
Authy is a Two-Factor Authentication platform for developers
Explore the risks and possibilities with a prompt for ChatGPT, Claude, or your agent.
Authy made two-factor authentication easier for developers and less fragile for users. Founded by Daniel Palacio in 2011 and launched through Y Combinator's Winter 2012 batch, it combined an API for relying websites with an encrypted, synchronized authenticator app.[1]
This is an acquisition story, not a shutdown. Twilio bought Authy for $6.1 million in 2015 after roughly 6,000 sites had adopted it.[2] Authy's distribution and recovery design solved real problems, but its phone-number identity model also concentrated risk. Later breaches and endpoint exposure showed the tension between convenient recovery and a centralized attack surface.
Palacio came to authentication through security work. He had been a penetration tester and had worked on Microsoft's Windows security team before starting Authy. TechCrunch reported that he was tired of internet services relying on passwords alone.[3]
Authy's initial insight was practical: two-factor authentication failed when every service had to build enrollment, delivery, recovery, and fraud controls itself. The company offered those mechanics through a developer API, while its app generated time-based codes offline and encrypted backups behind a password Authy did not store.[4]
The observed research contains only one fetched founder quotation and does not preserve its exact wording. A second founder interview or transcript was not found. Rather than inventing dialogue, this report records the gap. The evidence still shows a consistent founder thesis: remove the engineering work that kept stronger authentication out of ordinary products.
Authy joined two products that competitors often separated. Developers integrated an API to enroll users and challenge logins by SMS or app-generated token. Consumers installed one authenticator that could retain encrypted TOTP seeds, work offline, back up accounts, and synchronize them across devices.[4]
The phone number became the bridge. It gave developers a familiar identifier and gave users a path to move tokens to a new device. Twilio later added QR enrollment that kept phone and email data from the relying website, an attempt to preserve convenience while reducing disclosure.[10]
That architecture differentiated Authy from single-device code generators. It also meant recovery could become an authentication event with high consequences. Authy had to secure app access, device registration, encrypted backups, phone-number changes, and the service endpoints connecting them.
Authy initially sold to developers who wanted two-factor authentication without building carrier delivery and token infrastructure. By 2014 it had hired an identity executive to pursue enterprise accounts. Coinbase, MercadoLibre, and Cloudflare were among roughly 6,000 sites using Authy when Twilio acquired it.[11]
The observed sources do not establish a reliable market-size figure. Adoption is clearer than revenue: thousands of sites integrated Authy within four years, proving demand for an outsourced authentication layer. Contract values, retention, gross margins, and consumer usage were not disclosed.
Authy competed with authenticator apps, SMS providers, enterprise identity vendors, and internal security teams. Its advantage was integration speed plus consumer recovery. Twilio said Authy cut an authentication integration from months to days, matching Twilio's API-first developer strategy.[12]
Passkeys have since changed the category. They use public-key credentials and resist phishing better than shared secrets or one-time codes. AWS IAM added passkeys as a second factor in June 2024.[13] TOTP remains useful for compatibility, but it is no longer the obvious destination.
Authy sold authentication infrastructure to businesses while offering the consumer app as the user-facing credential holder. Public sources do not disclose pricing, revenue, margins, or enterprise contract size. About $3.8 million had been invested before the $6.1 million acquisition, so the sale exceeded invested capital in aggregate, but that does not establish individual investor or employee returns.[11]
The strategic value to Twilio was distribution into developer accounts and a faster path from messaging APIs to identity. Authy gained an owner that already operated communications infrastructure and developer sales.
Approximately 6,000 sites used Authy by February 2015.[11] Named customers showed adoption across cryptocurrency, commerce, and internet infrastructure. The sources do not quantify active end users or authentication volume, so site count is the strongest available traction measure.
Authy's multi-device backup solved the loss and replacement problem that made ordinary authenticators brittle. Yet a phone-number-centered account created a target whose compromise could affect many linked services. During Twilio's 2022 breach, attackers registered devices on 93 accounts, enabling code generation for connected accounts.[7]
The July 2024 endpoint exposure revealed another version of the same mechanism. Twilio's incident response team wrote: "Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint."[9] Twilio found no evidence of account compromise or access to other sensitive internal data. The lesson is not that synchronization was wrong. It is that recovery convenience expands the service boundary that must remain secure.
Twilio's acquisition made strategic sense because Authy accelerated authentication integration from months to days.[12] The $6.1 million price was modest beside the long-term importance of identity, but the observed evidence cannot establish whether founders, employees, or investors viewed the outcome as strong.
Twilio CEO Jeff Lawson made the build-versus-buy logic explicit in 2015: "Authy had already built the solution we would have built."[11] Acquisition was therefore not a rescue from a failed product. It was recognition that Authy's developer-first architecture filled a gap Twilio's customers were rebuilding independently.
Authy improved a TOTP and SMS world. Passkeys now offer a phishing-resistant path without reusable shared secrets.[13] A modern successor should treat TOTP as a compatibility layer and center recovery, credential portability, and device trust across passkeys.