Why a code as well as a password
Passwords leak. They get reused across sites, guessed, phished, or turned up in a breach of somewhere else entirely, and the person holding yours does not have to be anywhere near you to try it.
A one-time code closes that off. It is generated fresh each time you sign in, it is sent to your email rather than shown anywhere, and it expires. Someone with your password and nothing else gets as far as the code screen and stops there. To go further they would need your inbox too.

Trusting the browser you use every day
Security you resent is security you work around, so a code every single time would be the wrong trade on a laptop only you use.
Underneath the code field is Trust this device for 30 days. Tick it and MyBento remembers that browser: your password is enough for the next month, and the code step is skipped. It is unticked by default, because being trusted should be something you choose rather than something that happens to you. On a shared or borrowed computer, leave it alone.

How the trust is held
Each browser is trusted on its own. Trusting your laptop does not trust your phone, and nothing you do on your account affects anyone else's.
Trust does not roll forward every time you use it. Thirty days after you set it, the code is asked for once more, and you can trust the device again from there. That is deliberate: a device you stop using drops out of trust on its own rather than staying trusted indefinitely.
If you lose a device or pass it on, changing your password ends its trust along with everything else.