What it means
A password manager's integrated TOTP stores the code-generating secret near the account password. A separate authenticator or hardware key can keep that factor outside the password vault. The integrated method can be sensible for everyday convenience, yet a vault compromise could expose both pieces. Recovery codes are a separate emergency path and should not live solely on the same vulnerable device.
A real-world example
A user unlocks their vault to fill both password and rotating code for a forum account. They use a separate security key for their email account because that email can reset many other services.
What to do
Choose per account based on consequence, verify the setup with a real sign-in and protect recovery codes. Keep an old working factor until the new one is confirmed.
The distinction that matters
TOTP is not origin-bound like a properly implemented security-key or passkey flow; a real-time phishing page may relay a code. A separate authenticator is not magically safer if its cloud backup is poorly protected. Assess the complete recovery and device-security chain. Keep the password manager's own two-step method outside the vault it protects, or a locked-out user could need the locked vault to recover access. For high-impact accounts, prefer a phishing-resistant method when the service supports one and keep a tested backup method.
Bitwarden integrated TOTP scope