Skip to main content

Use one-time codes

Zen Passwords generates one-time codes itself, stored on the login they belong to rather than in a separate app. Once a code is on an entry, AutoFill offers the password and then the code, so signing in is two taps instead of a hunt through another app.

Zen PasswordsChecked 2026-08-26

A one-time code is the six digit number that changes every thirty seconds. Most people keep them in a dedicated authenticator app, which works, and which also means every sign in involves switching apps and typing digits from memory before they expire.

Adding a code to a login

  1. Start on the site, not in the app

    Turn on two-factor authentication where you have the account. It will show you a QR code, and usually a setup key in text form underneath if you ask for it.

  2. Add it to the entry that owns it

    Open the existing login in Zen Passwords and add the one-time code to it, rather than creating a new item. Keeping the code on the login is what lets AutoFill offer both together.

  3. Save the recovery codes somewhere

    Sites hand you a list of one-time recovery codes when you turn two-factor on. Put them in a secure note in the vault. They are what gets you into that account if you lose the device, and they are easy to close and forget.

One-time codes in Zen Passwords, counting down beside the logins they belong to.
Codes live on the entry, not in a separate list.

Is one vault for both a bad idea?

It is a fair question and the honest answer has two halves. Keeping the password and the second factor in the same vault means anybody who opens the vault has both, so the vault becomes the single thing to protect. Against that, the second factor exists mainly to defeat a stolen or reused password, and a vault that generates unique passwords has already dealt with that. The threat it does not cover either way is somebody who is already inside your unlocked device.