Apple Watch¶
Private Authenticator has an Apple Watch app, so you can read a code from your wrist without reaching for the phone. The Watch app shows codes only: adding, editing and everything else stays on the iPhone.
Setting it up¶
- Install the Watch app. Open the Watch app on your iPhone, scroll down to Available Apps, and tap Install beside Private Authenticator. Your Watch needs watchOS 10 or later.
- Give the Watch a passcode, if it doesn't have one (Watch app → Passcode). The Watch app refuses to run without one, because the passcode is what protects your codes there.
- Turn on Device Sync. In Private Authenticator on the iPhone, go to Info → Settings, and under Apple Watch switch on Use Device Sync. Face ID or Touch ID confirms, and the app sends every active account, with its tags, to the Watch.
- Open Private Authenticator on the Watch. The setting stays greyed out on the iPhone, with the note Waiting for your Apple Watch to confirm the change, until the Watch app has received the accounts. Once it has, the note reads Synced: 12 accounts and 3 tags on the Watch.
[Screenshot: the Settings page's Apple Watch section with Use Device Sync on and the Synced note]
Everything travels over the private connection between your iPhone and its paired Watch, never through iCloud, and never through Pebble IT.
Using the Watch app¶
Open the app on the Watch and unlock it with the Watch's passcode. It always asks. You then see three pages to swipe between:
- Recent: the accounts you used most recently at the top, just like the iPhone. Using a code on the Watch moves the account to the top on the iPhone too, and the other way round.
- Alphabetical: every account by name, with an A–Z / Z–A button.
- Tags: your tags with their counts, and 🚫 No Tags for the rest. Tap a tag to see its accounts.
Tap an account and its code appears straight away, with the three pebbles emptying below it. A coloured ring around the edge of the screen shrinks as the code screen's time runs out (the same Close After time as on the iPhone), turning red near the end. Swipe up or down for the account's name and description, its tags, and its code type and the time of the last sync. Tap the code to close it. There is no copying on the Watch; that's a limit of watchOS, not of the app.
[Screenshot: the Watch showing a code with the ring around the edge]
The Watch app locks itself again whenever the screen dims or the Watch locks, and after the iPhone's Idle Timeout with nothing touched. Each unlock lands you on Recent.
What is, and isn't, on the Watch¶
- Active accounts only. Archived accounts are never sent, and archiving an account removes it from the Watch.
- Tags come across with their accounts; a tag with no active account isn't shown.
- An account added on another iPhone through iCloud Keychain sync, or one you have just unarchived, isn't on the Watch yet. The iPhone's Settings page lists how many are waiting. Open each one's code once on the iPhone and it goes across, or switch Device Sync off and on again to send everything afresh.
- Settings don't exist on the Watch. The Close After and Idle Timeout values follow the iPhone's.
Turning it off¶
Switch Use Device Sync off on the iPhone. The app asks you to confirm with Turn Off and Remove from Watch, because turning it off removes every account from the Watch. The switch stays greyed out until the Watch has confirmed.
Unpairing a Watch from the iPhone erases the Watch completely, Private Authenticator's accounts included, so a Watch you sell or pass on never keeps your codes.
Messages you might see on the Watch¶
- No passcode: set one in the Watch app on your iPhone, under Passcode, then open the app again.
- No accounts: check that Device Sync is on in Private Authenticator's Settings on the iPhone, and open the app there so it can send.
- This account is no longer on the Watch: it was archived or removed on the iPhone while its code was open. Go back to the list.
Each of these offers Quit, which closes the Watch app.
Continue to the Backups & Moving book: Why Back Up?.