Field Guide to Two-Step Login
Two-step login (also called two-factor authentication or 2FA) is a common security technique used by websites and apps to protect your sensitive data. Websites that use two-step login require you to verify your identity by entering an additional "token" (also called verification code or one-time password (OTP)) besides username and password, typically retrieved from a different device.
Without physical access to the token from your secondary device, a malicious actor would be unable to access the website, even if they discover your username and password:
Commonly, websites or apps with sensitive data (for example, your online bank account) will attempt verify your identity outside of the login screen by:
Sending a token in an SMS / text message to the mobile device on-file.
Asking for a token generated by an Authenticator app (for example, Authy) on your mobile device.
Looking for a token from a physical security key (for example, Yubikey).
Security often involves a tradeoff between protection and convenience, so ultimately it's up to you! Generally, the two most critical ways to use two-step login are:
Secure all vault data by requiring a secondary step each time you log in to Bitwarden, in addition to entering your master password.
Secure an individual website by requiring a temporary one-time password (TOTP) when you log in. You can store and generate TOTPs with Bitwarden.
Since your password manager stores all of your logins, we highly recommend that you secure it with two-step login. Doing so protects all of your logins by preventing a malicious actor from accessing your vault, even if they discover your master password.
Enabling two-step login will require you to complete a secondary step each time you log in, in addition to entering your master password. You won't need to complete your secondary step to unlock your vault, only to log in.
Bitwarden offers several two-step login methods for free, including:
via an authenticator app (for example, Authy or Google Authenticator)
For premium users, Bitwarden offers several advanced two-step login methods:
Duo Security with Duo Push, SMS, phone call, and security keys
YubiKey (any 4/5 series device or YubiKey NEO/NFC)
FIDO (any FIDO2 WebAuthn certified key)
Learn more about your options or get help setting up any method using our Setup Guides.
Bitwarden probably isn't the only website or app you use that has two-step login options, which is especially useful for websites that store sensitive information (for example, credit card or bank account numbers). Most websites with a two-step login option will locate it in the Settings, Security, or Privacy menus.
Activating two-step login will typically open a QR code, like this example from Reddit:
Scanning this code with an authenticator app will enable the app to generate rotating six-digit tokens that you can use to verify your identity, like this one generated by Authy:
To setup two-step login for Reddit using Authy, tap the Add Account button and scan the QR code presented by your website or app. Scanning the QR code will generate your six-digit token. Enter this code in the Verification Code input box to finish setting up.
Typically, you will be given the option to download recovery codes. Downloading recovery codes is critical to prevent you from losing access to your two-step login tokens, even if you lose the device Authy is installed on.
Next time you login to Reddit, you will be required to verify your identity by entering a verification code from Authy. Verification codes rotate every 30 seconds, so it will be impossible for a malicious actor to discover your code without physical access to your device.
Authy is our recommended authenticator app because it includes backups for any device. Backups prevent you from losing access to your tokens, even if you lose the device Authy is installed on. Flip the Authenticator Backups toggle on the Accounts screen of the Authy app to use this feature.
Other authenticator apps include Google Authenticator and FreeOTP, and as of May 7, 2020 Google Authenticator includes verification code portability across Android devices.
As an alternative to Authy, Bitwarden offers a built-in authenticator for premium users, including members of paid organizations (families, teams, or enterprise).
Bitwarden for iOS and Android can scan QR codes and generate six-digit tokens just like other authenticator apps. Using Bitwarden authenticator to secure a website will save a rotating six-digit token with that login vault item. You can also manually save your verification code secret to a vault item from any Bitwarden app.
Learn how to use Bitwarden authenticator.
Why use Bitwarden authenticator?
Understandably, some users are skeptical about using Bitwarden for token authentication. Remember, security often involves a tradeoff between protection and convenience, so the best solution is up to you. Generally, folks that use Bitwarden authenticator do so for two reasons:
When you use Bitwarden mobile apps or browser extensions to auto-fill a username and password, it will automatically copy the verification code to your clipboard for easy pasting.
If you are using a browser extension, you can chain together the login keyboard shortcut (Windows:
Ctrl + Shift + L/ macOS:
Cmd + Shift + L), following by the paste shortcut (Windows:
Ctrl + V/ macOS:
Cmd + V) for lightning-fast logins.
For organizations, a large benefit of using the Bitwarden authenticator for token verification is the ability to share the token generation among team members. This allows organizations to protect their accounts with two-step login without sacrificing the ability for multiple users to access that account or requiring coordination between two employees to share tokens in an unsafe way.
Now that you are a two-step login expert, we recommend: