Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.

In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.

There is a comprehensive roadmap planned with additional functionality.

Available for iOS and Android

  • Simon Müller@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    102
    ·
    2 months ago

    To those that are confused about this:

    Bitwarden does indeed handle TOTP directly in the password manager, but only on paid accounts and only logged in.

    This is a completely offline app, separate from your existing Bitwarden account, that is entirely free.

    It might serve as an alternative to e.g Aegis to some.

    • Serinus@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 months ago

      I haven’t been entirely happy with Bitwarden for other reasons. You can’t self host and share with one other person without paying them $40/year. Their advertising is deceptive, because they say you can do both for free. But that one or the other, not both.

      You also can’t easily share individual passkeys outside of the app. If you want to grab a passkey, you have to export your entire vault.*

      It’s basically annoyance-ware.

      * note that sharing passkeys is not best practice, but there are use cases.

      • Vetinari@reddthat.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        As others have said vaultwarden is the solution here. It is free, you can manage multiple vaults, totp is free. All the platform bit warden apps & plugins work with it. Supposedly it is leaner and easier to set up. Don’t know for sure because it is all I have used.

        For shared passwords, I have a family vault where I put my streaming pws and such and everyone has access without having to share my personal vault.

  • Chemical Wonka@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    28
    ·
    edit-2
    2 months ago

    with full Internet access (As shown in Aurora Store)

    Thanks but I pass, I’d rather use Aegis that doesn’t need internet connection at all.

  • Concave1142@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 months ago

    Correct me if I am wrong, but the Bitwarden client itself already does this. I store several of my TOTP’s in my self hosted Vaultwarden/Bitwarden install.

    • aseriesoftubes@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      You’re right, it does. This is a head-scratcher.

      I guess they already had the TOTP code written, so creating a standalone app was trivial, but what’s the point?

      • 4am@lemm.ee
        link
        fedilink
        English
        arrow-up
        7
        ·
        2 months ago

        TOTP in the Bitwarden Vault is a paid feature. The standalone app is free, and doesn’t even require a Bitwarden account.

        This allows free tier users a way to use TOTP without upgrading, and without needing to trust Google Authenticator or something else.

  • Thoralf Will@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 months ago

    After Authy scrapped its support for the desktop client, I’m looking for an alternative. Sadly, this does not look like it.

    • redfellow@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      I’m in the same boat. I’m a paid Bitwarden user but I’d like to keep 2fa and passwords separated.

      If no alternative soon, i’ll just bite the bullet and put everything in bitwarden (except itself, ofc)

  • capital@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 months ago

    Glad these were answered:

    Isn’t this the same as storing TOTP authentication codes in Bitwarden Password Manager?

    Integrated TOTP authentication is a premium feature in Bitwarden Password Manager. Bitwarden Authenticator is a standalone mobile app that generates TOTP codes for any online service that supports them. Bitwarden Authenticator can be used without a Bitwarden account.

    Should I use both? When should I use the integrated authentication  feature? When should I use Bitwarden Authenticator?

    Integrated authentication in Bitwarden Password Manager offers a convenient way for users to add 2FA to their online accounts. This popular feature will remain available across paid plans.

    Bitwarden Authenticator can be used to store your verification codes to access your Bitwarden account, as well as other online applications you use.

    They can be used together, or separately, depending on your security preferences.

  • penquin@lemm.ee
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 months ago

    Does this save to my cloud account with them or is it only local? I got screwed over by Aegis (my fault) when I got a new phone and forgot to back up Aegis and lost a lot of my logins. Some of them I can’t get unless I call the company and verify it’s me 🤦🏽‍♂️

  • Coreidan@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 months ago

    Jesus fuck. How many more authentication apps do we need that all do the same thing?

    At work I need at least 4-5 different authentication apps because every customer has something different.

    We don’t need another.

    • dave@feddit.uk
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 months ago

      4-5 TOTP apps? So far, when, e.g. Microsoft or Google have insisted use of their own Authenticator app is required, it’s worked fine for me using Ente Auth or similar just by entering the code / QR.

      • million@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        This even works with some apps that hide the standard part - like Symantec VIP - it’s possible to extract what they are doing and use a standard TOTP app instead of VIP.

  • n0x0n@feddit.de
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 months ago

    OK, so one TOTP app more. What’s this one doing better than all the others like 2FAS?

    • Corhen@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Thats what i want to know, i use Authy, and want to know if its worth switching for.

    • InvaderDJ@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      Is there anything about Aegis that makes it better than Authy? Just looking at the page for Aegis, I’m not seeing a lot of difference. And it being Android only limits it.

  • edric@lemm.ee
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 months ago

    Nice! I currently have a couple of services on MS Authenticator that I can migrate over.

  • Evotech@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 months ago

    I’m not putting my totp with my password, same as I’m not putting my password with my email (proton)