The key object (GoogleAuthenticatorKey) has a secret (the purpose of which is clear), scratch codes (the purpose is clear) and a verificationCode at UNIX Epoch. The purpose of the last one is not documented, and it's not used or passed anywhere (except to the repository).
Is there any purpose of that one and do we have to store it. If yes - please add to the documentation. If not - maybe get rid of it?