mSecure 7 is here – our biggest update yet. Get the app.

Passkeys and OTPs: Passwordless Sign-In, Built-In 2FA

July 29, 2026   |    mSecure, Security

Passwords have a problem: the more secure they are, the harder they are to remember. So people reuse them, or shorten them, or write them on a sticky note – and every one of those habits makes an account easier to break into. mSecure 7 tackles that problem two ways at once. You can now… Read more

Passwords have a problem: the more secure they are, the harder they are to remember. So people reuse them, or shorten them, or write them on a sticky note – and every one of those habits makes an account easier to break into.

mSecure 7 tackles that problem two ways at once. You can now sign in to supported sites with passkeys instead of typing anything at all, and you can keep your one-time passwords (OTPs) for two-factor authentication right next to the logins they protect – no separate authenticator app required. Here’s what that actually means for you.

Passkeys: nothing to type, nothing to steal

A passkey replaces your password with something a phishing site can’t fake: your face, your fingerprint, or your device PIN.

Behind the scenes, your device creates a pair of cryptographic keys when you set one up. The website keeps the public half. Your device – or mSecure – keeps the private half, and it never leaves. There’s no string of characters for an attacker to guess, leak, or steal from a breached database, because there isn’t one to steal in the first place.

That also makes passkeys naturally phishing-resistant – a property the FIDO Alliance built into the standard from the start. A fake login page can trick you into typing a password. It can’t trick your device into using a passkey that was only ever created for the real site.

Using one is simple:

  1. Choose Sign in with a passkey on a supported site.
  2. Approve with Face ID, Touch ID, Windows Hello, or your device PIN.
  3. You’re in. No typing, no copying codes, no password reset emails.

mSecure 7 stores your passkeys alongside your passwords, syncs them across every device, and lets you organize them with the same tags and vaults you already use. Major services – Google, Apple, Microsoft, Amazon, PayPal, and more – already support signing in this way, and that list keeps growing.

One-Time Passwords: your 2FA codes, finally in one place

If you’ve ever fumbled between mSecure and a separate authenticator app to grab a six-digit code before a countdown timer hits zero, this is the fix.

mSecure 7 can generate and store OTPs directly in your vault. Set one up once, and mSecure produces a fresh code every 30 seconds – right inside the same record as the login it protects. No app-switching, no hunting for the right entry, no racing the clock. Not sure which of your accounts even offer this? Check our list of websites that support one-time passwords.

Setup happens on the site you’re protecting, not in mSecure:

  1. Open the security or two-factor authentication settings on the site or app.
  2. Choose to add an authenticator app – the site shows you a QR code.
  3. Scan it with your phone’s camera and pick mSecure when prompted.

From then on, the code lives right next to that login, encrypted with the same AES-256 protection as the rest of your vault. And if you’re on macOS 15 (Sequoia) or later, you can set mSecure as your default codes provider so OTPs autofill in Safari automatically – just like passwords do.

Why both, together

Passkeys and OTPs solve different problems. Passkeys replace the password entirely, for the sites that support it. OTPs strengthen the password you still have everywhere else. Most people will end up using a mix of both for a long time – which is exactly why it matters that mSecure keeps them in the same encrypted vault instead of scattering them across separate apps.

One place for passwords, passkeys, and 2FA codes. One less app on your phone. One fewer thing standing between you and getting logged in.

Passkeys and OTPs are just two pieces of a bigger update – see the full rundown of what’s new in mSecure 7, including Custom Filters and a redesigned sharing experience.

Getting started

Both features are available on Essentials and up. A good place to start: pick two or three high-value accounts – email, banking, cloud storage – and see which ones already support passkeys. Add OTPs to whatever’s left. You don’t have to convert everything today; every account you upgrade is one less password an attacker can use against you.

Want the full walkthrough? Check our How to Use Passkeys in mSecure 7 and Use One-Time Passwords (OTP) in mSecure 7 in our support center. And if you want to see everything else mSecure can organize beyond passwords, don’t miss Powerful mSecure Features You Should Be Using.