Two-factor codes

The second factor lives where the first one does.

  1. Turn on two-factor sign-in at the service

    GitHub, Google, your bank - any service that shows a QR code for an authenticator app.

  2. Scan the QR code in Secret Keeper

    A “One-time code” record appears in the Vault next to the password for that service. An otpauth:// link can also be pasted by hand.

  3. Copy the code with a tap

    Six digits and a timer ring: a code lives 30 seconds, the next one is already waiting.

Good to know

  • Time-based codes (TOTP) are supported - the standard used by Google Authenticator and the like. Counter-based codes (HOTP) are not.
  • The code secret lives in the Vault and is restored from the 12 words: losing the phone does not cut you off from your accounts.
  • The QR code with the secret can be shown to another authenticator - only your own.

Download