Integrated one-time passwords

Using 1Password as an authenticator safely

1Password can store a service's time-based one-time password secret with its login item, generate the rotating code, and fill it after the password. Add the QR code only from the service's verified security settings. The workflow is convenient, but both factors then depend on access to the 1Password account, so protect and recover that account carefully.

Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.

Last reviewed: 2026-08-17 · Report a change

Short answer

What to know before you start

1Password can store a service's time-based one-time password secret with its login item, generate the rotating code, and fill it after the password. Add the QR code only from the service's verified security settings. The workflow is convenient, but both factors then depend on access to the 1Password account, so protect and recover that account carefully.

01 · decision point

Know what 1Password is storing

When a service offers authenticator-app 2FA, its setup QR code encodes a shared secret. 1Password can save that secret in the matching login item and calculate the same time-based codes that a standalone authenticator would. The service still controls whether TOTP is supported and how recovery works. 1Password is not turning an unsupported account into a 2FA account; it is acting as the authenticator selected in that service's official security settings.

Treat the QR code and manual setup key as authentication secrets. Open the service from a trusted bookmark, verify the domain, and begin setup there. Use 1Password's documented scanner or field workflow instead of photographing the QR image or sending it between devices through chat. Label the login item and website precisely so a future user can tell which account the rotating code belongs to.

02 · decision point

Set up and test the one-time password

Keep the service's security page and existing authenticator available during setup. Add the one-time password field to the correct 1Password item, then enter a generated code on the service to confirm enrollment. Save any service-issued recovery codes separately. Sign out in a private browser and perform one complete test: verify the domain, fill the login, and confirm the changing code is accepted. Do not remove the old method until the test and backup route both work.

If a code is rejected, confirm that the entry belongs to the same account and that device time is automatic. A duplicate item can hold an obsolete secret after 2FA is reset. Do not repeatedly submit codes to an unfamiliar page. Return to the service's known settings from a trusted session, check which factor is registered, and replace the TOTP secret only through the official recovery or re-enrollment process.

03 · decision point

Evaluate the combined-vault trade-off

Storing the password and TOTP secret together improves usability: the code can be available across approved devices, backups follow the vault's model, and people are less tempted to fall back to SMS. The trade-off is concentration. Someone who fully compromises an unlocked 1Password account may obtain both the password and the rotating-code secret for stored logins. That differs from keeping codes on an independent hardware token or separate authenticator.

The right choice depends on the threat and the recovery burden. For many accounts, reliable TOTP in a strongly protected password manager is a meaningful improvement over no second factor. For the password manager itself, primary email, domain registrar, or privileged administrator account, consider a phishing-resistant passkey or separate security key. Do not keep the only way to recover 1Password inside the same vault without an independent copy.

04 · decision point

Protect the 1Password account itself

The 1Password account can become a high-impact control plane because it holds credentials for many services. Use the provider's current sign-in and recovery protections, safeguard the Secret Key and Emergency Kit according to its documentation, review authorized devices, and protect the email account used for notices. Family and business accounts can have organizer or administrator recovery features, but those roles and their limitations should be understood before an incident.

A passkey or security key used for sensitive accounts can reduce dependence on copyable codes. Review 1Password's own passkey documentation separately from its TOTP feature. A service can allow 1Password to save a passkey, generate a one-time password, store a recovery code, or all three; those artifacts have different security and recovery behavior. Name them clearly and remove obsolete factors after each account change.

05 · decision point

Move codes without silently losing access

Before migrating from another authenticator, inventory the services involved and keep the original device. Some services let you display a new QR code only after disabling and re-enabling TOTP; that action usually invalidates the old secret. Complete accounts one at a time. Save fresh recovery codes, test the 1Password-generated code in a separate session, and record completion before moving to the next service.

Do not use screenshots as a migration archive. An image of the QR code can let anyone generate future codes, and it may remain in cloud photo backups long after setup. If the old phone is lost before migration, use each service's official backup factor or recovery flow. 1Password cannot derive a TOTP secret that was never stored in the vault, and login.com cannot receive or convert authentication secrets.

Practical sequence

Use this checklist before changing the account

  1. 01

    Begin TOTP setup on the service's verified security page.

  2. 02

    Save the QR secret only in the correct 1Password login item.

  3. 03

    Confirm the code and store service recovery codes independently.

  4. 04

    Test one complete sign-in before removing the prior authenticator.

  5. 05

    Use stronger separation for the vault, email, and administrator accounts.

  6. 06

    Migrate services one at a time and destroy unsafe QR screenshots.

Side-by-side comparison

Compare the relevant trade-offs

Storage modelConvenienceSeparationBest fit
TOTP in login itemHigh; password and code can fillBoth depend on vault accessRoutine accounts needing reliable 2FA
Separate authenticatorRequires another app or deviceDifferent app boundaryUsers who can maintain two systems
Hardware security keyPhysical key requiredPhishing-resistant hardware boundaryHigh-impact or administrator accounts
Service recovery codeEmergency use onlyDepends on storage locationLockout backup, not daily sign-in

Common questions

Using 1Password as an authenticator safely FAQ

Does 1Password become the second factor?

It stores the TOTP shared secret and generates the service's rotating code. The service remains responsible for 2FA policy and recovery.

Is storing passwords and codes together still 2FA?

The service sees two proofs, but compromise of the unlocked vault can expose both. Decide whether the usability gain fits the account's risk.

Can I copy an authenticator entry with a screenshot?

Do not use QR screenshots as backups. Re-enroll from the verified service and store recovery material through a protected, intentional process.

Continue on login.com

Related independent guidance

Primary-source ledger

Official documentation reviewed

Product features, plan packaging, and interfaces can change. The claims above are limited to the official documentation linked here and the review date shown on this page. Recheck the live provider material before changing a high-impact account or buying a subscription.

  1. 1Password: Use 1Password as an authenticator ↗Checked 2026-08-17
  2. 1Password: Passkey security ↗Checked 2026-08-17