/
All topics

Passwords and Autofill

Passkeys and one-time codes

Sign in with Touch ID or your phone, and keep your two-step codes beside the password.

⌥⌘C

Passkeys#

When a site offers a passkey, the Mac’s own sheet asks how: Touch ID, iCloud Keychain or a password app, an iPhone nearby, or a security key. macOS asks once whether Yab may use passkeys. Passkeys only work on secure pages.

One-time codes#

Yab can be the authenticator for a site, so its six-digit code sits beside the password.

  1. On the site, start setting up two-step sign-in with an authenticator app, and copy the setup key.
  2. Press ⌥⌘L, pick the account, press ⌘K and choose Add One-Time Code….
  3. Paste the key, or the otpauth:// link. Yab shows the code: type it on the site to finish.

From then on, ⌥⌘C copies the code, and with the site’s code box in use, ↩ pastes it. The key stays in the keychain; only the code ever reaches the page.

Codes from your mail and Messages#

When a site asks for a code it just mailed or texted you, the code hangs under the box with who sent it, and ↩ puts it in. A code is never filled without you. Settings › Autofill has, under One-time codes:

  • From your mail: through Mail once it’s on, and before that, if you turn it on, from Gmail’s unread mail with the tab’s own sign-in.
  • From Messages: the codes you’re texted. It needs Full Disk Access for Yab, and the row offers Allow… for it.
  • Archive code mails after use, with Mail on.