iPhone Not Autofilling Verification Codes? What to Check
iPhone fills codes through three separate features—Messages, Mail, and the Passwords app—each with its own rules. This guide separates them and gives an ordered check for each failure point.
iPhone does not have one "autofill verification codes" feature. It has three, and Apple's naming makes them easy to mix up. Messages can detect a texted passcode and offer it above the keyboard. The Passwords app can make its own rotating code from a setup key you saved earlier, and Apple's guide for that feature is the one titled "Automatically fill in verification codes". A code emailed to the Mail app can autofill in Safari, a feature Apple announced in June 2023 that has no end-user guide page of its own on iPhone today. If nothing fills in, work out which of the three you are using, then check in order: that AutoFill is on, that a suggestion is not already waiting above the keyboard, that the website's field is built to take a code, and that the message was not addressed to a different site.
This page uses Apple's current iPhone User Guide, the iOS 27 version (checked September 28, 2026). The two Settings paths below read the same in the iOS 26 guide.
Which code feature are you using?
| Where the code arrives | What fills it | What has to be true |
|---|---|---|
| A text message | iPhone detects the passcode in Messages and shows it above the keyboard; you tap it | Apple's page describes codes in the Messages app |
| An email, in the Mail app | Safari autofills it, a feature Apple announced in June 2023 | You're using Safari, and the mail is in the Mail app, not the Gmail or Outlook app, which Apple's pages don't cover |
| Nothing arrives; the Passwords app generates it | The Passwords app produces a rotating code from a setup key or QR code you added earlier, offered above the keyboard | You already linked the account to Passwords with a setup key or QR code; this is what Apple's guide calls "verification codes" |
The middle row has the thinnest Apple documentation: there is no current iPhone guide page for Mail codes the way there is for SMS passcodes and Passwords-app codes. The bottom row is a different feature from the other two: it doesn't wait for an incoming message at all, it generates its own code, and it only works for a site you've already set up in Passwords with a setup key.
What should you check, in order?
- Confirm you're looking in the right place. Apple's SMS passcode page describes Messages: "iPhone can detect the passcode in Messages and display it above the keyboard. To use the passcode, tap it." A code in the Gmail app or Outlook app is not "Mail" in Apple's sense, and Apple's pages don't describe reading either one. If the text never arrives at all, use the text-message code check instead.
- Check that AutoFill is on. Apple's guide for saved passwords says: "Turn Password AutoFill on or off: Go to Settings > General > AutoFill & Passwords, then turn on or off AutoFill Passwords and Passkeys." The same screen holds the Verification Codes section in step 6.
- Tap into the code field and look above the keyboard. A texted code appears there as a suggestion. For a Passwords-app code, Apple's instructions say: "When asked for a verification code, tap the suggestion that appears above the keyboard." If no suggestion appears for a Passwords-app code, Apple's fallback is to "go to the Passwords app on your iPhone, select your account for the website or app, tap the verification code, then tap Copy Verification Code." A texted code is not in Passwords: open the message in Messages and copy the code from there.
- Check whether the website's own field accepts a code. This cause, like step 5, sits on the site's side, not yours. Apple's developer documentation says a page enables this with an attribute on the input: "you can autocomplete security codes from single-factor SMS login flows" with
<input id="single-factor-code-text-field" autocomplete="one-time-code"/>. Without it, iOS has to guess from the page; Apple says an explicit value supports login flows "that couldn't otherwise be detected by Password AutoFill's heuristics." If you run the site, check a code field's markup. - Check whether the code was addressed to a different site. Some services format the text message itself with the site's domain built in. The WICG draft for these origin-bound codes says the message ends with "a top-level host and a code, each prefixed with a sigil: U+0040 (@) before the top-level host, and U+0023 (#) before the code", for example
@example.com #747723. When that host is not the same site as the page you're on, the draft says the browser "should not assist the user with providing the origin-bound one-time code's code to the website." A service that texts codes for a different domain (a separate regional domain, not just a subdomain) is set up against that rule; that is the service's fix, not your phone's. - If AutoFill filled a code the site then rejected, find the newest message yourself. Apple's guide says you "can choose to automatically delete the verification codes after entering them with Autofill, or keep them": "Under Verification Codes, turn Delete After Use on or off." With it on, a code AutoFill already entered is removed after use, so open Messages or Mail and look for the newest code.
