- Passcode or biometric locks on an app are a gimmick and offer negligible value.
- The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface.
- In particular, Authy, LastPass and 1password have a giant attack surface compared to a simple app like Google Authenticator. They also rely on centralized services and if you also keep your passwords in there, you eliminate the whole point of two factor authentication.
- One important risk with authentication apps is compromised updates, and Google Authenticator has a very low risk of this since it's backed by Google's strict security processes.
What you should actually do is to move to U2F/WebAuthn and pester any of your service providers that do not offer it. Yes, if you need to replace a token, you'll have to go through all accounts and change it. There's is absolutely no way to prevent this without compromising on security.