Guide

Password manager with a built-in authenticator

Two-factor codes protect your accounts, but switching between a password manager and a separate authenticator app at every sign-in is tedious. A built-in authenticator keeps the code next to the password, so you copy both from one place. Here is what that gives you, what it costs in security, and how SyncPass handles it.

The honest trade-off

Two-factor authentication works because the second factor is separate from the password. When both live in the same vault, they are protected by the same master password. That is still far safer than having no 2FA: a leaked or phished password alone is not enough to sign in. But someone who unlocks your vault gets both.

A practical split: keep codes in your password manager for everyday accounts, where convenience means you actually turn 2FA on. For your main email and your bank, use a separate authenticator app, a passkey or a hardware key.

What SyncPass supports

  • Time-based codes (TOTP) with SHA-1, SHA-256 or SHA-512, 6 to 8 digits and a custom period
  • Counter-based codes (HOTP)
  • Add a code by scanning its QR code: with the camera on Android; from the screen, the clipboard or an image file on Windows
  • Import every account at once from a Google Authenticator export QR code
  • Attach a code to a login, so the password and the code are in the same entry
  • Copy a code in one tap; the clipboard is marked sensitive and cleared automatically
  • Codes are generated on the device from its clock, so they work offline

The secret behind each code is encrypted in your vault like your passwords, and stays on your device unless you turn on sync through your own Google Drive.

Moving from Google Authenticator

  1. 1In Google Authenticator, open the menu and choose Transfer accounts, then Export accounts. Select the accounts and it shows a QR code.
  2. 2In SyncPass, add a new 2FA code and choose to scan a QR code. Scan the export code; every account in it is added.
  3. 3Sign in to one or two of the services with a code from SyncPass to confirm it works before you delete anything from the old app.

Frequently asked questions

Is it safe to keep 2FA codes in a password manager?+

It is a trade-off. Codes in the same vault are protected by the same master password and encryption as your passwords, which is much better than no 2FA at all. But if someone gets into your vault, they get both factors. For your most important accounts (main email, bank), a separate authenticator app, a passkey or a hardware key keeps the second factor truly separate.

Can I import my codes from Google Authenticator?+

Yes. Export your accounts as a QR code in Google Authenticator (Transfer accounts, then Export accounts) and scan it in SyncPass. All accounts in the QR code are imported.

Do the codes work without internet?+

Yes. Time-based codes are calculated on the device from the shared secret and the current time. Only the device clock needs to be correct.

Does SyncPass support push approvals or Steam Guard?+

No. SyncPass generates standard TOTP and HOTP codes, which is what most websites use. Push sign-in prompts (like Microsoft Authenticator approvals) and Steam Guard use their own systems and are not supported.

Is the authenticator free?+

No. 2FA codes are part of Premium on Android and Windows, together with unlimited items, Drive backup and sync, and breach checks. The free version stores up to 15 items, with no ads and no account.

Related: offline password manager for Android and Windows · SyncPass features and pricing