You can create a TOTP (time-based one-time passcode) in your LastPass vault and use it for authentication when logging in to a third-party app or website.
Restriction: This feature is only available for LastPass Teams and LastPass Business accounts.
Tip: You can share this temporary code with others who also access the same site with the same site credentials, where Two-Factor Authentication/Two-Step Verification is required.
To enter the secret key into your LastPass site entry and generate a TOTP that can be used, do the following:
Generate a secret key from your third-party site
- Log in to your account on the third-party app or site you want to use.
- Follow the site's instructions to set up Two-Factor Authentication within the site's security settings (outside of LastPass) and enable the site to use an authentication app (for example, LastPass Authenticator app).
- Many sites will provide a QR code to scan for setting up authentication. Instead, locate the option for manual setup, then copy the secret key (intended to be used for third-party services) and then paste it into a text editor.
Remember: You will be using this value in later steps.
Enter the secret key into LastPass.
- Log in to LastPass and access your vault by doing either of the following:
- In your web browser toolbar, select the LastPass icon and select Vault.
- Go to
https://lastpass.com/login/
and log in with your email address and master password.
- Log in to the LastPass for Desktop app.
- To activate a new secret key, add a new site password or edit an existing password:
Action in LastPass | Instructions |
|---|
Add a new password | - Select the PLUS icon
- Select Password.
- Enter all of the information you want to store.
|
Edit an existing password | - Locate your password.
- Select the Edit icon
|
- In Two-factor authentication, paste the secret key to the Secret key field, you copied in Step 3 (copied from your third-party site's authentication settings) then select Activate.
Note: The TOTP automatically populates in the One-time passcode (TOTP) field if the site is stored in your vault and has a secret key associated. If the generated code expires before it has been submitted on the site, expires every 30 seconds, then the new TOTP is automatically generated and filled into the One-time passcode (TOTP) field.
Attention: Only use the characters A–Z, 2–7, and = when entering the secret key, and do not include any spaces.
Result: LastPass generates a 6-digit, time-based one-time passcode (TOTP), using the SHA-1 algorithm, and the TOTP changes every 30 seconds.
- In the One-time passcode field, select the view icon to view the TOTP, then copy the passcode.
Tip: Select the no view icon to hide the current TOTP, or select the view icon to show the TOTP again.
- Return to your site's settings and paste the code for verification, then save and proceed.
Results: You have now paired your site entry in your vault with LastPass and a new TOTP for your site is displayed which will change every 30 seconds.
What to do next: You can share this site entry with others who also need to use the same site credentials.