A password alone is a single point of failure. If it leaks in a breach, gets phished, or someone guesses it, that's the whole lock picked. Two-factor authentication, usually shortened to 2FA, adds a second lock: a short code that changes every 30 seconds and lives only on your phone. Even if someone has your password, they can't get in without that code.

An authenticator app is what generates those codes. It's better than getting them by text message, and once it's set up you barely think about it. Let's walk through the whole thing.

What you'll need

An account that supports 2FA (most banks, email providers, social networks and crypto exchanges do), and an authenticator on your phone. OneVault has one built in, right alongside your passwords, so you don't need a separate app like Google Authenticator or Authy.

Why an authenticator app beats SMS codes

Plenty of sites still offer to text you a code. It's better than nothing, but it's the weakest form of 2FA, and here's why:

  • SIM swapping. An attacker who convinces your carrier to move your number to their SIM starts receiving your texts, codes included. It happens more than you'd think.
  • Texts can be intercepted. The network that carries SMS was never built to be secure, and codes can be read in transit.
  • No signal, no code. On a plane, abroad, or in a dead zone, a texted code never arrives. An authenticator app works completely offline.

An authenticator generates the code on your device using a shared secret and the current time. Nothing is sent over the network, so there's nothing to intercept and no number to hijack.

Step 1: Turn on 2FA for the account

Start on the service you want to protect, not in the authenticator. The setting is almost always under account security.

1

Find the security settings

Log in to the website or app and look for Settings › Security, then an option called Two-Factor Authentication, 2-Step Verification or Authenticator app. Choose the authenticator-app option rather than SMS.

2

Reveal the QR code

The site will show a QR code, and usually a short text key underneath it in case you can't scan. Keep that screen open, you're about to point OneVault at it.

Step 2: Add the account in OneVault

Now open OneVault and unlock your vault. Tap the 2FA tab at the bottom, then the + button to add an account. You have two ways to do it.

  1. Scan QR is the quick path. Point your camera at the QR code on the other screen and OneVault reads the secret automatically.
  2. Manual is the fallback. Type a name for the account and paste the text key the site showed you. Handy when the QR code is on the same phone you're setting things up on.
OneVault Add 2FA Account screen with Scan QR and Manual tabs, showing Service Name, Account and Secret Key fields
Adding an account in OneVault: scan the QR code, or switch to Manual and paste the setup key.

Once it's added, OneVault starts generating a six-digit code that refreshes on a timer. That's your authenticator working.

Step 3: Confirm the code and save your backups

Almost done. Two small things separate a setup that works from one that locks you out later.

3

Enter the current code to verify

Back on the website, it will ask you to type the code OneVault is showing. This proves the two are in sync. Enter it before the timer runs out and the site confirms 2FA is on.

4

Save the recovery codes

Most services hand you a set of one-time backup codes at this point. Save them somewhere safe. A secure note in OneVault is a good home, since it's encrypted and always with you.

Don't skip the recovery codes

Recovery codes are your way back in if you ever lose access to your authenticator. Save them the moment they're offered. If you close that screen without copying them, some services won't show them again.

Why keep 2FA codes with your passwords

There's an old habit of putting passwords in one app and 2FA codes in another, on the theory that splitting them is safer. In practice, for most people, it mainly makes logging in a chore, and a chore is the thing you eventually stop doing.

OneVault keeps both in one encrypted vault on your device. When you go to sign in, your password and your live code are a tap apart, which means you're far more likely to keep 2FA turned on everywhere. The vault is encrypted with AES-256 and only opens with your master password or biometric, so "together" doesn't mean "exposed."

OneVault authenticator tab listing live 2FA codes for Amazon, Coinbase, Facebook and GitHub with countdown timers
Your codes refresh on a timer, right beside the logins they protect.

It also works with no internet connection, which matters more than people expect. Codes are generated from the time and a stored secret, so they keep ticking on a flight or in another country. If a local-first setup appeals to you, our piece on offline password managers for Android goes deeper.

A few common questions

Is it safe to keep passwords and 2FA in the same app?

Yes, as long as the app is a real zero-knowledge vault. OneVault encrypts everything on your device and never uploads a readable copy, so the risk isn't "one app holds both," it's whether anyone else can open that app. With a strong master password and biometric lock, they can't.

What happens if I lose my phone?

This is exactly what the recovery codes are for, so save them. On top of that, OneVault can back up an encrypted copy of your vault to your own Google Drive or a WebDAV server, so you can restore your codes on a new phone with your master password.

Does the authenticator work offline?

Completely. Codes are calculated from your stored secret and the current time, with no server involved. Airplane mode has no effect on it.

Can I move my codes from Google Authenticator?

You can re-add each account by turning 2FA off and on again at the source and scanning the fresh QR code, or by exporting from your old app and importing the tokens. OneVault reads standard otpauth:// secrets, so nothing about your accounts is proprietary.

Passwords and 2FA, one private vault

Set up your logins and your two-factor codes in the same encrypted app, on your phone, with no account and no subscription. Start free.

Get OneVault free on Google Play →

New to OneVault and bringing logins over from somewhere else? Start with our guide on how to import your passwords, and if you're still weighing options, see the 2026 password manager comparison. If you've been relying on your browser to remember logins, here's why that's a risk worth fixing.