Search “awardwallet not working” and you land in the middle of an argument that has been running for a couple of years. Forum threads, one-star reviews, cancelled subscriptions, people rebuilding spreadsheets. The common thread is almost always the same three characters: 2FA.
I’m Jakke, and I built Gast — so I am not a neutral party here. But this is not a hit piece, because AwardWallet earned its place. For years it was the best tool of its kind; one reviewer called it “absolutely fantastic a few years ago,” which is fair. The problem is not that the team got lazy. It is that the thing breaking it is baked into how the tool works — and it is getting worse, not better.
When I researched Gast, I read 77 AwardWallet reviews across the US and German App Stores plus a stack of Head for Points and FlyerTalk threads. Sync failure tied to two-factor authentication was the single most common complaint — roughly a quarter of them. Here is what is actually happening, why it is structural rather than a patchable bug, and what a tracker looks like when the conflict cannot occur.
Why AwardWallet stops working: the short version
AwardWallet keeps your loyalty balances up to date by logging into each airline, hotel, and card account on your behalf, using the username and password you gave it. When a loyalty programme turns on two-factor authentication (2FA/MFA), that automated login can no longer complete on its own — it needs a one-time code that only you receive. The sync fails, and in some cases the programme reads the repeated login attempts as suspicious and locks the account. Because 2FA is now standard across European loyalty programmes, this is a structural limit of any credential-based tracker, not a temporary outage.
Source: Gast research — 77 AwardWallet reviews (US + DE App Stores) plus Head for Points and FlyerTalk threads. Last verified: [FOUNDER: verify date]
How AwardWallet actually updates your balances
The headline feature of AwardWallet is automatic sync: your balances stay current without you touching them. To do that, the tool needs a way in. So it asks for your login — your British Airways password, your Miles & More password, your hotel account password — and stores it. Then, on a schedule, it logs in as you, reads the balance off the page, and updates your number.
When it works, it is genuinely convenient. But look at what it requires: a third party holding your credentials and impersonating you every time it refreshes. That model was fine when a username and password was all a website asked for. It is not that era anymore.
Two-factor authentication is designed, on purpose, to stop exactly this — an automated login from something that is not you, at your device, right now. When British Airways or Qatar or Payback turns on 2FA, the login stops and asks for a one-time code sent to your phone. AwardWallet has your password, but not your phone. The sync cannot complete.
And it gets worse than a failed refresh. The login attempt itself trips the alarm: you get a verification code you did not request, and to the programme’s security system a background process getting stuck at login looks a lot like an attack — so some programmes lock the account.
The community record
This is not me extrapolating from one grumpy review. The pattern is remarkably consistent across communities.
On the FlyerTalk British Airways forum, a collector described getting “an email from BA with a 2FA verification code today suggesting that someone else was trying to log in — I checked and it was Award Wallet doing its thing.” Another, in the same thread: “AwardWallet was trying to update last night, I received 2 emails from BA telling me it was time to setup 2FA and the update failed. I think it’s the end of the line for AW and me.”
Then there are the lockouts, which are the part that actually costs people something. On Head for Points, one reader wrote plainly: “My BA account took months to get unlocked.” Another: “Because of AW, I had my account on QR blocked and I am unable to access it.” A German App Store reviewer hit the same wall with Payback, which he said “seems to have problems with two-step verification” — and off the iPhone it went.
These are not edge cases. In the review set I read, sync failure caused by 2FA was the most-cited single complaint. When roughly a quarter of the feedback on a tool is about one failure mode, that is not a rough patch. That is the shape of the thing.
Why this is structural, not a bug
Here is the part that matters if you are deciding whether to wait for a fix.
Two-factor authentication is not a fad that will pass. Across Europe, loyalty programmes are adding it, not removing it — the whole security direction of travel is toward stronger authentication, more one-time codes, more app-based approval. Every programme that switches it on is one more account a credential-based tracker can no longer reliably read, and one more it can accidentally get locked.
AwardWallet cannot engineer its way out of this without giving up the credential-scraping engine that makes automatic sync possible in the first place. No clever patch lets a stored password answer a challenge built to require a live human with a second device. This is not a knock on the team’s competence — it is an honest architectural bind, and the modern security environment is winning it.
So the trajectory is not “AwardWallet fixes 2FA.” It is more programmes adding 2FA, more failed syncs, more manual intervention, and more of the workarounds you already see people adopting — back to spreadsheets, or keeping the tool for manual entry only.
What a no-credential tracker looks like
This is the exact problem I designed Gast around, so I will be direct about the choice and its trade-off.
Gast never asks for a loyalty login. There is no password field for your airline account, because Gast does not log into your airline account. You get your balances in one of three ways: a screenshot your phone reads for you with OCR (a Gast Plus feature), a Google Sheet import if you already track your points in a spreadsheet (free), or manual entry (free). No credential is stored, no login is ever attempted, no one-time code is triggered, and no account can get locked as a result of using Gast — see how Gast imports without a login →.
It is worth being clear about what that costs you: updates are not fully automatic. You refresh a balance when you choose to, on your own device, rather than a server doing it silently overnight. That is a real trade-off, and for some people the automatic magic was the whole appeal.
But the magic is what is broken. A tracker that cannot log in cannot be locked out, cannot trigger a 2FA storm, and cannot degrade every time another programme tightens its security. The failure mode that a quarter of AwardWallet’s reviewers describe simply does not exist in a tool that never had your password. It is not that Gast handles 2FA better — there is no 2FA in the loop at all.
If you are weighing the switch
If “awardwallet not working” is what brought you here, the honest answer is that it is unlikely to start working reliably again — for reasons that have little to do with the app itself. Its automatic-sync promise is simply on a collision course with where European loyalty programmes are heading.
For a full side-by-side — coverage, price, and where the no-credential model trades convenience for reliability — see Gast vs. AwardWallet — the full comparison →.
Track your points without ever handing over a password — no login, no 2FA to break, no account to lock.
Gast is arriving soon. Get notified when it launches — no spam, one email: