Wowkey iPhone Guide: From AutoFill to Passkey Sign-In

Set up Password AutoFill, login items, OTP, Passkeys, in-context login saving, secure sharing, and password generation on iOS 16 and later.

This guide applies to iOS 16 and later. Password AutoFill and OTP QR scanning work on iOS 16 or later. Passkeys require iOS 17 or later. System OTP suggestions in a verification-code field require iOS 18 or later.

1. Before you begin: Turn on Password AutoFill

Make Wowkey an iOS Password AutoFill provider first. Once it is enabled, iPhone can show Wowkey suggestions when you tap a username, password, or verification-code field in Safari or another app.

  1. Open Wowkey, sign in, and unlock your vault.
  2. Go to Settings and open AutoFill, then select Password AutoFill.
  3. Turn on the switch and follow the prompt to iOS Settings. Under PasswordsPassword Options, select Wowkey for AutoFill.
  4. Return to Wowkey and make sure Password AutoFill shows as enabled.
  5. On iOS 17 or later, make sure Passkey support is also enabled. If you want the current OTP copied after filling a login, optionally enable Auto-copy OTP passwords.

Note: Wowkey must be unlocked before it can request that AutoFill be enabled. The names of the iOS Password and Password Options pages can vary slightly by iOS version and language; follow the system page opened by Wowkey when it is available.

2. Create a login item

A login item stores a service name, username, password, and matching website address. iOS matches AutoFill suggestions using the item’s domain or URL. Even when you sign in to a native app, add the service’s real website domain when possible.

  1. On the vault home screen, tap the add button and choose Login.
  2. Give the item a recognizable name, such as “Example website” or “Work email”.
  3. Enter the username and password. A username can be an email address, phone number, or service-specific account name.
  4. In the Smart suggestions search field, enter a website or service name, such as “Google” or “Taobao”. Select the correct result to fill its domain into the Website field below.
  5. If there is no suitable result, or you need a specific sign-in address, enter the real URL directly under Website, for example https://example.com.
  6. Optionally add a folder, note, or favorite, then tap Save.

Why does the website address matter? An item without an address can still be stored, but iOS may not offer it for the current sign-in page. Do not combine unrelated websites in a single login item.

3. View, edit, and organize items

When a password changes, an account is updated, or a website moves, update the original item instead of creating a similar duplicate.

  1. Search the vault by item name, username, or website address and open the item.
  2. Select Edit.
  3. Update the name, username, password, website, folder, or notes, then tap Save.
  4. After changing a password or website address, keep Wowkey open and unlocked briefly so the app can refresh iOS AutoFill suggestions.

Add favorites for frequent items, or use folders for personal, work, and household accounts. For high-sensitivity items, you can require a further confirmation before viewing or autofilling them.

4. Use the password generator

Use the generator to create unique passwords for new accounts, password resets, and repeated-password replacements.

  1. Open Generator and select Random password.
  2. Set the length. For normal website passwords, use at least 15 characters with upper- and lowercase letters, numbers, and special characters.
  3. If a website rejects certain symbols, adjust Special characters and generate again instead of reusing an old password.
  4. Tap Use to place the password in a new item, or copy it into the password field you are editing.
  5. Save the login item, then return to the website or app to finish registration.

The generator also provides Random phrase and PIN options. A random phrase is useful when you must type a password manually. Use a PIN only when a service explicitly requires one.

5. Add one-time passwords (OTP) to a login item

An OTP is a time-based verification code used by authenticator apps and two-step verification. Saving it in its corresponding login item keeps the username, password, and code together.

  1. In the website’s security settings, enable two-step verification and choose Authenticator app.
  2. Keep the QR code or authenticator key visible on the website.
  3. Open the related Wowkey login item, choose Edit, and find the OTP password or authenticator-key field.
  4. Tap the scan icon to scan the QR code. When iPhone asks, allow Wowkey to use the camera. If the website gives you a key instead, enter or paste the standard TOTP key.
  5. Save the item and confirm that Wowkey now displays a rotating code.
  6. Return to the website and enter the current code to finish setup. Do not close the website’s setup page until it confirms success.

Important: QR codes and authenticator keys are as sensitive as passwords. Do not share them, and do not remove an existing authenticator method until the website has confirmed setup. This flow currently supports standard otpauth://totp links only.

6. Save and use Passkeys

A Passkey must be created by a website or app that supports Passkeys; you cannot create a usable Passkey from an empty vault item. On iOS, creation, saving, and sign-in are handled by the Wowkey Password AutoFill extension.

Save a new Passkey

  1. Make sure your iPhone runs iOS 17 or later, Password AutoFill is set up as described in Chapter 1, and Passkey support is enabled in Wowkey Settings > AutoFill.
  2. In a website or app that supports Passkeys, open account security settings and choose to add, create, or register a Passkey.
  3. When iOS presents a credential request, choose Wowkey.
  4. Unlock Wowkey with Face ID, Touch ID, or your master password. If the service asks for additional verification, complete it when prompted.
  5. On the Save passkey screen, verify the website and username. You may change the item name, then tap Save passkey.
  6. Wowkey creates a new login item for that account and saves the Passkey. The original service can then finish registration.

Sign in with an existing Passkey

  1. On the website or app sign-in screen, choose Sign in with Passkey or similar wording.
  2. In the iOS credential sheet, select Wowkey and the correct account.
  3. Verify with Face ID, Touch ID, or your master password when prompted.
  4. iOS returns to the original website or app and completes sign-in.

Note: The iOS Passkey registration flow creates a new login item; it does not offer an option to attach the Passkey to an existing item. If Wowkey says that a Passkey is not up to date, open the app, refresh the vault, and try again.

7. Sign in automatically in Safari or apps

After AutoFill is enabled and a login item is saved, day-to-day sign-in usually means choosing an item from iPhone’s password suggestion.

  1. Open the sign-in page in Safari or the target app and tap the username or password field.
  2. From the Passwords suggestion above the keyboard, or from the key icon, choose the matching item supplied by Wowkey.
  3. If the vault is locked, the Wowkey extension shows its unlock screen. Verify with Face ID, Touch ID, or your master password.
  4. iOS returns the username and password to the original sign-in page. Confirm the account before submitting.

For items with OTP:

  • On iOS 18 or later, tapping the verification-code field can show Wowkey’s matching OTP as a system suggestion. Choose it to fill the code.
  • On iOS 16 or 17, enable Auto-copy OTP passwords. When Wowkey fills the username and password, it copies the current OTP to the clipboard; paste it into the code field.

If the correct item is not offered, use Search vault inside the Wowkey extension. If it still cannot be found, check that the item has a username, password, and the real website address for the current service.

8. Save a new item or update a password from a sign-in page

This works differently from Android: iOS does not read your submitted username and password after a form is sent and then offer an automatic save prompt. To save a new account, open Wowkey’s AutoFill extension from the current sign-in page and choose New login item, then enter the details yourself.

Save a new account

  1. On a website or app sign-in page, tap the username or password field and open iOS Password AutoFill, then enter Wowkey.
  2. At the bottom of the Wowkey extension, tap New login item.
  3. The website address and suggested item name are prefilled. Enter the username and password, and adjust the item name if needed.
  4. Tap Save login item. Wowkey refreshes sign-in suggestions for that website.
  5. Return to the sign-in page and choose the item you just saved.

Update an existing password

When a website asks you to change a password, edit the existing Wowkey login item and save the new password. New login item checks whether the same website and username already exist; if it finds a similar item, it asks you to edit the existing one instead of creating a duplicate.

9. Securely share a vault item

Secure sharing starts from an existing vault item and generates a separate protected link. It does not share your entire vault. The link holds a snapshot of the item at the time it was created; editing the original item later does not update an existing link.

  1. Open the regular vault item you want to share. OTP items cannot be securely shared.
  2. In the item’s action menu, choose Secure share, then review the item and its information.
  3. Set an expiration period: 1 hour, 1 day, 7 days, 14 days, or 30 days.
  4. Optionally enable Allow one view only. For extra protection, enable Require access password and set a password.
  5. Tap Generate link.
  6. From the vault home screen, open My shares. Open the record you created, copy the link, or use the iPhone system share sheet to send it.
  7. When the share is no longer needed, disable or permanently delete the link in My shares.

Secure sharing does not have a field-by-field selection screen. A login item includes its username and website, and includes its password when you have permission to view it. OTP, Passkeys, and attachments are not included. If you only need to share part of the information, create a separate item with only the required content before sharing it.

Safer practice: Do not send an access password and its sharing link in the same chat. Give the password by phone, in person, or through another trusted channel.

10. Troubleshooting

Wowkey does not appear on a sign-in page

  • In Wowkey Settings > AutoFill, make sure Password AutoFill is enabled and that iOS Settings has Wowkey selected as a provider.
  • Make sure you can sign in to Wowkey and unlock the vault. After editing an item, open the app briefly so it can refresh its system suggestions.
  • Check that the item includes a username, password, and website address. iOS does not recommend an item based on its name alone.
  • Use Search vault in the AutoFill extension. If the item is found there, its saved website address probably does not match.

OTP or Passkeys do not work

  • OTP: make sure you scanned the authenticator QR code supplied by the website, not an SMS-code QR code. Also make sure iPhone time is set automatically.
  • System OTP suggestions require iOS 18 or later. On earlier versions, use auto-copy and paste instead.
  • Passkeys: make sure the iPhone runs iOS 17 or later, the service itself supports Passkeys, and Passkey support is enabled in Wowkey.
  • If a Passkey is reported as out of date, open Wowkey, refresh the vault, and try again.

New login item is missing

  • First tap the username or password field, then enter Wowkey through the iOS Password AutoFill entry point.
  • The target page must provide iOS with a recognizable website address. If it does not, create the item manually in Wowkey as described in Chapter 2.
  • To change a password, edit the existing item. New items with the same website and username are blocked to prevent duplicates.

After setup, try the complete flow with a low-risk test account first: create an item, autofill it, add OTP or a Passkey, then save a new item from the sign-in page. Move email, payment, and work credentials only after that test is successful.