How to get an SMS verification code from Android onto your Mac

·7 min read

You are signing in to your bank on the Mac, and the code goes to the Android phone in your bag. The free fix is Google Messages for web: keep it open in a browser tab and the text, code included, appears on the Mac for you to copy. The Relay goes one step further and copies the code to the Mac's clipboard when the text arrives, so you only paste. For accounts that allow it, the better long-term fix is to stop using texted codes at all and switch to a passkey or an authenticator app.

Publisher note: The Relay publishes this guide and is one of the products discussed. Details about other products come from each maker's own pages, checked on 1 October 2026. Prices and features change, so confirm before you buy.

How does a Mac do this with an iPhone?

Apple's Safari guide has a page called Autofill security codes from your iPhone in Safari on Mac. You turn on Text Message Forwarding on the iPhone, in Settings under Messages, and select your Mac. After that, when a website sends a security code to the iPhone, "Safari provides the information on your Mac" and you click the code to fill it in.

That depends on Text Message Forwarding, which is an iPhone feature. An Android phone cannot forward its texts into the Mac's Messages app, so Safari never sees the code. The three routes below are how you get the same result.

Option 1: Google Messages for web (free)

Google Messages for web shows the texts from your phone's Google Messages app in a browser on the Mac. Google's page says it works in Chrome, Firefox, Safari, or Edge and needs Android 5.0 or later on the phone.

To use it for codes:

  1. Pair it once. On the phone, open Google Messages, tap your account menu, then Device Pairing. On the Mac, open messages.google.com/web and sign in with the same Google Account. Full steps are in Android messages on a Mac.
  2. Keep the tab open, and pin it so it survives a tidy-up.
  3. When a site texts you a code, switch to the tab. Google says the tab's icon "will show a red notification and the number of unread messages".
  4. Select the code, copy it, switch back, and paste.

What to know:

  • The phone has to be switched on and online. Google says messages travel over "a connection from your computer to your phone".
  • It only shows texts handled by the Google Messages app. If your Galaxy uses a different texting app, you would have to switch.
  • Google warns about shared computers for exactly this reason. It says unpairing keeps other people from seeing "sensitive info, like two factor verification codes". Do not leave it paired on a Mac other people use.
  • Google's page says you are unpaired automatically after a few weeks without use, so the tab can be signed out on the day you need it.

If you get a code a week, this is enough. Do not pay for anything.

Option 2: a notification mirroring app

Apps that show the phone's notifications on the Mac will show the text message notification too, and with it the code, if the notification's preview includes it. KDE Connect is the free one, with a stable macOS release listed on its download page.

There is a catch on newer phones. Google's Android 15 behaviour changes say Android stops untrusted apps that listen to notifications "from reading unredacted content from notifications where an OTP has been detected". OTP means one-time password. KDE Connect's wiki confirms what that looks like: on Android 15 or later it shows "Sensitive notification content hidden" in place of the real text, unless the app is granted an extra permission with a developer command from a computer. So on a recent Pixel or Galaxy, the one notification you wanted may be the one that arrives blank. Test with a real code before you rely on this route. Background on the permission involved is in Android notifications on a Mac.

Option 3: The Relay

With The Relay, an SMS that arrives on the phone shows up on the Mac, and a login code in it is copied to the Mac's clipboard so you can paste it. You stay in the form you were filling in and press Command-V.

It is installed on both devices and paired by scanning a QR code shown on the Mac. Your texts travel directly between your phone and your Mac over your local network and are not uploaded to The Relay's servers. The privacy policy has the detail. It needs Android 8.0 or later and macOS 13 Ventura or later, costs $19.99, paid once, and comes from the download page.

Its limits, plainly:

  • It shows incoming texts. It does not send texts from the Mac. To reply to people, keep Google Messages for web.
  • The phone and the Mac must be on the same network or within Bluetooth range. If the phone is at home and you are at the office, the code will not reach the Mac.
  • It is not free. If codes are rare for you, Option 1 costs nothing.

Where it earns its price is frequency. If your work logs you out daily and your bank, your payroll, and your email each text you a code, removing the trip to the phone each time adds up. The same app also handles the clipboard, files, notifications, calls, links, and the webcam.

Which route fits?

Your situationUse
A code now and thenGoogle Messages for web
Codes most days, phone on the desk next to the MacThe Relay
You already run KDE Connect and your phone is on Android 14 or earlierIts notification sync, after a test
The phone is in another buildingGoogle Messages for web, if the phone is on and online
The account offers a passkey or an authenticator appSwitch, and skip the text altogether

Should I still be using texted codes?

Sometimes you have no choice, because the service offers nothing else. Where you do have a choice, the standards bodies and the platform makers point the same way.

  • The US standards agency NIST, in its digital identity guideline SP 800-63B, classes codes sent over the phone network as a restricted method. It tells services that use them to watch for risk indicators such as "device swap, SIM change, number porting".
  • The FIDO Alliance, the industry group behind passkeys, says "Passkeys are phishing resistant and secure by design", and calls one-time codes as a second factor "both inconvenient and still phishable".
  • Google's page on signing in with a passkey says you sign in with your fingerprint, face scan, or phone screen lock, and that passkeys "can't be shared, copied, written down, or accidentally given to someone else".

Two practical moves:

Passkeys, where offered. A passkey signs you in with your fingerprint, face, or screen lock, with no texted code to carry from the phone to the Mac.

An authenticator app, where passkeys are not offered. Google says Google Authenticator can "generate one-time verification codes for sites and apps" and that you "can still generate codes without an internet connection or mobile service". You still enter a code, but it no longer depends on a text arriving. If you copy the code on the phone, a synced clipboard carries it to the Mac. See clipboard sync between Android and a Mac.

Changing sign-in methods is a decision about your own accounts. Follow each service's instructions, and keep your recovery options up to date before you remove a phone number.

How do I test my setup in five minutes?

  1. Pick a low-stakes account that texts a code, such as a shopping site.
  2. Put the phone out of reach, screen locked.
  3. Sign in on the Mac and request the code.
  4. Note whether the code reached the Mac, whether you had to switch windows to get it, and whether the digits were readable or hidden.
  5. Repeat after the Mac has been asleep for an hour, which is when pairings tend to drop.

Questions people ask

Can the Mac's Messages app receive codes from an Android phone?

No. Apple's code autofill relies on Text Message Forwarding from an iPhone. The Mac's Messages app has no way to receive the SMS sent to an Android phone's number.

Is it safe to have login codes appear on my Mac?

It moves the code to a second screen, so the Mac needs the same care as the phone: a login password, a locked screen when you walk away, and no shared user accounts. Google advises unpairing Messages for web on shared computers because of two-factor codes. With The Relay, the text travels between your own devices on your local network. No tool can promise an outcome for your accounts, so use codes on a Mac you control.

Why does my notification app show the code as hidden?

On Android 15 or later, Android redacts notifications in which it detects a one-time password before handing them to untrusted notification listener apps. KDE Connect documents the result as "Sensitive notification content hidden".

Does Google Messages for web copy the code for me?

Google's help page describes reading and sending messages in the browser. It does not describe copying codes to the clipboard automatically, so plan on selecting and copying the code yourself.

What about codes from WhatsApp or email?

Those are not SMS. Open the service's own web or desktop version on the Mac, where the code arrives directly.

KEEP READING

SOURCES · CHECKED 1 OCTOBER 2026