Skip to main content

OTP activity record

Currently it appears that when a user reveals or copies a One-Time Passcode this activity is not logged as recent activity on the pasword entry. This is a security flaw as it permits a user to see the password once, not it elsewhere, then continue to use it without any insight into who/when since the OTP click is not registered in the same way revealing or copying the password itself would be.

Please log user activation of the OTP fields in passwords in the same way as actifity on the password itself is currently logged.

4 comments

Log in to comment and vote

Comments4

  • Coffee Moss

    •

    Jul 31, 2025

    +1, this would be super useful.

  • Aquamarine Oak

    •

    Jul 28, 2023

    Additionally, OTP history is not recorded. We had an engineer wipe out the OTP code and were not able to recover it.

  • Harlequin Star

    •

    May 30, 2023

    Yes, definitely required to track who accesses the OTP.

  • Bronze Mist

    •

    Mar 29, 2023

    This is definitely needed.