- Copy and paste it instead. This skips every step above and works in any field that accepts a paste. W3C's Understanding page for WCAG 2.2's Accessible Authentication criterion is direct about sites: "A service that requires manual transcription of a verification code is not compliant", and it must be possible "to at least paste the code". A field that blocks paste is worth reporting to the site.
Does this checklist apply on a Mac or an Android phone?
No; both have their own rules and their own guide. On a Mac, macOS 26 extends code AutoFill from Messages and Mail to other apps, including Chrome, with mixed results; see Safari autofills Mail codes; Chrome depends on your Mac. For Chrome or an Android phone, see Does Chrome autofill verification codes? Android SMS: yes, email: no. And if the code landed on your phone but you are logging in on a laptop, see Code on your phone, login on your laptop.
Does MagicLess work on iPhone?
No. MagicLess is a Chrome extension for computers (Chrome 116 or later), and Chrome on iPhone does not run extensions. On a computer, in Chrome, it reads a Gmail inbox you connect and offers the code on the login page, which covers the case iPhone's own Mail AutoFill can't reach: a code that lands in Gmail rather than the Mail app, read on a laptop rather than a phone. See what MagicLess works with.
FAQ
Does turning on AutoFill Passwords and Passkeys also enable code autofill?
Apple's guide documents that switch for saved passwords and passkeys. The Verification Codes section, including Delete After Use, lives on the same Settings > General > AutoFill & Passwords screen, but Apple's pages don't state that the switch itself is what enables the Messages SMS-passcode suggestion. Turn it on regardless, then work through the rest of the checklist.
Does a code from Mail fill in browsers other than Safari?
Apple's 2023 announcement names Safari only: "one-time verification codes received in Mail will now automatically autofill in Safari." It says nothing about other browsers on iPhone, so if the suggestion does not appear in another browser, copy the code from Mail and paste it.
What does Delete After Use do?
Apple's guide says you can choose to automatically delete the verification codes after entering them with AutoFill, or keep them. Keeping them makes it easier to compare a new code with an older one when a site rejects a code.
Claim ledger
| Claim | Source | Last checked | Confidence |
|---|---|---|---|
| "iPhone can detect the passcode in Messages and display it above the keyboard. To use the passcode, tap it." | Apple Support: Automatically fill in SMS passcodes on iPhone | 2026-09-28 | High |
| "Turn Password AutoFill on or off: Go to Settings > General > AutoFill & Passwords, then turn on or off AutoFill Passwords and Passkeys." | Apple Support: Automatically fill in strong passwords on iPhone | 2026-09-28 | High |
| "When asked for a verification code, tap the suggestion that appears above the keyboard. If no suggestion appears, go to the Passwords app on your iPhone, select your account for the website or app, tap the verification code, then tap Copy Verification Code." | Apple Support: Automatically fill in one-time verification codes on iPhone | 2026-09-28 | High |
| "You can choose to automatically delete the verification codes after entering them with Autofill, or keep them."; "Under Verification Codes, turn Delete After Use on or off." | Apple Support: Automatically fill in one-time verification codes on iPhone | 2026-09-28 | High |
A website enables code autofill on a web field with <input autocomplete="one-time-code"/>. | Apple Developer: Enabling Password AutoFill on an HTML input element | 2026-09-28 | High |
| "One-time verification codes received in Mail will now automatically autofill in Safari." | Apple Newsroom, June 2023 | 2026-09-28 | High |
In the WICG draft (a Community Group report, not a W3C standard), origin-bound code messages end with a top-level host and a code, each marked with a sigil (e.g. @example.com #747723), and a user agent "should not assist" when the host is not the same site as the page. | WICG: Origin-bound one-time codes delivered via SMS | 2026-09-28 | Medium |
| "A service that requires manual transcription of a verification code is not compliant"; it must be possible for a user "to at least paste the code". | W3C: Understanding SC 3.3.8 Accessible Authentication (Minimum) | 2026-09-28 | High |
Sources
- Apple Support: Automatically fill in one-time verification codes on iPhone
- Apple Support: Automatically fill in SMS passcodes on iPhone
- Apple Support: Automatically fill in strong passwords on iPhone
- Apple Newsroom: Apple announces powerful new privacy and security features
- Apple Developer Documentation: Enabling Password AutoFill on an HTML input element
- WICG: Origin-bound one-time codes delivered via SMS
- W3C WAI: Understanding Success Criterion 3.3.8: Accessible Authentication (Minimum)