We're on Product Hunt today! Leave a comment

Add to Chrome

Authenticator app for your 1Password account

1Password’s own two-factor authentication works with any authenticator app — except 1Password itself, which is why a separate one in your browser fits. On 1Password.com open your name → Manage Account → More Actions → Manage Two-Factor Authentication, select “Set Up App”, and scan the QR code from the screen with the Authenticator extension.

Your 1Password account opens every other password you have, so it deserves a second lock more than any of them. Your account password and Secret Key already guard it; with two-factor authentication on, a new device also needs the six-digit code before it can sign in. 1Password itself says that code must not live inside 1Password — that would be the key to the safe kept inside the safe.

Turn on two-factor authentication on 1Password.com

Two-factor authentication is set up on 1Password.com in the browser, not in the 1Password apps, and needs a 1Password membership. On 1Password Business an owner or administrator can require it for everyone under Policies → Authentication policy → “Enforce two-factor authentication”. If your organization uses Duo, you will not see the option at all — Duo already does this job.

  1. Sign in to your account on 1Password.com in your browser.
  2. Select your name in the top right, then select “Manage Account”.
  3. Select “More Actions” → “Manage Two-Factor Authentication”.
  4. Select “Set Up App”. 1Password shows a QR code with a 16-character secret next to it — write the secret down before you go on.
  5. Leave the QR code on the screen and add it to the extension as described below — then select “Next”, enter the six-digit code and select “Confirm”.
1Password’s own instructions

Add 1Password to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the 1Password page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to 1Password and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. 1Password confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on 1Password’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Write down the 16-character secret

1Password has no backup codes for two-factor authentication. Its backup is the 16-character secret shown next to the QR code: write it down and keep it somewhere safe, away from this computer — 1Password suggests with your passport and Emergency Kit. Typed into any authenticator, it brings the codes back. A 1Password recovery code does not help here: after a recovery, two-factor authentication stays on.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Which authenticator app should I use for my 1Password account?
Any app that produces standard six-digit codes, except 1Password itself. 1Password names Authy, Microsoft Authenticator and Okta Verify as examples. The Authenticator extension works too, needs no phone, and keeps the code apart from your vault — which is the point.
Will 1Password ask for a code every time I unlock it?
No. Once a device has accepted a code, 1Password asks again only if you sign out on it, change your email address or account password, regenerate your Secret Key, have your account recovered, or someone chooses “Require 2FA on Next Sign-in” for that device.
What if I lose access to my authenticator?
Add the 16-character secret you wrote down to an authenticator again. Or, on a device or browser that is still signed in, turn two-factor authentication off and set it up anew — on 1Password.com you confirm that with your account password. With neither, ask your family organizer or team administrator to recover your account; that resets two-factor authentication.
Why does 1Password say my code is wrong?
Usually the computer clock is off by a minute or more — 1Password’s own help says to check the date and time first. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension and set two-factor authentication up again.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free