Bank 2FA without a US phone number: which logins actually work on an authenticator app
Disclosure: this article links to Tello. If you sign up through those links I may earn a commission, at no extra cost to you. It does not change what I recommend — I link to what I actually use or would use, and I say when I have not tested something.
The short version. Most major US brokerages now let you log in without a US phone number: Fidelity switched to standard authenticator-app (TOTP) codes on March 26, 2025, Vanguard backs YubiKey security keys, and Schwab uses the Symantec VIP app. Retail banks lag — Chase and Wells Fargo added passkeys in 2025–2026, but Citi is still SMS-only. The catch nobody mentions: nearly every institution still routes password resets and account recovery through an SMS code to a US number. So even after you move everything to an app, keep one cheap real US number (I use Tello) as the recovery anchor. This is a checklist by account type — set it up before you leave.
I’m Jin — a Japanese national who worked in US manufacturing for four years and researched the money side of moving between the two countries the hard way. When I looked into this for my own move, the whole “keep a US number for 2FA” conversation felt fatalistic — as if you’re chained to SMS forever. You’re not, mostly. A lot of your US logins can run on an authenticator app or a passkey with no phone number involved. But “mostly” is doing heavy lifting, and the gap is exactly where people get locked out. I’m not a licensed advisor — this is my own research, not tax or investment advice. Confirm each institution against its own security page before you rely on it.
The three ways to log in without a US number
There are exactly three second-factor methods that don’t touch a phone number:
| Method | What it is | Where it works | Phone number needed? |
|---|---|---|---|
| TOTP (authenticator app) | 6-digit codes from Google Authenticator, Microsoft Authenticator, Duo, 1Password, etc. | Fidelity, many fintechs | No |
| Passkey (FIDO2/WebAuthn) | Face ID / fingerprint or device passkey synced via iCloud Keychain or Google Password Manager | Chase, Wells Fargo, Capital One, U.S. Bank, Merrill | No |
| Hardware security key | A physical YubiKey you tap | Vanguard, Merrill, Bank of America (partial) | No |
TOTP and passkeys are phone-number-free by design. A passkey stored in iCloud Keychain follows your Apple account across devices — it never checks what SIM is in your phone. That’s the whole point, and it’s why these methods keep working the day your US SIM goes dark.
Brokerages: the checklist
Brokerages are where this matters most, because a locked brokerage abroad can mean missing a trade window or a required distribution. Here’s where each major one stands:
| Brokerage | Phone-number-free method | Notes |
|---|---|---|
| Fidelity | ✅ Standard TOTP (any authenticator app) | Dropped Symantec VIP on March 26, 2025. Set up online in Security settings — no phone call. YubiKey works too, via the Yubico Authenticator app storing the TOTP secret. |
| Schwab | ✅ Symantec VIP Access app (or ~$24 hardware token) | Standard TOTP apps are not supported — it has to be VIP. One VIP token can be registered at multiple firms. In-app Face ID push is also an option. |
| Vanguard | ✅ YubiKey (FIDO2 security key) | Register at least two keys as backup. Reportedly you cannot fully remove SMS as a fallback — a phone number stays on file. |
| Merrill / Merrill Edge | ✅ Synced passkeys and FIDO2 hardware keys | Both supported for sign-in. |
Two things to do before you leave:
- Fidelity + YubiKey: front-line reps often don’t know this exists. Send a secure message to Technical Support to enable it rather than calling in.
- Vanguard: enroll a spare YubiKey while you’re still in the US. Losing your only registered key abroad is a genuine lockout risk, and Vanguard’s non-US recovery is slow.
If you’re still deciding whether to keep your US brokerage open at all after moving, that’s a separate and bigger question — I walk through it in keeping a US brokerage when moving to Japan and the 401k/IRA side.
