Authenticator codes can protect an account after its password is exposed, but setup is not complete just because a six-digit code appears on your screen. The service must accept that code, and you need a recovery route before you close its security settings. These steps cover QR setup, manual keys, migration, troubleshooting, and recovery.
Quick answer
How do you set up 2FA codes in Krypt? On the service’s security page, choose an authenticator app. In Krypt, open Authenticator → Add TOTP → Scan QR Code on iOS or Android. Krypt saves the scanned code entry; enter its current code on the service’s page to finish enrollment. If the service gives you a bare manual key, put it in the TOTP field of that service’s password record instead. Save the service’s recovery codes and confirm its security page says the authenticator is active.
View all Krypt how-to videos. The video is a short overview; the detailed steps below describe the current controls and the order in which they save an entry.
Before you start: open the real service’s security page
Sign in to the account you want to protect and open its security, two-step verification, or multifactor authentication settings. Choose an authenticator app method. The next screen typically shows a QR code and may offer a manual key. Leave it open until the service accepts a code from Krypt.
Navigate to the service yourself instead of following an unexpected email or text link. A setup QR code contains a shared secret that can generate future codes. Treat the QR image and any manual key as credentials: do not post them in chat, save ordinary screenshots, or paste them into a third-party QR decoder. If you think a setup secret was exposed, cancel enrollment and create a new one through the service.
Have Krypt unlocked on your device. For the QR path, your phone’s camera must be able to see the code, usually displayed on another screen. SMS and email codes are different methods and cannot be imported as TOTP.
How to scan a service’s 2FA QR code
- Open Authenticator in Krypt and select Add TOTP.
- On iOS or Android, choose Scan QR Code and point the camera at the service’s authenticator setup QR code.
- When the code card appears, check its service name and account name. Those labels come from the setup data when the service supplies them.
- Enter the current code on the service’s setup page. If the countdown is nearly finished, wait for a fresh code before entering it.
- Confirm the service says the authenticator method is enabled. Collect its recovery codes before leaving the page.
Krypt imports and saves a scanned code as an authenticator entry when the scan succeeds. There is no separate Save button in this path. The service still needs the verification code to complete enrollment. Seeing a code in Krypt alone does not prove the service has enabled 2FA. You can tap the code card or its copy button to copy the current code; paste it only into the legitimate service’s verification form.
The Authenticator scanner accepts supported TOTP setup or migration QR codes. A QR code for a website login, payment, device pairing, or other purpose is not a TOTP setup code. If Krypt says the code is unsupported, return to the service’s authenticator setup step and look for its 2FA QR code or manual key.
How to enter a manual setup key
When scanning is impractical, many services show a manual key. For a bare key—usually a string of letters and digits without an otpauth:// prefix—open the service’s existing login in Krypt’s Passwords section for editing. Or create a password record with the account’s password; this editor requires a nonempty password field. Enter the correct title and account name, paste the key into the TOTP field, and save the record. Then open Authenticator, find that account, and verify its current code on the service’s page.
Krypt’s password-record TOTP field also accepts a complete otpauth://totp/... URI. By contrast, Authenticator → Add TOTP → Paste otpauth URI expects the full URI, not a bare manual key. If a service supplies only a bare key, use the password-record field. After copying a key or URI, clear the clipboard when you are done. Both forms contain the secret that generates future codes.
If you already store the account password in Krypt, adding TOTP to that record keeps the login context together. Scanning in Authenticator creates a separate code entry, so you may see both a password record and an authenticator-only record. Verify the account label to avoid picking the wrong code when you have two accounts at one service.
What makes the code change?
Time-based one-time passwords use a shared secret and the current time. The common arrangement uses six digits and a 30-second interval; setup data can specify other supported values. RFC 6238 defines the mechanism, including why clock alignment matters. Krypt’s code card shows a countdown so you can tell when the next code will appear.
The QR code or URI is therefore more sensitive than one displayed code. A single TOTP code expires quickly, but someone with the shared setup secret can generate later codes too. Protect the setup material like a password, even if it looks like a harmless QR image.
Why is the first code rejected?
Start with four checks before resetting anything:
- Account: Check the service and account label in Krypt. Two accounts at the same provider may have different secrets.
- Timing: Wait for the next code if the countdown is near zero. Submit that new code once.
- Device clock: Enable automatic date and time on the phone. TOTP depends on Krypt and the service using reasonably aligned time; RFC 6238 explains clock drift.
