DOMAIN GLOSSARYUPDATED 2026-05-06

Authcode

An authcode (also called EPP code or transfer code) is a domain-specific password used to authorise a transfer between registrars. The losing registrar generates the code; the registrant supplies it to the gaining registrar; the gaining registrar uses it to initiate the transfer. Authcodes are required for almost all gTLD and many ccTLD transfers.

Also known as: Auth code, EPP code, Transfer code

In depth

When a registrant decides to move a domain from one registrar to another, the gaining registrar must prove they have authorisation. The authcode is the proof — a per-domain secret that only the legitimate registrant should be able to obtain.

The flow: registrant disables the registrar lock at the losing registrar. Registrant retrieves the authcode (some registrars email it; others display it in the dashboard). Registrant provides the authcode to the gaining registrar along with payment. Gaining registrar submits an EPP transfer request with the authcode.

After submission the losing registrar has 5 days to approve, deny, or let the transfer auto-approve. ICANN policy auto-approves after 5 days unless the losing registrar explicitly denies (with a valid reason).

Authcodes are sometimes single-use — the losing registrar may regenerate after each transfer attempt. They are sometimes time-limited. Always retrieve a fresh authcode at transfer time.

Examples

  • Standard transfer flow: disable registrar lock → retrieve authcode → submit to gaining registrar → wait 5 days for completion.
  • Common bug: using a stale authcode that has been regenerated. Solution: retrieve fresh code immediately before transfer.
  • A registrar that requires email verification for authcode retrieval (Namecheap, GoDaddy) adds a security layer against account takeover.

Frequently asked questions

How do I get an authcode?

From your current (losing) registrar's dashboard. The exact location varies by registrar. Some email it for security; some display it directly.

Why is the authcode required?

Security. It proves to the gaining registrar that the legitimate registrant authorised the transfer.

How long is an authcode valid?

Varies. Some registrars regenerate after each retrieval; some have time limits (e.g., 24 hours); some persist indefinitely. Always retrieve a fresh one at transfer time.

Can my registrar refuse to provide an authcode?

Generally no, except during specific lock periods (60-day post-transfer lock, dispute resolution). ICANN policy requires registrars to provide authcodes within 5 days of request.

What if the authcode does not work?

Retrieve a fresh code (often regenerated each time). Verify there are no active locks. Confirm the receiving registrar accepts the TLD.

Related terms

References

Watch a domain you want to buy — snooze.domains tracks the lifecycle and emails you when it changes status. Free, up to 100 domains. Start watching — free