What Is a 2FA Key? Secret Key vs. Security Key
A “2FA key” can be the secret text key you copy when setting up an authenticator, or a physical security key you plug in. This page explains the difference, shows what a 2FA secret key looks like and how to protect it.
People search for a “2FA key” and mean quite different things. Knowing which one you have matters, because they are used in different ways and need different care.
The three things people call a 2FA key
| What it is | What it looks like | Used with |
|---|---|---|
| 2FA secret key (also called setup key, authentication key or authenticator key) | A string of letters and digits such as JBSWY3DPEHPK3PXP | Authenticator apps and online authenticators like 2FA Auth |
| Hardware security key | A small physical USB, NFC or Bluetooth device | FIDO2 / WebAuthn sign-in. Not supported by 2FA Auth. |
| Backup (recovery) codes | A list of one-time codes | Emergency access if you lose your authenticator |
2FA Auth works with the first kind only: the secret key used to calculate time-based codes. It cannot read or replace a physical security key.
What is a 2FA secret key?
When you enable authenticator-based two-factor authentication, the service creates a random secret and shows it to you as a QR code and as text. Your authenticator and the service both store this secret. Every 30 seconds each side combines the secret with the current time to calculate the same 6-digit code, as explained in what is TOTP.
The text version is usually Base32: capital letters A–Z and the digits 2–7, often shown in groups of four. Because Base32 has no 0, 1, 8 or 9, a typed key containing those characters has been copied incorrectly.
Sample only – do not use it for a real account: JBSWY3DPEHPK3PXP
Where to find your 2FA key
- In the account’s security settings, choose “Authenticator app”. Next to the QR code, look for “Can’t scan it?”, “Enter a setup key” or “Show secret key”.
- Inside the QR code. It contains an
otpauth://link with the secret, the account name and the issuer, for exampleotpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example. You can scan it with the camera or paste the link into the generator. - In your password manager or notes, if you saved it when you first set up 2FA.
Most services show the key only once. If you did not save it, the usual fix is to turn 2FA off and on again (using a backup code to sign in) to receive a new key.
Is there an online 2FA key generator?
You do not generate the secret key yourself – the service that protects your account creates it. What 2FA Auth does is the next step: it turns that key into the current 6-digit 2FA code. If you were looking for a “2FA key generator” in that sense, use the online 2FA code generator. Be cautious of any site that offers to create a secret key for an existing account; it will not match what the service expects.
How to keep a 2FA key safe
Treat the secret key like a password. Anyone who has it can generate your codes from anywhere.
- Save it in a password manager or another encrypted place, or write it down and store it offline.
- Do not send it by email or chat, and do not take screenshots that sync to the cloud.
- Enter it only on devices you trust.
- If you suspect it was exposed, reset 2FA for that account to get a new key.
What about hardware security keys?
A hardware security key is a different, often stronger, form of two-factor authentication. It does not contain a secret you type anywhere; it proves your identity to the genuine website using public-key cryptography. If a service offers one, it is a good choice for important accounts. It is a separate method from authenticator codes, and the two can be enabled side by side. See what is 2FA for how the methods compare.