# Bitwarden Authenticator

**URL:** https://discuss.privacyguides.net/t/bitwarden-authenticator/18120
**Category:** Tool Suggestions
**Created:** 2024-05-01T15:49:41Z
**Posts:** 31

## Post 1 by @user1 — 2024-05-01T15:49:41Z

Open source and available for Android and iOS.

> **[Bitwarden just launched a new authenticator app. Here’s what it means to...](https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/)**
>
> Bitwarden Authenticator gives users the ability to generate and store TOTP codes

---

## Post 2 by @anon29374801 — 2024-05-01T15:53:27Z

I love Aegis but once they implement being able to locally sync with my bitwarden vault, its going to be hard for me not switch.

EDIT: doesn’t seem like the Android app has a way to import from other authenticators yet. So I will probably hold off for a bit.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/9/9981d3fe341a9f0bde21480465e7308049888975.png)

---

## Post 3 by @jerm — 2024-05-01T15:53:50Z

Source codes:

Android

> **[GitHub - bitwarden/authenticator-android: The Bitwarden Authenticator app moved to...](https://github.com/bitwarden/authenticator-android)**
>
> The Bitwarden Authenticator app moved to https://github.com/bitwarden/android !

IOS

> **[GitHub - bitwarden/authenticator-ios: The Bitwarden Authenticator app moved to...](https://github.com/bitwarden/authenticator-ios)**
>
> The Bitwarden Authenticator app moved to https://github.com/bitwarden/ios !

---

## Post 4 by @lepras — 2024-05-01T16:50:39Z

> [@anon29374801](#):
>
> love Aegis but once they implement being able to locally sync with my bitwarden vault, its going to be hard for me not switch

Eleborate pl.

---

## Post 5 by @anon29374801 — 2024-05-01T16:58:42Z

> [@lepras](#):
>
> Eleborate pl.

Being able to automatically sync any TOTP token, locally, that you scan with the Bitwarden Authenticator into your Bitwarden Vault will be extremely convenient and add extra value to being a premium subscriber (only premium can add TOTP tokens to their vault at this moment).

This would be even better as a new premium customer because you could import all your TOTP token to Bitwardens Authenticator and then sync it to your vault.

It also seems like much less of a risk then having to manually enter your TOTP secret into your vault each time.

side note im going to guess that Proton will rollout a similar feature in the near future.

---

## Post 6 by @Securely0845 — 2024-05-01T17:32:17Z

I wonder if the vault sync is going to be two way, one way and or optional, I still don’t like the idea of storing my 2FA codes in my PW manager.

\*Looks like they answered my question in the FAQ on their site:

> Should I use both? When should I use the integrated authentication feature? When should I use Bitwarden Authenticator?

> Integrated authentication in Bitwarden Password Manager offers a convenient way for users to add 2FA to their online accounts. This popular feature will remain available across paid plans.

> Bitwarden Authenticator can be used to store your verification codes to access your Bitwarden account, as well as other online applications you use.

> They can be used together, or separately, depending on your security preferences.

---

## Post 7 by @anonymous176 — 2024-05-01T19:01:33Z

Ehh, for me no reason to consider switching from Aegis. For one, Aegis is obviously much more mature. But more importantly I think storing these TOTP codes locally on device only instead of in your password manager makes 2FA much more effective.

---

## Post 8 by @ph00lt0 — 2024-05-01T19:03:21Z

![image](//forum-uploads.privacyguidesusercontent.com/original/2X/2/26456a54e0d4ece7978843281dac267e1825ed82.jpeg)

so bitwarden actually can make nice designs.

might consider it if it gets a desktop app too.

---

## Post 9 by @moonwriting — 2024-05-01T19:08:15Z

> [@anonymous176](#):
>
> I think storing these TOTP codes locally on device only instead of in your password manager makes 2FA much more effective.

Bitwarden Authenticator stores them locally on device.

