Many sites ask for a six-digit code after your password. Vallkey can make those codes, so you don’t need a separate authenticator app.
Add a code to a login
- On the website, turn on two-step verification, and choose the authenticator app option.
- The site shows a QR code. Choose its option to see the setup key instead, often called “Can’t scan?” or “Enter key manually”.
- In Vallkey, edit the login, and paste the key into One-time password. A full
otpauth://link works too. - Save. The item now shows the current code, with the seconds left.
- Type that code into the website to finish.
Fill a code
On a page that asks for the code, click the code field and pick the login. Vallkey fills the code as it is at that moment.
Which codes are supported
Time-based codes (TOTP), of 6 to 8 digits. That’s what almost every site uses. Counter-based codes (HOTP) aren’t supported.
Bringing codes from another app
Importing from 1Password, Bitwarden, Keeper, KeePass and Credential Exchange files brings each login’s codes along.
Is it safe to keep the code beside the password?
It’s a trade. The code still protects you if the site’s password database leaks, or if someone learns your password. It no longer protects you if your vault itself is opened. For most accounts the convenience is worth it. For the few that matter most, a passkey or a hardware security key is stronger than any code.
Last updated October 3, 2026