Saved logins and 2FA codes
Keep a profile's usernames and passwords on the profile, and get its 6-digit 2FA code from the app instead of your phone.
On this page
A profile can carry the logins it uses and the 2FA secret for its account. Two things come out of that: you can copy a current 6-digit code from LoginDeck without reaching for your phone, and a Flow can type the username, password and code in for you.
π Save a login on a profile#
- Open the profile's editor (row β― β Edit).
- On the Overview tab, scroll to Linked accounts and click + Add account.
- Fill the row in:
- platform (accounts.google.com): the site's address. The box suggests common ones. Use the real address, not a nickname β it's what keeps the password from being typed anywhere else.
- email or username
- password
- 2FA key (optional): this account's own 2FA secret.
- note (optional)
- Click Save changes.
Add a row per account with + Add account, up to 50 per profile. The β button removes a row.
π’ Add the profile's 2FA secret#
Use 2FA secret (TOTP) on the Overview tab when one account is the profile's main one.
- On the site, set up an authenticator app and choose "Can't scan the QR code?" to see the key.
- Paste the key into 2FA secret (TOTP). A full
otpauth://link works too. - A live 6-digit code appears beside the box with a countdown. Check it matches what the site expects, then click Save changes.
Copy the code without opening the editor
On the profile's row, click β― β Copy 2FA code. You'll see "2FA code 481920 β copied, 18s left". The item only shows on profiles that have a secret.
You can also click the code in the editor to copy it ("Code copied").
If the secret isn't accepted#
The box under the field says what's wrong, and the profile won't save until it's fixed:
| Message | What to do |
|---|---|
"1" is not a base32 character β check the secret for typos | Retype the key. Base32 keys use AβZ and 2β7, and spaces don't matter. |
| "the secret is too short" | You've pasted part of the key. Copy it again. |
| "that is an HOTP (counter) link β only time-based TOTP is supported" | The site is using counter-based codes, which LoginDeck can't produce. Keep using your authenticator app. |
| "algorithm SHA3 is not supported (SHA1, SHA256, SHA512 are)" | Same: use your app for this account. |
| "that otpauth:// link has no secret in it" | Copy the whole link, or paste just the key. |
| "digits must be 6, 7 or 8" / "that period is not usable" | The link asks for something unusual. Use your app. |
π€ How Flows use them#
In a Flow's type step, these stand in for the saved values:
| Token | Value |
|---|---|
${account.email} | The first account's email (falls back to the username) |
${account.username} | The username (falls back to the email) |
${account.password} | The password |
${account.totp} | A fresh 6-digit code, worked out at the moment it's typed |
${accounts.<name>.email} | A specific account. <name> is the short name taken from its platform (accounts.google.com becomes google), or from its label when there's no address |
Passwords and codes never appear in a run's log.
Passwords are only typed on the account's own site
${account.password} and ${account.totp} are filled in only into a page field, and only when the page belongs to the account's platform address. Anywhere else β a web request, the clipboard, a variable, a URL β they come out blank. If platform holds a nickname rather than an address, there's nothing to check against and the password is typed into whatever page the step is on. That's why the platform field should hold the real address.
See Build or change a Flow by hand and Flow steps reference.
π₯οΈ Codes on your other computers#
The 2FA secret and linked accounts are part of the profile, so they sync. The same profile on your laptop shows the same codes. See What syncs between your computers and How your data is protected.
β Common questions#
Is this as safe as an authenticator app?
It's the same maths, so the codes are the same. The difference is where the secret lives: on your computers, inside your encrypted profile data, instead of on your phone. If somebody has your unlocked computer, they have the codes β which is also true of a phone lying unlocked on a desk. For accounts where that risk isn't acceptable, keep using your phone.
Do I need to keep my authenticator app as well?
Keep the site's recovery codes somewhere safe, whatever you choose. LoginDeck holds the secret, not the account's backup codes.
Where do the saved passwords show up?
Only in the editor, where the field is masked, and in a Flow typing them into the right site. They're not shown in the profile list, and they're not in run logs.
Are the passwords in an export file?
Yes, in clear text, along with the 2FA secret. Keep export files private. See Back up profiles to a file.
Can a teammate see these?
Anyone who can open the profile has what the profile holds. Give folder access deliberately. See What members can see and do.
βΉοΈ Good to know#
- Notes are the wrong place for passwords. They show in the profile list and in search.
- The code in the editor is worked out in the app, not on a website. It works with no internet connection.