---

## Post 10 by @saltostrichpool — 2024-05-01T19:45:56Z

I will definitely make sure to keep an eye on this. I have tried the iOS app, and it is ok with the features you would expect from most authentication apps. A few features I did notice that it didn’t have is the ability to import your authentication codes from other apps and that it doesn’t allow you to hide codes, and show them once double tapped. This is a feature that I liked from ente. However, I did notice on the iOS GitHub repo for the authentication app that there is a [pull request](https://github.com/bitwarden/authenticator-ios/pull/56) to allow the user to import from JSON.

Another cool thing I noticed is that the apps are built with their native OS languages. The iOS app being built with Swift, and the android app being built with Kotlin. I like that they decided to do this, and this kind of gives us a sneek peek of what Bitwarden will become once the clients have been rebuilt with their native OS languages.

---

## Post 11 by @Handheld7434 — 2024-05-01T23:18:30Z

Sync across devices would be useful.

---

## Post 12 by @purplecactus — 2024-05-02T00:31:29Z

i’m excited about this! probly won’t migrate to it (i actually don’t really want my 2FA codes associated with my vault) but i still like that a trustworthy company (thinking of what happened with Raivo when i say this) is coming out with an open source authenticator, especially x-platform, considering there just aren’t that many options.

---

## Post 13 by @anon7592771 — 2024-05-02T04:24:53Z

Tritt das nicht den zahlenden Kunden auf die Füße?

---

## Post 14 by @jonah — 2024-05-02T04:47:13Z

Well, paying customers get to sync their codes to their vault. Free customers using this app only have their codes stored locally.

(Although syncing codes to your PWM can be a double-edged sword, it’s not for everyone)

---

## Post 15 by @suffix — 2024-05-02T04:53:45Z

It looks like the iOS version (2023.5.0 (38)) is not the latest as in the GitHub (2024.5.0)

Do you know how to add website icons next to the TOTP?

---

## Post 16 by @mentalfoss — 2024-05-02T15:42:59Z

Every time i see a sensitive-private app collecting any kind of data, i get discouraged to even try it.

It’s shame because especially in iOS we lack good options and after the Raivo OTP sold out, there is a huge gap left.

In Android atm is all good, we have Aegis.

---

## Post 17 by @anonymous176 — 2024-05-02T16:58:08Z

Wait, what data does Bitwarden Authenticator collect?

---

## Post 18 by @anon2844160 — 2024-05-02T18:06:34Z

Exodus can’t download the app, so no direct information on what trackers.

Apple app store lists: Contact Info, Identifiers, Diagnostics  
Google Play store lists: App info and performance, which can be shared with third parties. Data cannot be deleted.

This is looking a lot less interesting to me.

---

## Post 19 by @lepras — 2024-05-02T20:03:14Z

> [@anon2844160](#):
>
> Google Play store lists: App info and performance, which can be shared with third parties. Data cannot be deleted.
> 
> This is looking a lot less interesting to me

interesting.

---

## Post 20 by @eqrlzo8t — 2024-05-03T04:06:26Z

> [@anon2844160](#):
>
> Exodus can’t download the app, so no direct information on what trackers.
> 
> Google Play store lists: App info and performance, which can be shared with third parties. Data cannot be deleted.

It has crashlytics

> ****
>
> ![bitwarden](//forum-uploads.privacyguidesusercontent.com/original/2X/4/4de8c868cc449ec8d048cc632ddb41ec3dade0cc.png)

I’m also not too fond of 2FA app with network permission.

---

## Post 21 by @redoomed1 — 2024-06-13T15:18:48Z

> [@anon29374801](#):
>
> import from other authenticators yet

Looks like this has changed very recently:  
[https://redlib.nohost.network/r/Bitwarden/comments/1dezfku/bitwarden\_authenticator\_adds\_import\_options\_for/l8fbuyt/?context=3](https://redlib.nohost.network/r/Bitwarden/comments/1dezfku/bitwarden_authenticator_adds_import_options_for/l8fbuyt/?context=3)

> **[Import and Export | Bitwarden](https://bitwarden.com/help/authenticator-import-export/)**
>
> Learn how to import data to and export data from Bitwarden Authenticator.

---

## Post 22 by @Securely0845 — 2024-06-13T15:52:21Z

They just added the functionality yesterday on iOS.

