Jin US ↔ JAPAN MONEY
Before you leave

Bank 2FA without a US phone number: which logins actually work on an authenticator app

By Jin · A Japanese expat who spent 4 years in the US · August 4, 2026 · 8 min read

Disclosure: this article links to Tello. If you sign up through those links I may earn a commission, at no extra cost to you. It does not change what I recommend — I link to what I actually use or would use, and I say when I have not tested something.

The short version. Most major US brokerages now let you log in without a US phone number: Fidelity switched to standard authenticator-app (TOTP) codes on March 26, 2025, Vanguard backs YubiKey security keys, and Schwab uses the Symantec VIP app. Retail banks lag — Chase and Wells Fargo added passkeys in 2025–2026, but Citi is still SMS-only. The catch nobody mentions: nearly every institution still routes password resets and account recovery through an SMS code to a US number. So even after you move everything to an app, keep one cheap real US number (I use Tello) as the recovery anchor. This is a checklist by account type — set it up before you leave.

I’m Jin — a Japanese national who worked in US manufacturing for four years and researched the money side of moving between the two countries the hard way. When I looked into this for my own move, the whole “keep a US number for 2FA” conversation felt fatalistic — as if you’re chained to SMS forever. You’re not, mostly. A lot of your US logins can run on an authenticator app or a passkey with no phone number involved. But “mostly” is doing heavy lifting, and the gap is exactly where people get locked out. I’m not a licensed advisor — this is my own research, not tax or investment advice. Confirm each institution against its own security page before you rely on it.

The three ways to log in without a US number

There are exactly three second-factor methods that don’t touch a phone number:

MethodWhat it isWhere it worksPhone number needed?
TOTP (authenticator app)6-digit codes from Google Authenticator, Microsoft Authenticator, Duo, 1Password, etc.Fidelity, many fintechsNo
Passkey (FIDO2/WebAuthn)Face ID / fingerprint or device passkey synced via iCloud Keychain or Google Password ManagerChase, Wells Fargo, Capital One, U.S. Bank, MerrillNo
Hardware security keyA physical YubiKey you tapVanguard, Merrill, Bank of America (partial)No

TOTP and passkeys are phone-number-free by design. A passkey stored in iCloud Keychain follows your Apple account across devices — it never checks what SIM is in your phone. That’s the whole point, and it’s why these methods keep working the day your US SIM goes dark.

Brokerages: the checklist

Brokerages are where this matters most, because a locked brokerage abroad can mean missing a trade window or a required distribution. Here’s where each major one stands:

BrokeragePhone-number-free methodNotes
Fidelity✅ Standard TOTP (any authenticator app)Dropped Symantec VIP on March 26, 2025. Set up online in Security settings — no phone call. YubiKey works too, via the Yubico Authenticator app storing the TOTP secret.
Schwab✅ Symantec VIP Access app (or ~$24 hardware token)Standard TOTP apps are not supported — it has to be VIP. One VIP token can be registered at multiple firms. In-app Face ID push is also an option.
Vanguard✅ YubiKey (FIDO2 security key)Register at least two keys as backup. Reportedly you cannot fully remove SMS as a fallback — a phone number stays on file.
Merrill / Merrill Edge✅ Synced passkeys and FIDO2 hardware keysBoth supported for sign-in.

Two things to do before you leave:

  • Fidelity + YubiKey: front-line reps often don’t know this exists. Send a secure message to Technical Support to enable it rather than calling in.
  • Vanguard: enroll a spare YubiKey while you’re still in the US. Losing your only registered key abroad is a genuine lockout risk, and Vanguard’s non-US recovery is slow.

If you’re still deciding whether to keep your US brokerage open at all after moving, that’s a separate and bigger question — I walk through it in keeping a US brokerage when moving to Japan and the 401k/IRA side.

Retail banks: passkeys are spreading, but slowly

Banks are further behind, and none of the big ones offer a standard TOTP authenticator app the way Fidelity does. What they’re adding is passkeys:

BankPhone-number-free methodStatus
Chase✅ Passkeys on chase.comRolled out to retail customers in early 2026; in-app biometric login already existed.
Wells Fargo✅ Passkeys (iOS 16+, Android 14+) + browsersAlso in-app biometric approval.
Capital One✅ PasskeysCreate during sign-in or in Security settings.
U.S. Bank✅ PasskeysAdded November 2025.
Bank of America⚠️ FIDO2 hardware key as second factor onlyNo true passwordless passkey login, no TOTP app.
Citibank❌ SMS / voice call onlyNo passkeys, no authenticator app as of mid-2026. (This one changes fastest — re-check before you rely on it.)