- Setup secret: If you typed a manual key, inspect it for missing or transposed characters. If necessary, restart enrollment on the service and import its fresh QR code or key.
Do not remove a working authenticator or disable an existing second factor while troubleshooting. Keep a working sign-in route until the service confirms the replacement. Krypt may prevent copying the same code twice in one time window; wait for the next code if it reports that the code was already used.
Save recovery codes before setup is complete
A changing TOTP code and a service’s recovery codes serve different purposes. The former is produced repeatedly from the shared secret. Recovery codes are fallback credentials issued by the service for times when the authenticator is unavailable. Google’s backup-code guidance gives one example of using them after device loss; each service’s exact rules may differ.
If the service gives you recovery codes, save them in the Recovery Codes field of its Krypt password record, one per line. The field stores them with that login in the vault. For critical accounts, a controlled physical copy may be useful too. Do not leave codes in ordinary screenshots, unencrypted notes, or an exposed downloads folder. Our guide to storing 2FA backup codes safely covers cleanup if you already captured them that way.
Know which recovery route the service will accept, and check that your contact email, trusted devices, or other enrolled methods are current. Krypt’s own Recovery Kit is separate: it helps with vault recovery, while a service’s 2FA recovery codes help you regain that service account. You may need both after losing a device.
How to move codes from another authenticator
Keep the old authenticator active while moving. Krypt’s Authenticator menu → Import Codes offers QR scanning and clipboard import of supported otpauth:// URIs. Some authenticator export QR codes contain several accounts, so inspect the imported count and each account label. Clipboard import can accept multiple URIs separated by lines or commas.
Test a fresh sign-in for each important account after importing. An imported entry does not prove the service accepts its code or that you have recovery codes. Keep the old app and its backup until those checks pass. If you are replacing a compromised authenticator, importing the old secret does not rotate it: enroll a new secret through each service instead.
The Export Codes menu can copy otpauth:// URIs to the clipboard. Those URIs carry the secrets needed to generate future codes, so use export only in a private migration workflow and clear the clipboard afterward. It does not replace the service’s recovery codes.
Krypt’s answer: codes with account context
Krypt’s Authenticator lists saved TOTP accounts and their changing codes. Its password records can also hold the account name, website, TOTP setup, notes, and recovery codes. That makes it easier to check which code belongs to which login and where its recovery path lives. As a zero-knowledge password manager, Krypt lets you keep this account context in your encrypted vault instead of spreading setup secrets and recovery codes across screenshots and loose documents.
Storing a password and its TOTP secret in one vault is a choice with a tradeoff: someone who gains access to the unlocked vault may get both. For high-value accounts, consider whether a separate authenticator, passkey, or hardware security key fits your risk better. Authenticator apps versus built-in 2FA examines that storage choice in detail.
TOTP itself is not phishing-resistant. A convincing fake site can ask for your password and the current code, then relay both immediately. NIST’s authentication guidance distinguishes manually entered OTPs from phishing-resistant methods. Use a passkey or hardware security key where the service supports one, especially for your primary email or other account that can reset many others.
FAQ
Can I paste a manual setup key into Add TOTP?
Add TOTP offers QR scanning or pasting a complete otpauth URI. For a bare manual key, open or create the service’s password record, enter it in the TOTP field, and save the record.
Does seeing a code in Krypt mean 2FA is enabled?
No. The service must accept a current code during enrollment and show the authenticator method as active. Keep its setup page open until you confirm both.
What should I do if my authenticator code is rejected?
Check that you selected the right account, wait for a fresh code, enable automatic device date and time, and verify that you imported the correct setup secret. Keep an existing sign-in method active until the new one works.
What happens if I lose the device that holds my codes?
Use the service’s recovery codes or another recovery method you enrolled there. Restore access to Krypt through your separate vault recovery plan. The service’s recovery codes and Krypt’s Recovery Kit serve different purposes.
Technical references
- IETF RFC 6238: TOTP — shared-secret and time-step specification.
- NIST SP 800-63B — authenticator and phishing-resistance guidance.
- Google Account Help: backup codes — a service-specific recovery example.
The older video describes the flow broadly. For a bare manual key, use Passwords → TOTP; scanning in Authenticator saves an entry before the service verifies it. The transcript below is preserved as spoken.
Video transcript
To set up two-factor codes, open the code section in Krypt. Scan the service QR code or paste the manual setup key. Verify the current code with the service, then save any recovery codes in a secure note for backup.