continuity helped stronger authentication reach mainstream users.
  2. Developer speed drove adoption. Packaging enrollment, delivery, and recovery behind an API helped roughly 6,000 sites adopt Authy before acquisition.
  3. Convenience expands the perimeter. Synchronization reduced user pain, but device registration and phone-number recovery became security-critical surfaces.
  4. Standards move the boundary. Passkeys reduce dependence on shared secrets, shifting value toward cross-device recovery, governance, and credential portability.

Overview

Authy made two-factor authentication easier for developers and less fragile for users. Founded by Daniel Palacio in 2011 and launched through Y Combinator's Winter 2012 batch, it combined an API for relying websites with an encrypted, synchronized authenticator app.[1]

This is an acquisition story, not a shutdown. Twilio bought Authy for $6.1 million in 2015 after roughly 6,000 sites had adopted it.[2] Authy's distribution and recovery design solved real problems, but its phone-number identity model also concentrated risk. Later breaches and endpoint exposure showed the tension between convenient recovery and a centralized attack surface.

Founding Story

Palacio came to authentication through security work. He had been a penetration tester and had worked on Microsoft's Windows security team before starting Authy. TechCrunch reported that he was tired of internet services relying on passwords alone.[3]

Authy's initial insight was practical: two-factor authentication failed when every service had to build enrollment, delivery, recovery, and fraud controls itself. The company offered those mechanics through a developer API, while its app generated time-based codes offline and encrypted backups behind a password Authy did not store.[4]

The observed research contains only one fetched founder quotation and does not preserve its exact wording. A second founder interview or transcript was not found. Rather than inventing dialogue, this report records the gap. The evidence still shows a consistent founder thesis: remove the engineering work that kept stronger authentication out of ordinary products.

Timeline

  • 2011: Palacio founded Authy.
  • Winter 2012: Authy joined Y Combinator and launched its developer authentication API.[1]
  • September 2014: Authy raised $2.3 million and hired Marc Boroditsky as president and COO to pursue enterprise customers.[5]
  • February 2015: Twilio acquired Authy for $3 million in cash and $3.1 million in preferred stock.[2]
  • 2020: Twilio renamed the app Twilio Authy.[6]
  • August 2022: Attackers registered devices on 93 Authy accounts during Twilio's social-engineering breach.[7]
  • March 2024: Authy's desktop apps reached end of life.[8]
  • July 2024: Twilio secured an unauthenticated endpoint that exposed Authy account data including phone numbers.[9]

What They Built

Authy joined two products that competitors often separated. Developers integrated an API to enroll users and challenge logins by SMS or app-generated token. Consumers installed one authenticator that could retain encrypted TOTP seeds, work offline, back up accounts, and synchronize them across devices.[4]

The phone number became the bridge. It gave developers a familiar identifier and gave users a path to move tokens to a new device. Twilio later added QR enrollment that kept phone and email data from the relying website, an attempt to preserve convenience while reducing disclosure.[10]

That architecture differentiated Authy from single-device code generators. It also meant recovery could become an authentication event with high consequences. Authy had to secure app access, device registration, encrypted backups, phone-number changes, and the service endpoints connecting them.

Market Position

Target Customers

Authy initially sold to developers who wanted two-factor authentication without building carrier delivery and token infrastructure. By 2014 it had hired an identity executive to pursue enterprise accounts. Coinbase, MercadoLibre, and Cloudflare were among roughly 6,000 sites using Authy when Twilio acquired it.[11]

Market Size

The observed sources do not establish a reliable market-size figure. Adoption is clearer than revenue: thousands of sites integrated Authy within four years, proving demand for an outsourced authentication layer. Contract values, retention, gross margins, and consumer usage were not disclosed.

Competition

Authy competed with authenticator apps, SMS providers, enterprise identity vendors, and internal security teams. Its advantage was integration speed plus consumer recovery. Twilio said Authy cut an authentication integration from months to days, matching Twilio's API-first developer strategy.[12]

Passkeys have since changed the category. They use public-key credentials and resist phishing better than shared secrets or one-time codes. AWS IAM added passkeys as a second factor in June 2024.[13] TOTP remains useful for compatibility, but it is no longer the obvious destination.

Business Model

Authy sold authentication infrastructure to businesses while offering the consumer app as the user-facing credential holder. Public sources do not disclose pricing, revenue, margins, or enterprise contract size. About $3.8 million had been invested before the $6.1 million acquisition, so the sale exceeded invested capital in aggregate, but that does not establish individual investor or employee returns.[11]

The strategic value to Twilio was distribution into developer accounts and a faster path from messaging APIs to identity. Authy gained an owner that already operated communications infrastructure and developer sales.

Traction

Approximately 6,000 sites used Authy by February 2015.[11] Named customers showed adoption across cryptocurrency, commerce, and internet infrastructure. The sources do not quantify active end users or authentication volume, so site count is the strongest available traction measure.

Post-Mortem

Convenience concentrated recovery risk

Authy's multi-device backup solved the loss and replacement problem that made ordinary authenticators brittle. Yet a phone-number-centered account created a target whose compromise could affect many linked services. During Twilio's 2022 breach, attackers registered devices on 93 accounts, enabling code generation for connected accounts.[7]

The July 2024 endpoint exposure revealed another version of the same mechanism. Twilio's incident response team wrote: "Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint."[9] Twilio found no evidence of account compromise or access to other sensitive internal data. The lesson is not that synchronization was wrong. It is that recovery convenience expands the service boundary that must remain secure.

The product moved inside a broader platform

Twilio's acquisition made strategic sense because Authy accelerated authentication integration from months to days.[12] The $6.1 million price was modest beside the long-term importance of identity, but the observed evidence cannot establish whether founders, employees, or investors viewed the outcome as strong.

Twilio CEO Jeff Lawson made the build-versus-buy logic explicit in 2015: "Authy had already built the solution we would have built."[11] Acquisition was therefore not a rescue from a failed product. It was recognition that Authy's developer-first architecture filled a gap Twilio's customers were rebuilding independently.

Authentication standards moved forward

Authy improved a TOTP and SMS world. Passkeys now offer a phishing-resistant path without reusable shared secrets.[13] A modern successor should treat TOTP as a compatibility layer and center recovery, credential portability, and device trust across passkeys.

Key Lessons

  • Recovery is part of authentication. Authy's growth came from solving device loss and migration, not merely generating six-digit codes.
  • Developer speed creates distribution. Cutting integration work gave Authy a direct path into thousands of relying services.
  • Convenience changes the threat model. Synchronization helps users, but every recovery endpoint and device-registration flow becomes security-critical.
  • Standards can move the product boundary. Passkeys reduce the role of TOTP while making cross-device recovery and credential governance more valuable.

Sources

  1. Y Combinator company profile
  2. Twilio SEC filing
  3. TechCrunch, 2012 launch profile
  4. Authy features
  5. TechCrunch, 2014 financing
  6. Twilio, Authy rename
  7. TechCrunch, 2022 breach
  8. Twilio, desktop app end of life
  9. Twilio, 2024 security alert
  10. Twilio, private QR enrollment
  11. TechCrunch, acquisition
  12. Twilio, acquisition rationale
  13. AWS, passkey support