OTP Authenticator
LockYit includes a built-in authenticator for storing and generating one-time passwords (OTP).
What is OTP?
OTP (One-Time Password) codes are temporary 6-digit codes used for two-factor authentication (2FA). Instead of using a separate authenticator app, you can store and generate these codes directly in LockYit.
Adding an OTP Entry
Method 1: Scan QR Code
- Go to OTP screen
- Click or tap + Add OTP
- Click or tap Scan to ensure that you are on the QR code scanning screen
- Click or tap on the camera_alt Start Scanning button
- Point your camera at the QR code provided by the service
- The entry is automatically created
Method 2: Manual Entry
If you can't scan a QR code:
- Click or tap + Add OTP
- Select Manual
- Enter the details:
- Title: Service name (e.g., "Google")
- Account: Your account email/username
- Secret Key: The alphanumeric key provided by the service
- Click or tap Save
Viewing OTP Codes
- Open the OTP section
- See all your authenticator entries
- Each entry shows:
- Service name and account
- A visibility toggle icon to hide/show the OTP code
- On making the OTP code visible, you will see
- Current 6-digit code
- Countdown timer until next code
- A copy icon to copy the OTP code to the clipboard
- A hide icon to hide the OTP code
Using OTP Codes
When a service asks for your authenticator code do the following.
- Open LockYit → OTP
- Find the service
- Read the current code. Refer to viewing OTP codes on how to see the code.
- Enter it on the website/app before the timer expires
Click or tap the code to copy it to your clipboard instantly. Then paste it into the service's login screen.
Code Refresh
OTP codes change every 30 seconds. The countdown timer shows how long you have in seconds until the next code comes up.
If the code changes before you enter it, just use the new one.
Security
Your OTP secrets are stored with the same encryption as all other vault items:
- AES-256-GCM encryption
- Local storage only
- Protected by your master password
Backing up OTP Codes
LockYit includes your OTP secret keys in your vault backups, and the CSV export file.
- CSV Export: Your OTP secrets are exported in the
otp_uricolumn. You can re-import them via CSV Import. - Security Warning: Since CSV exports are unencrypted, your OTP seeds will be visible in the file. Keep the export file secure.
Migrating from Other Apps
Moving from Google Authenticator, Authy, or another app?
- Go to the old app's settings
- Look for "Export" or "Transfer codes"
- Scan the QR codes with LockYit one by one
When removing entries from your old authenticator, make sure they're working in LockYit first!
You can also choose to retain the codes in the old authenticator for a while, to be sure that you have it working in LockYit correctly.
Troubleshooting
Code Not Working?
- Check the time - Your device clock must be accurate
- Check the account - Make sure you're using the right entry
- Wait for refresh - Try the next code if this one is about to expire
Time Sync Issues
OTP codes are time-based. If your device clock is off by more than 30 seconds, codes won't work.
- Go to your device Settings
- Find Date & Time
- Enable the option to set the time automatically