So a realistic setup: your brokerage runs on TOTP or a YubiKey, your Chase and Capital One accounts run on passkeys, and your Citi card… still texts you a code. Which brings us to the part everyone underestimates.

The SMS fallback problem — why a US number is still the anchor

Here’s the trap. Even when TOTP or a passkey covers your daily login, account recovery and password reset at most banks still route through an SMS code or a phone call to your registered US number. Vanguard reportedly can’t suppress the SMS path at all. So the day you forget a password, or a passkey doesn’t sync, or the bank forces a re-verification — you’re back to needing a text on a US number.

If that number is dead, you’re into call-in recovery from abroad: identity-verification hold music across a 13–14 hour time difference and, in the worst case, a frozen account. I wrote up how ugly that gets in locked out of a US bank from abroad. The hours and stress involved are the real cost of skipping this step — not the ~$5–10/month a number costs.

The hierarchy security-minded personal-finance sources recommend:

hardware key > authenticator app > SMS to Google Voice > real US carrier number.

The two ends do different jobs. TOTP and passkeys handle login. A real US number handles the recovery path that login methods can’t override. You want both.

Why a real number and not Google Voice? Because some banks refuse to send verification texts to VoIP numbers, and Google Voice can lapse if you don’t sign in periodically. I compare them directly in Google Voice vs a real US number for 2FA, and the broader keep-your-number playbook is in keeping a US phone number for 2FA after leaving.

My wife used Tello in the US at about $30/month for unlimited — it just worked, and it’s roughly the cheapest way to have a real US line. When I mapped out the exit plan, I let her number go but kept mine — I’m carrying it to Japan on Tello’s cheap keep-alive tier. The reason is the whole point of this article: my US bank and brokerage accounts are tied to that number, and losing 2FA access would be critical. A real number on a ~$5/month plan is the anchor under everything else.

(Full disclosure: the Tello links here are a referral — you and I each get $10 in Tello credit if you sign up through them. I’d point to Tello regardless; it’s the plan I actually chose for the number I’m keeping.) You can look at the Tello plans here.

Your before-you-leave checklist

Do this while you still have a working US SIM and can pass any SMS re-verification:

  1. Fidelity → turn on TOTP in Security settings. Save the backup seed somewhere safe.
  2. Schwab → install VIP Access (or register a VIP hardware token).
  3. Vanguard → register two YubiKeys.
  4. Chase / Capital One / Wells Fargo / U.S. Bank → create a passkey in each app’s security settings.
  5. Citi and any SMS-only holdout → accept it needs a US number, and point it at your kept number.
  6. Keep one real US number on a cheap plan as the recovery anchor. Port it before your line closes — see port your US number before moving abroad.

Skipping steps 1–4 costs you nothing but a spare evening. Skipping step 6 can cost you an account.

FAQ

Can I really use a bank without a US phone number?

For daily login, yes at a growing number: Fidelity via authenticator app, Chase/Capital One/Wells Fargo/U.S. Bank via passkeys, Vanguard via YubiKey. But almost none of them let you fully delete SMS from the recovery path, so a US number is still the safety net even when you never use it to log in.

Which authenticator app should I use for my US bank?

For Fidelity, any standard TOTP app works — Google Authenticator, Microsoft Authenticator, Duo, or a password manager like 1Password. Schwab is the exception: it only accepts its own Symantec VIP Access app, not standard TOTP. Most retail banks don’t offer a TOTP app at all and use passkeys or SMS instead.

If I set up TOTP and passkeys everywhere, do I still need Tello?

In practice, yes. Password resets, new-device verification, and periodic re-authentication at most banks still fall back to an SMS code, and some (like Vanguard) can’t turn that off. A ~$5/month real US number keeps that recovery door open — which is why I’m carrying mine to Japan on Tello. Treat it as insurance, not a daily-use line.