Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.
Last reviewed: 2026-08-17 · Report a change
Short answer
What to know before you start
1Password can store a service's time-based one-time password secret with its login item, generate the rotating code, and fill it after the password. Add the QR code only from the service's verified security settings. The workflow is convenient, but both factors then depend on access to the 1Password account, so protect and recover that account carefully.
01 · decision point
Know what 1Password is storing
When a service offers authenticator-app 2FA, its setup QR code encodes a shared secret. 1Password can save that secret in the matching login item and calculate the same time-based codes that a standalone authenticator would. The service still controls whether TOTP is supported and how recovery works. 1Password is not turning an unsupported account into a 2FA account; it is acting as the authenticator selected in that service's official security settings.
Treat the QR code and manual setup key as authentication secrets. Open the service from a trusted bookmark, verify the domain, and begin setup there. Use 1Password's documented scanner or field workflow instead of photographing the QR image or sending it between devices through chat. Label the login item and website precisely so a future user can tell which account the rotating code belongs to.
02 · decision point
Set up and test the one-time password
Keep the service's security page and existing authenticator available during setup. Add the one-time password field to the correct 1Password item, then enter a generated code on the service to confirm enrollment. Save any service-issued recovery codes separately. Sign out in a private browser and perform one complete test: verify the domain, fill the login, and confirm the changing code is accepted. Do not remove the old method until the test and backup route both work.
If a code is rejected, confirm that the entry belongs to the same account and that device time is automatic. A duplicate item can hold an obsolete secret after 2FA is reset. Do not repeatedly submit codes to an unfamiliar page. Return to the service's known settings from a trusted session, check which factor is registered, and replace the TOTP secret only through the official recovery or re-enrollment process.
03 · decision point
Evaluate the combined-vault trade-off
Storing the password and TOTP secret together improves usability: the code can be available across approved devices, backups follow the vault's model, and people are less tempted to fall back to SMS. The trade-off is concentration. Someone who fully compromises an unlocked 1Password account may obtain both the password and the rotating-code secret for stored logins. That differs from keeping codes on an independent hardware token or separate authenticator.
The right choice depends on the threat and the recovery burden. For many accounts, reliable TOTP in a strongly protected password manager is a meaningful improvement over no second factor. For the password manager itself, primary email, domain registrar, or privileged administrator account, consider a phishing-resistant passkey or separate security key. Do not keep the only way to recover 1Password inside the same vault without an independent copy.
04 · decision point
Protect the 1Password account itself
The 1Password account can become a high-impact control plane because it holds credentials for many services. Use the provider's current sign-in and recovery protections, safeguard the Secret Key and Emergency Kit according to its documentation, review authorized devices, and protect the email account used for notices. Family and business accounts can have organizer or administrator recovery features, but those roles and their limitations should be understood before an incident.
A passkey or security key used for sensitive accounts can reduce dependence on copyable codes. Review 1Password's own passkey documentation separately from its TOTP feature. A service can allow 1Password to save a passkey, generate a one-time password, store a recovery code, or all three; those artifacts have different security and recovery behavior. Name them clearly and remove obsolete factors after each account change.
05 · decision point
Move codes without silently losing access
Before migrating from another authenticator, inventory the services involved and keep the original device. Some services let you display a new QR code only after disabling and re-enabling TOTP; that action usually invalidates the old secret. Complete accounts one at a time. Save fresh recovery codes, test the 1Password-generated code in a separate session, and record completion before moving to the next service.
Do not use screenshots as a migration archive. An image of the QR code can let anyone generate future codes, and it may remain in cloud photo backups long after setup. If the old phone is lost before migration, use each service's official backup factor or recovery flow. 1Password cannot derive a TOTP secret that was never stored in the vault, and login.com cannot receive or convert authentication secrets.
Practical sequence
Use this checklist before changing the account
- 01
Begin TOTP setup on the service's verified security page.
- 02
Save the QR secret only in the correct 1Password login item.
- 03
Confirm the code and store service recovery codes independently.
- 04
Test one complete sign-in before removing the prior authenticator.
- 05
Use stronger separation for the vault, email, and administrator accounts.
- 06
Migrate services one at a time and destroy unsafe QR screenshots.
Side-by-side comparison
Compare the relevant trade-offs
| Storage model | Convenience | Separation | Best fit |
|---|---|---|---|
| TOTP in login item | High; password and code can fill | Both depend on vault access | Routine accounts needing reliable 2FA |
| Separate authenticator | Requires another app or device | Different app boundary | Users who can maintain two systems |
| Hardware security key | Physical key required | Phishing-resistant hardware boundary | High-impact or administrator accounts |
| Service recovery code | Emergency use only | Depends on storage location | Lockout backup, not daily sign-in |
Common questions
Using 1Password as an authenticator safely FAQ
Does 1Password become the second factor?
It stores the TOTP shared secret and generates the service's rotating code. The service remains responsible for 2FA policy and recovery.
Is storing passwords and codes together still 2FA?
The service sees two proofs, but compromise of the unlocked vault can expose both. Decide whether the usability gain fits the account's risk.
Can I copy an authenticator entry with a screenshot?
Do not use QR screenshots as backups. Re-enroll from the verified service and store recovery material through a protected, intentional process.
Continue on login.com
Related independent guidance
Primary-source ledger
Official documentation reviewed
Product features, plan packaging, and interfaces can change. The claims above are limited to the official documentation linked here and the review date shown on this page. Recheck the live provider material before changing a high-impact account or buying a subscription.
- 1Password: Use 1Password as an authenticator ↗Checked 2026-08-17
- 1Password: Passkey security ↗Checked 2026-08-17