Back to all companies
Sign in
Back to all companies
Authy logo

Authy

Winter 2012Acquired

Authy is a Two-Factor Authentication platform for developers

Save
Authy logo

Authy

Winter 2012Acquired

Authy is a Two-Factor Authentication platform for developers

Save
Company details

Authy provides strong authentication for the connected world, protecting people and the enterprise against malicious attacks. Our two-factor authentication (2FA) security solution enables organizations to minimize risk while enhancing the user experience.

Authy 2FA provides a fast-to-implement, highly scalable and proven 99.999 % reliable alternative to passwords. Used by 11,000+ websites serving 2 million consumers worldwide, it's designed to give users the ability to self-service or easily manage their own 2FA experience. Coinbase, CloudFlare, Humble Bundle and Twitch.tv are just some Authy clients.

Authy is a Twilio company. Follow us on: Twitter at @Authy Facebook at https://www.facebook.com/authysec Google+ at https://plus.google.com/+Authy GitHub at https://github.com/authy

Location
San Francisco, CA, USA
Founded
2011
Category
Security
YC Directory Pageauthy.com
Founders
  • DP
    Daniel Palacio
    Founder/CEO
    LinkedIn
  • GC
    Gleb Chuvpilo
    Founder
    X / TwitterLinkedIn

Authy provides strong authentication for the connected world, protecting people and the enterprise against malicious attacks. Our two-factor authentication (2FA) security solution enables organizations to minimize risk while enhancing the user experience.

Authy 2FA provides a fast-to-implement, highly scalable and proven 99.999 % reliable alternative to passwords. Used by 11,000+ websites serving 2 million consumers worldwide, it's designed to give users the ability to self-service or easily manage their own 2FA experience. Coinbase, CloudFlare, Humble Bundle and Twitch.tv are just some Authy clients.

Authy is a Twilio company. Follow us on: Twitter at @Authy Facebook at https://www.facebook.com/authysec Google+ at https://plus.google.com/+Authy GitHub at https://github.com/authy

Location
San Francisco, CA, USA
Founded
2011
Category
Security
YC Directory Pageauthy.com
Founders
  • DP
    Daniel Palacio
    Founder/CEO
    LinkedIn
  • GC
    Gleb Chuvpilo
    Founder
    X / TwitterLinkedIn

Pressure-test this opportunity

Turn this teardown into a decision-ready prompt for ChatGPT, Claude, or your agent.

On this page
  • Overview
  • Founding Story
  • Timeline
  • What They Built
  • Market Position
  • Target Customers
  • Market Size
  • Competition
  • Business Model
  • Traction
  • Post-Mortem
  • Convenience concentrated recovery risk
  • The product moved inside a broader platform
  • Authentication standards moved forward
  • Key Lessons
  • Sources

This report was generated by our Deep Research agent and may contain mistakes.

Did we get something wrong? DM @oscrhong and we'll fix it ASAP!

Startups.RIP — Dead startups, alive ideas
PricingContactPrivacyGot feedback? DM @oscrhong
Exec Briefing

Actionable insights

If you only have a few minutes to spare, here’s what investors, operators, and founders should know about Authy (W12).

  1. Recovery was the wedge. Device loss and migration made ordinary authenticators brittle; solving continuity helped stronger authentication reach mainstream users.
  2. Developer speed drove adoption. Packaging enrollment, delivery, and recovery behind an API helped roughly 6,000 sites adopt Authy before acquisition.
  3. Convenience expands the perimeter. Synchronization reduced user pain, but device registration and phone-number recovery became security-critical surfaces.
  4. Standards move the boundary. Passkeys reduce dependence on shared secrets, shifting value toward cross-device recovery, governance, and credential portability.

Overview

Authy made two-factor authentication easier for developers and less fragile for users. Founded by Daniel Palacio in 2011 and launched through Y Combinator's Winter 2012 batch, it combined an API for relying websites with an encrypted, synchronized authenticator app.[1]

This is an acquisition story, not a shutdown. Twilio bought Authy for $6.1 million in 2015 after roughly 6,000 sites had adopted it.[2] Authy's distribution and recovery design solved real problems, but its phone-number identity model also concentrated risk. Later breaches and endpoint exposure showed the tension between convenient recovery and a centralized attack surface.

Founding Story

Palacio came to authentication through security work. He had been a penetration tester and had worked on Microsoft's Windows security team before starting Authy. TechCrunch reported that he was tired of internet services relying on passwords alone.[3]

Authy's initial insight was practical: two-factor authentication failed when every service had to build enrollment, delivery, recovery, and fraud controls itself. The company offered those mechanics through a developer API, while its app generated time-based codes offline and encrypted backups behind a password Authy did not store.[4]

The observed research contains only one fetched founder quotation and does not preserve its exact wording. A second founder interview or transcript was not found. Rather than inventing dialogue, this report records the gap. The evidence still shows a consistent founder thesis: remove the engineering work that kept stronger authentication out of ordinary products.

Timeline

  • 2011: Palacio founded Authy.
  • Winter 2012: Authy joined Y Combinator and launched its developer authentication API.[1]
  • September 2014: Authy raised $2.3 million and hired Marc Boroditsky as president and COO to pursue enterprise customers.[5]
  • February 2015: Twilio acquired Authy for $3 million in cash and $3.1 million in preferred stock.[2]
  • 2020: Twilio renamed the app Twilio Authy.[6]
  • August 2022: Attackers registered devices on 93 Authy accounts during Twilio's social-engineering breach.[7]
  • March 2024: Authy's desktop apps reached end of life.[8]
  • July 2024: Twilio secured an unauthenticated endpoint that exposed Authy account data including phone numbers.[9]

What They Built

Authy joined two products that competitors often separated. Developers integrated an API to enroll users and challenge logins by SMS or app-generated token. Consumers installed one authenticator that could retain encrypted TOTP seeds, work offline, back up accounts, and synchronize them across devices.[4]

The phone number became the bridge. It gave developers a familiar identifier and gave users a path to move tokens to a new device. Twilio later added QR enrollment that kept phone and email data from the relying website, an attempt to preserve convenience while reducing disclosure.[10]

That architecture differentiated Authy from single-device code generators. It also meant recovery could become an authentication event with high consequences. Authy had to secure app access, device registration, encrypted backups, phone-number changes, and the service endpoints connecting them.

Market Position

Target Customers

Authy initially sold to developers who wanted two-factor authentication without building carrier delivery and token infrastructure. By 2014 it had hired an identity executive to pursue enterprise accounts. Coinbase, MercadoLibre, and Cloudflare were among roughly 6,000 sites using Authy when Twilio acquired it.[11]

Market Size

The observed sources do not establish a reliable market-size figure. Adoption is clearer than revenue: thousands of sites integrated Authy within four years, proving demand for an outsourced authentication layer. Contract values, retention, gross margins, and consumer usage were not disclosed.

Competition

Authy competed with authenticator apps, SMS providers, enterprise identity vendors, and internal security teams. Its advantage was integration speed plus consumer recovery. Twilio said Authy cut an authentication integration from months to days, matching Twilio's API-first developer strategy.[12]

Unlock the full Authy teardown

Read the complete post-mortem, the rebuild playbook, and the exact reasons Authy is still worth studying now.

See Pro plans