Your smartwatch is designed to surface what matters now—messages, alerts, and calendar updates at a glance. But “at a glance” is exactly why one-time passwords (OTPs) and verification codes don’t belong there. If a 6‑digit code appears on your wrist during sign‑in, anyone nearby could see it, or a thief who steals your watch could access recent notifications. This guide shows you how to stop security codes from reaching wearables, while keeping the helpful alerts you actually want.
Why security codes on wearables are risky
Verification codes are short-lived, high-impact secrets. Showing them on a small screen that’s easy to glance at, mirror to other devices, or leave unlocked creates unnecessary risk. Specific problems include:
- Shoulder surfing: People near you can read a 6‑digit code in a split second.
- Lost or stolen device: Recent notifications can expose codes and reset links.
- Accidental mirroring: Multiple devices signed into the same account may display the same code.
- Phishing plus speed: Attackers who trick you into sharing a code gain from instant visibility on your wrist.
The fix is simple: prevent codes from appearing on the wearable in the first place and reduce what shows on lock screens.
Core strategy: keep codes off the wrist, keep previews off lock screens
There are two main controls that reduce exposure across nearly every platform:
- Turn off message previews on watches and phone lock screens so codes are never readable at a glance.
- Stop forwarding or mirroring of messages and email accounts that deliver codes.
Below are practical, step‑by‑step settings for Apple Watch, Wear OS (Samsung, Google Pixel Watch, etc.), Fitbit, and Garmin, plus app‑by‑app redaction and filtering options.
Apple Watch (watchOS) and iPhone
Option A: Block message previews on Apple Watch
- On iPhone, open Watch app > Notifications.
- Under Messages:
- Set Show Alerts on if you still want to know you received a message.
- Tap Custom > turn Show Alerts on but disable Show Previews.
- Repeat for Mail and any apps that can deliver OTPs (e.g., banking apps). Disable Show Previews or set to Never.
Result: You’ll get a subtle alert but no readable code on the watch face.
Option B: Stop messages and mail from mirroring to the watch
- In the iPhone Watch app > Notifications, scroll to Mirror iPhone Alerts From.
- Turn off Messages, Mail, and any finance/authentication apps that might show codes.
Result: OTPs won’t reach the watch at all.
Harden iPhone lock‑screen previews (affects watch behavior)
- On iPhone, go to Settings > Notifications > Show Previews > choose When Unlocked or Never.
- In Settings > Messages > Notifications: set Show Previews to Never or When Unlocked.
- Do the same in Settings > Mail > Notifications for each account that receives OTPs.
Result: Even if a code alert appears, it won’t reveal digits on a locked phone or mirrored watch alert.
Extra: Filter and silence likely OTPs on iPhone
- Silence Unknown Callers: Settings > Phone > Silence Unknown Callers (helps reduce vishing attempts).
- Filter Unknown Senders: Settings > Messages > Filter Unknown Senders. OTPs from short codes will still arrive but are separated and won’t notify if you turn off notifications for filtered senders.
Wear OS (Google Pixel Watch, Samsung Galaxy Watch, and others)
Option A: Turn off previews or content on the watch
- On the watch: open Settings > Apps & notifications (or Notifications).
- Look for Notifications > Device lock or On lock screen and set Hide content or Don’t show notifications at all.
- In Notifications, review App notifications and disable Messages, Gmail, banking apps, and any app that may show OTPs.
Option B: Control from the paired Android phone
- Open the Watch companion app (e.g., Galaxy Wearable or Google Pixel Watch).
- Go to Notifications and toggle off Messages, Gmail, and financial apps that display codes.
- In the Android phone’s Settings > Notifications:
- Tap Lock screen notifications (varies by brand) and select Hide sensitive content or Don’t show notifications on lock screen.
- For each app (Messages, Gmail, Outlook, banking), open its notification settings and disable Preview/Show content or set to Silent.
Extra: Redact OTPs in Gmail on Android
- Open Gmail > Settings > your account > Notifications.
- Choose High priority only and disable Email previews in system settings to avoid code visibility.
Fitbit
Fitbit devices mirror phone notifications. The safest route is to prevent OTP‑carrying apps from mirroring.
- Open the Fitbit app on your phone > tap your profile > select your device > Notifications.
- Turn off Text Messages and Email. If you want alerts but not content, disable previews on the phone’s lock screen as described above (iPhone or Android).
Garmin
Garmin uses mirrored smartphone notifications via Garmin Connect.
- Open Garmin Connect > Device Settings > Notifications.
- Turn off Text Messages, Email, and any app that may display OTPs.
