authorization code
An authorization code is a one-time secret your current registrar issues that proves you have the right to move a domain to a different registrar.
An authorization code, sometimes called an EPP code after the transfer protocol it comes from, is a short string of letters and numbers that acts as proof of ownership when a domain moves between registrars. Think of it as a one-time password specific to that domain and that move. The registrar you are leaving generates it, you hand it to the registrar you are moving to, and that exchange is what lets the transfer proceed instead of being rejected outright.
It exists because domain transfers are exactly the kind of moment transfer lock is designed to guard against. Without some proof that the request is coming from the actual owner, anyone could ask a registrar to hand over a domain that is not theirs. The code is that proof, and it is deliberately short-lived so an old, leaked code cannot be reused later.
Why it matters to you
You mostly never think about this code until the moment you need it, and that moment tends to be time-sensitive: consolidating scattered domains under one account, moving away from a registrar that has become unreliable, or taking full ownership of a domain a vendor originally registered on your behalf. In every one of those cases, the code is the one thing standing between “domain moved” and “transfer stuck.”
The awkward version of this is finding out, mid-move, that the registrar holding your domain will not release the code without a request that only the account owner can make, and the account owner is a former vendor who is slow to respond or gone entirely. That is a much harder problem to solve than getting the code itself.
How I use it
When I am moving a domain, I request the authorization code first, before anything else, since it is often the step with the longest wait if access to the old account is uncertain. Once I have it, I keep the transfer lock off only for the window the transfer actually needs, submit the code to the new registrar, and confirm the move completed before locking it again.
I never ask a client to hand a code to me over an insecure channel like a plain text message. It is a credential, even though it is short-lived, and I treat it the way I treat any other password: passed through something like a password manager, not pasted into a chat that sits around forever.
What it looks like in practice
You will see this code exactly once per transfer, if you see it at all. It usually shows up as a short jumble of characters on a settings page or in an email from your registrar, valid for a limited window. Once the transfer it was issued for goes through, or the window closes, that same code stops working and a fresh one would be needed for any future move.
If a domain of yours ever needs to change hands, this is the piece I go and get first, because everything else in the transfer waits on it.
Questions I get about this
- Where do I get my domain's authorization code?
- From the registrar that currently holds the domain, usually somewhere in the domain's own settings page under a label like "transfer" or "authorization code." Some registrars email it to you instead of showing it directly.
- Does the authorization code ever expire?
- Yes, usually within a few days to a couple of weeks of being issued, and it becomes invalid once used. Request a fresh one right before you actually need it rather than pulling it far in advance.
- Is it safe to share my authorization code with a new registrar?
- Yes, that is the intended use. It only works for the one domain it was issued for, and only while a transfer is actually being requested. Do not post it anywhere public or send it to anyone other than the registrar you are moving to.
Want this set up properly for your business?
This is the kind of thing I build every week. Grab a time and we will talk through what fits.