---

## Post 23 by @BionicBison — 2024-06-13T15:53:32Z

The apparent inclusion of tokens in iCloud backups with no clear option to disable it should probably be a consideration in recommending this. It’s not clear whether they are encrypted in any way before sending to iCloud, and not everyone has Advanced Data Protection enabled.

 ![IMG_5786](//forum-uploads.privacyguidesusercontent.com/original/2X/2/21cc8e02c5d0af94e00eb13544d4a24d4e029e4d.jpeg)

---

## Post 25 by @Regime6045 — 2024-06-13T16:22:26Z

That’s not usually true. The password can be stolen / phished / hacked, but it’s useless without the TOTP code which is only valid for 30 seconds. Of course, if your TOTP _seed_ (from which the codes are derived) is stolen, then yes.

---

## Post 27 by @Regime6045 — 2024-06-13T16:48:53Z

You’re right, that’s true if you have your Bitwarden and Aegis on different devices or secured by different passwords (i.e. the attacker has access to one but not the other app), and no recovery codes are saved in Bitwarden either.

---

## Post 28 by @Bhaelros — 2024-06-13T16:48:54Z

Bitwarden Authenticator is totally different app from Bitwarden Password Manager. They don’t have an integration between each other. BW Authenticator doesn’t require an account too.

---

## Post 29 by @xe3 — 2024-06-13T17:46:35Z

> [@Balsamic3361](#):
>
> Just a reminder, having your 2FA in the same spot as your passwords means you don’t have 2FA.

I used to hold that opinion, but it seems like an overly black and white statement that is unintentionally misleading.

What you’ve said is true against one specific important but less likely category of threat: _your password manager vault is breached by an attacker who has not compromised the device you use for totp_. It is true that in this specific context, storing 2fa secrets totally separate from your passwords would offer a meaningful second layer of defense.

But a breach of our password manager vault is nowhere near the most likely or most common way that our accounts typically get compromised. A server side breach or hack of a service you use, or phishing, social engineering, malware, and/or someone close to you with physical access to your device, are typically more common threats, and in these cases storing TOTP in a separate app or inside your password manager, usually won’t make much of a difference, because the attacker doesn’t have and didn’t need access to your unencrypted vault.

I think you can and should feel more secure storing your totp secrets separately from your passwords/logins, But you shouldn’t frame not doing so as equivalent to not using 2fa at all. Because in most cases–apart from a breached vault–a similar level of protection is achieved regardless of whether your totp is stored within your password manager or in a standalone app. At least that is how I see it.

Also with Bitwarden, the choice is yours, they offer TOTP in the password manager itself, and they now offer this standalone app as well.

---

## Post 30 by @anon29374801 — 2024-06-13T19:17:30Z

> [@redoomed1](#):
>
> ![](https://forum-cdn.privacyguides.net/letter_avatar_proxy/v4/letter/a/2e7e31/48.png) anon29374801:
> 
> > import from other authenticators yet
> 
> Looks like this has changed very recently:

Awesome! Seems like a long time coming for, what I think, should be a day 1 feature. Better late then never I guess :smiley:

Imported from Aegis on my Pixel 7 with GOS, worked without any issue.

Probably still not ready to daily drive, even though I will keep it updated. Until I can set a password I probably wouldn’t consider it.

Even then, without the password manager sync feature being ready, there doesn’t seem to be any incentive to switch from Aegis, which is a much more polished product at this point.

Overall super happy to see progress. Really want this to be great!

---

## Post 31 by @anon29374801 — 2024-06-13T19:22:57Z

> [@Balsamic3361](#):
>
> Just a reminder, having your 2FA in the same spot as your passwords means you don’t have 2FA.

I don’t really understand the logic behind this.

If your vault already has MFA, then anything in the vault already has two factors of authentication to be able to access.

For example, if your proton email password and token are in BW vault, which also has a password and token or security key needed to access it, how would one see that as only one factor of authentication?

EDIT: sorry for the two comments in a row. Mods feel free to combine them in some way if you want.