- On the phone, hide notification content on the lock screen and for specific apps to ensure redaction carries through.
App‑level fixes that work across platforms
Messages (SMS)
- iPhone: Settings > Notifications > Messages > Show Previews > When Unlocked or Never.
- Android: Settings > Apps & notifications > Messages > Notifications > disable Preview/Show content, set to Silent, and hide on lock screen.
Gmail and Outlook
- Hide previews in system notification settings so subject and snippet are not shown.
- Limit alerts to high‑priority senders so automated OTP emails don’t ping your wrist.
Banking and payment apps
- Disable notification content previews or turn off notifications entirely to the watch.
- Prefer in‑app approvals or push prompts that require unlocking your phone instead of SMS codes.
Safer authentication options that avoid SMS
Blocking previews is important, but the best protection is to use methods that don’t leak sensitive codes to multiple devices:
- App‑based authenticators: Use an authenticator app (e.g., built‑in app prompts from your bank or a standard TOTP app) that requires unlocking your phone to view a code.
- Push approvals with device unlock: Many services send a push prompt that you approve only after unlocking your phone, reducing shoulder‑surfing risk.
- Security keys (FIDO2/WebAuthn): Physical keys or built‑in device passkeys can remove OTPs altogether and are resistant to phishing.
Where available, switch away from SMS and email codes to one of the methods above. Keep SMS as a recovery fallback only.
Set up redaction and delivery “fences” for OTPs
Combine these moves to keep codes visible only when you’re ready to use them:
- Redact everywhere by default: Set phone and watch to hide notification content until unlocked.
- Limit which apps alert your wrist: Stop mirroring messages and mail to the watch. Allow calendars, reminders, and health alerts only.
- Consolidate OTP delivery: Choose one secure inbox (e.g., authenticator app or a single email account) and make sure it does not mirror to any wearables.
- Use per‑app notification categories: On Android, turn off the “Security code/OTP” channel or set it to Silent and Hidden on the lock screen if available.
- Review watch history settings: Clear notification history on watches that store recent alerts, and enable watch passcode/lock if you keep any notifications.
What about lost or stolen wearables?
If your watch goes missing, assume any recent notifications could be exposed. Take these steps immediately:
- Remotely lock or erase: Use Find My (Apple) or Find My Device (Android) to lock, locate, or erase paired devices where applicable.
- Revoke sessions: Log into critical accounts (email, bank) and sign out of other devices, then change passwords.
- Rotate 2FA methods: If SMS/email was used, switch to app‑based or security keys and update recovery options.
Practical defaults to copy and paste
If you want fast, safe defaults that keep usability high:
- On your phone: Show previews only when unlocked. Hide lock‑screen content for Messages, Mail, Gmail, and banking apps.
- On your watch: Turn off mirroring for Messages and Mail; keep previews off for any finance/auth apps.
- For authentication: Use an authenticator app or security keys; keep SMS as emergency backup only.
How this protects your identity
Most account takeovers start with either a password compromise or a real‑time code interception. Preventing verification codes from appearing on glanceable surfaces blocks quick theft, reduces phishing success, and buys you time to recognize and stop fraudulent sign‑in attempts. Combined with strong, unique passwords and safer 2FA, you dramatically lower the chance of unauthorized account access.
Monitor for identity misuse
Even with solid notification hygiene, it’s smart to watch for signs of misuse tied to your financial identity. If an attacker gets in elsewhere, you want early warning. Consider a service that tracks credit changes, new account openings, and identity‑related alerts so you can respond quickly. For a practical overview of a toolset that combines privacy, credit monitoring, and identity‑protection features, see our SmartCredit resource.
Checklist: five‑minute setup
- Phone: Set notification previews to “When Unlocked” (or Never).
- Watch: Turn off mirroring for Messages, Mail, and banking/auth apps.
- Per‑app: Disable previews for SMS, email, and finance apps.
- Auth: Switch important accounts from SMS/email codes to app prompts or security keys.
- Recovery: Update backup codes and recovery email; store securely.
Conclusion
Smartwatches are great for quick glances, not for displaying secrets. By hiding previews, stopping message mirroring, and migrating to safer authentication methods, you prevent verification codes from leaking to your wrist without sacrificing useful alerts. Take a few minutes to apply the settings above on your phone and wearable—then review your authentication methods so sensitive codes stay private, and your accounts stay under your control.
Good to Know
SMS and email codes that show in smartwatch previews can be read by anyone who glances at your wrist. Turning off message previews or filtering one-time passcodes is the fastest fix—do it once on your phone and most wearables follow.