Two-factor codes
The second factor lives where the first one does.
-
Turn on two-factor sign-in at the service
GitHub, Google, your bank - any service that shows a QR code for an authenticator app.
-
Scan the QR code in Secret Keeper
A “One-time code” record appears in the Vault next to the password for that service. An otpauth:// link can also be pasted by hand.
-
Copy the code with a tap
Six digits and a timer ring: a code lives 30 seconds, the next one is already waiting.
Good to know
- Time-based codes (TOTP) are supported - the standard used by Google Authenticator and the like. Counter-based codes (HOTP) are not.
- The code secret lives in the Vault and is restored from the 12 words: losing the phone does not cut you off from your accounts.
- The QR code with the secret can be shown to another authenticator - only your own.