What is Auth Code?
Also known as: EPP Code, Transfer Key
A unique, per-domain secret code that the losing (current) registrar must provide so the gaining (new) registrar can authorize a domain transfer.
An Auth Code is a secret token assigned to a domain name by its current registrar. It functions as a proof of authorization for domain transfers between registries. The Extensible Provisioning Protocol (EPP), which is the standard protocol for domain registration and management, defines the Auth Info code field. Therefore, the code is often called the EPP Code or Transfer Key.
When a domain owner wants to transfer a domain to a different registrar, the losing registrar must first release the Auth Code to the owner. The owner then gives this code to the gaining registrar, who submits it to the registry as part of the transfer request. The registry validates the code against its records. If it matches and the transfer lock is removed, the transfer proceeds. If the code is incorrect or the domain is locked, the transfer is rejected.
Auth Codes are typically a random, case-sensitive string of letters, numbers, and special characters. They are generated by the registrar and visible in the domain management panel. For generic top-level domains (gTLDs), ICANN rules require registrars to provide the Auth Code upon request. For country-code TLDs (ccTLDs), policies vary. Some ccTLDs do not use Auth Codes at all, using alternative authorization methods. The code is a security measure. It prevents unauthorized transfers by ensuring only the verified domain owner can initiate a move.
Key facts
- Each domain has a unique Auth Code, generated by the current registrar.
- The code must be supplied by the losing registrar and entered by the gaining registrar.
- ICANN policy mandates registrars provide the Auth Code for gTLDs on request.
- The transfer will fail if the Auth Code is incorrect or if the domain has a transfer lock.
- Auth Code is synonymous with EPP Code and Transfer Key in common usage.
How it works in practice
Related terms
References
More in Domains
ccTLD
A ccTLD is a two-letter top-level domain assigned to a country or territory based on the ISO 3166-1 alpha-2 code, such as .us for the United States or .jp for Japan.
Domain Lock
A registrar-level status that prevents unauthorized domain transfers, modifications, or deletions until the registrant explicitly removes the lock.
Domain Privacy
An optional service that replaces the domain registrant's personal contact information in WHOIS records with the registrar's proxy details to shield the owner from spam and unwanted disclosure.
EPP
EPP (Extensible Provisioning Protocol) is an XML-based application protocol used by domain name registries and registrars to provision domain names, manage contacts, and transfer registrations.
Grace Period
The grace period is a window after a domain expires during which the registrant can renew at the standard renewal fee, without incurring additional redemption costs.
IDN
An Internationalized Domain Name (IDN) is a domain name that includes characters outside the ASCII set, encoded as Punycode for compatibility with the DNS.
Punycode
Punycode is a method defined in RFC 3492 for converting Unicode strings into ASCII labels, enabling Internationalized Domain Names (IDNs) to be used in the DNS.
RDAP
RDAP (Registration Data Access Protocol) is a modern RESTful protocol for querying domain name and IP address registration data, replacing the older WHOIS protocol with structured JSON responses and role-based access controls.
Registrant
The registrant is the legal holder of a domain name, listed as the owner in the registry database and responsible for the domain's renewal and administration.
Registrar
A domain registrar is an ICANN-accredited company that sells domain name registrations to individuals and organizations, managing the reservation of domain names within the DNS.