Retail banks: passkeys are spreading, but slowly
Banks are further behind, and none of the big ones offer a standard TOTP authenticator app the way Fidelity does. What they’re adding is passkeys:
| Bank | Phone-number-free method | Status |
|---|---|---|
| Chase | ✅ Passkeys on chase.com | Rolled out to retail customers in early 2026; in-app biometric login already existed. |
| Wells Fargo | ✅ Passkeys (iOS 16+, Android 14+) + browsers | Also in-app biometric approval. |
| Capital One | ✅ Passkeys | Create during sign-in or in Security settings. |
| U.S. Bank | ✅ Passkeys | Added November 2025. |
| Bank of America | ⚠️ FIDO2 hardware key as second factor only | No true passwordless passkey login, no TOTP app. |
| Citibank | ❌ SMS / voice call only | No passkeys, no authenticator app as of mid-2026. (This one changes fastest — re-check before you rely on it.) |
So a realistic setup: your brokerage runs on TOTP or a YubiKey, your Chase and Capital One accounts run on passkeys, and your Citi card… still texts you a code. Which brings us to the part everyone underestimates.
The SMS fallback problem — why a US number is still the anchor
Here’s the trap. Even when TOTP or a passkey covers your daily login, account recovery and password reset at most banks still route through an SMS code or a phone call to your registered US number. Vanguard reportedly can’t suppress the SMS path at all. So the day you forget a password, or a passkey doesn’t sync, or the bank forces a re-verification — you’re back to needing a text on a US number.
If that number is dead, you’re into call-in recovery from abroad: identity-verification hold music across a 13–14 hour time difference and, in the worst case, a frozen account. I wrote up how ugly that gets in locked out of a US bank from abroad. The hours and stress involved are the real cost of skipping this step — not the ~$5–10/month a number costs.
The hierarchy security-minded personal-finance sources recommend:
hardware key > authenticator app > SMS to Google Voice > real US carrier number.
The two ends do different jobs. TOTP and passkeys handle login. A real US number handles the recovery path that login methods can’t override. You want both.
Why a real number and not Google Voice? Because some banks refuse to send verification texts to VoIP numbers, and Google Voice can lapse if you don’t sign in periodically. I compare them directly in Google Voice vs a real US number for 2FA, and the broader keep-your-number playbook is in keeping a US phone number for 2FA after leaving.
My wife used Tello in the US at about $30/month for unlimited — it just worked, and it’s roughly the cheapest way to have a real US line. When I mapped out the exit plan, I let her number go but kept mine — I’m carrying it to Japan on Tello’s cheap keep-alive tier. The reason is the whole point of this article: my US bank and brokerage accounts are tied to that number, and losing 2FA access would be critical. A real number on a ~$5/month plan is the anchor under everything else.
(Full disclosure: the Tello links here are a referral — you and I each get $10 in Tello credit if you sign up through them. I’d point to Tello regardless; it’s the plan I actually chose for the number I’m keeping.) You can look at the Tello plans here.
Your before-you-leave checklist
Do this while you still have a working US SIM and can pass any SMS re-verification:
- Fidelity → turn on TOTP in Security settings. Save the backup seed somewhere safe.
- Schwab → install VIP Access (or register a VIP hardware token).
- Vanguard → register two YubiKeys.
- Chase / Capital One / Wells Fargo / U.S. Bank → create a passkey in each app’s security settings.
- Citi and any SMS-only holdout → accept it needs a US number, and point it at your kept number.
- Keep one real US number on a cheap plan as the recovery anchor. Port it before your line closes — see port your US number before moving abroad.
Skipping steps 1–4 costs you nothing but a spare evening. Skipping step 6 can cost you an account.
FAQ
Can I really use a bank without a US phone number?
For daily login, yes at a growing number: Fidelity via authenticator app, Chase/Capital One/Wells Fargo/U.S. Bank via passkeys, Vanguard via YubiKey. But almost none of them let you fully delete SMS from the recovery path, so a US number is still the safety net even when you never use it to log in.
Which authenticator app should I use for my US bank?
For Fidelity, any standard TOTP app works — Google Authenticator, Microsoft Authenticator, Duo, or a password manager like 1Password. Schwab is the exception: it only accepts its own Symantec VIP Access app, not standard TOTP. Most retail banks don’t offer a TOTP app at all and use passkeys or SMS instead.
If I set up TOTP and passkeys everywhere, do I still need Tello?
In practice, yes. Password resets, new-device verification, and periodic re-authentication at most banks still fall back to an SMS code, and some (like Vanguard) can’t turn that off. A ~$5/month real US number keeps that recovery door open — which is why I’m carrying mine to Japan on Tello. Treat it as insurance, not a daily-use line.