Bitwarden just launched a new authenticator app

https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/
  1. Blog
  2. Bitwarden just launched a new authenticator app. Here’s what it means to users.

Available for iOS and Android

Boost your security and download Bitwarden Authenticator today.

Storing 2FA codes is just the beginning. Bitwarden aims to add defense in depth to authentication. 

Bitwarden products equip enterprises and individuals with the ability to securely manage and share sensitive information online: password management for everyone, secrets management for developer and DevOps teams, and software developer tools for passwordless experiences such as passkeys and magic links. These solutions work together, adding protection across organizations that rely on passwords, machine credentials, and passkeys to safeguard sensitive applications and data.

Today, Bitwarden strengthens this security product portfolio with a new authenticator app that protects online services and applications from unauthorized access. Bitwarden Authenticator generates and stores time-based one-time passwords, aka TOTP, which adds another layer of user verification, ensuring identities are confirmed before users gain access to critical data. Released in app stores, Bitwarden Authenticator is available for everyone, even if they are not currently Bitwarden customers.

A new authentication approach that's dynamic and adaptive

This offering signals the future of advanced authentication where enterprises can deliver security at scale, elevate convenience, while embracing passwordless. Though multi-factor authentication (MFA) is a core defense strategy, some implementations have limitations. The infamous SolarWinds attack occurred after cybercriminals took advantage of employees' MFA requests to gain access to internal accounts. In short, traditional multi-factor authentication is susceptible to phishing attacks, code interceptions, stolen SIM cards, and other vulnerabilities. 

Today, Bitwarden Authenticator is available for everyone to store and generate TOTP codes. Looking forward, Bitwarden aims to expand the product roadmap, providing enterprises with more granularity and policy controls around how they manage workforce authentication. 

Just like logins and passwords, workforce authentication itself needs additional verification steps. Here’s an overview of what that future horizon looks like:

Authentication that aligns to custom enterprise policies

Generally, users are required to provide their identities and SSO access when accessing cloud applications. A modern authentication approach would require authorized users to provide additional verification or meet certain requirements before accessing their Windows or MacOS workstations, as well as any other service used within their domain. 

Authentication that integrates with your IT infrastructure

Adopting modern authentication solutions can often mean overhauling existing applications and identity infrastructure. By leveraging widely adopted standards such as TOTP, Bitwarden can work seamlessly everywhere, including legacy applications. Enterprises can remain nimble, without having to re-architect current systems while adopting strong passwordless options such as passkeys, FIDO2 hardware keys, magic links, biometrics, and beyond. 

Authentication that makes passkeys even more phishing resistant

With passkeys -- already more secure and simpler than passwords -- the user experience is greatly improved and human error is nearly eliminated. Even so, passkeys only remain phishing resistant as long as your device or browser remains uncompromised. With a need to further strengthen passkeys, Bitwarden envisions enterprises adding comprehensive policies that are dynamic to how employees use passkeys and the services they’re allowed to access.

Bitwarden Authenticator for everyone

Multi-factor authentication isn't just for businesses. An authenticator that supports cloud and mobile across devices helps everyone stay more secure online. Bitwarden Authenticator helps reduce your risk of fraud and data breaches at home, at work, and everywhere you go. 

“Bitwarden Authenticator provides immediate value to the Bitwarden user base who has been asking for a standalone app for several years. Stay tuned for upcoming new features that will help enterprise organizations enforce security policies to protect and monitor authentication to business applications," said Kyle Spearrin, founder and CTO of Bitwarden.

Use Bitwarden Authenticator to easily generate 2FA verification codes
Use Bitwarden Authenticator to easily generate 2FA verification codes

FAQs

Is Bitwarden Authenticator part of Bitwarden Password Manager?

Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.

What does Bitwarden Authenticator do?

In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.

Isn't this the same as storing TOTP authentication codes in Bitwarden Password Manager?

Integrated TOTP authentication is a premium feature in Bitwarden Password Manager. Bitwarden Authenticator is a standalone mobile app that generates TOTP codes for any online service that supports them. Bitwarden Authenticator can be used without a Bitwarden account.

Should I use both? When should I use the integrated authentication  feature? When should I use Bitwarden Authenticator?

Integrated authentication in Bitwarden Password Manager offers a convenient way for users to add 2FA to their online accounts. This popular feature will remain available across paid plans. 

Bitwarden Authenticator can be used to store your verification codes to access your Bitwarden account, as well as other online applications you use. 

They can be used together, or separately, depending on your security preferences. 

Can I use the Bitwarden Authenticator to add 2FA to my Bitwarden account?

Yes! Many Bitwarden users have asked for a standalone authenticator in which to store their verification codes used to access their Bitwarden account. 

Will Bitwarden be removing the TOTP feature in Bitwarden Password Manager? 

The integrated authenticator will continue to be available in paid plans.

Can I use different logins for Bitwarden Authenticator and Bitwarden Password Manager?

Yes, users can set up different accounts for Bitwarden Authenticator and Bitwarden Password Manager.

How do I backup my data in Bitwarden Authenticator?

Mobile OS: Your data will be backed up through the mobile operating system's backup services. Please make sure your device is configured for backups. Bitwarden Authenticator data is included in the OS backups and will be restored with them.

Data exports: You can export your data and store the file in a safe location, such as an encrypted thumb drive, as a backup that can be imported when needed.

Is Bitwarden Authenticator open source?

Yes! Bitwarden Authenticator is open source and available at the following GitHub repositories for Android and iOS.

Bitwarden Authenticator roadmap

Bitwarden Authenticator is now released with Phase 1 functions for local authenticator codes. There is a comprehensive roadmap planned with additional functionality including a longer term focus on business offerings for workforce authentication.

Bitwarden Authenticator Roadmap
Bitwarden Authenticator Roadmap

Editor's note: Updated June 13, 2024 with information on importing into and exporting from Bitwarden Authenticator

{
"by": "LaSombra",
"descendants": 3,
"id": 40234075,
"kids": [
40237709,
40237755,
40236294
],
"score": 9,
"time": 1714639903,
"title": "Bitwarden just launched a new authenticator app",
"type": "story",
"url": "https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/"
}
{
"author": null,
"date": null,
"description": "Storing 2FA codes is just the beginning. Bitwarden aims to add defense in depth to authentication.",
"image": "https://res.cloudinary.com/bw-com/image/upload/v1/ctf/7rncvj1f8mw7/Wq6bSqKCLFOs0pFKK2dbQ/34c585e2479a007a9c7566be142c2f43/Bitwarden_Auth_blog_card_2.png?_a=DATAdtfiZAA0",
"logo": "https://logo.clearbit.com/bitwarden.com",
"publisher": "Bitwarden",
"title": "Bitwarden just launched a new authenticator app. Here’s what it means to users. | Bitwarden Blog",
"url": "https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/"
}
{
"url": "https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/",
"title": "Bitwarden just launched a new authenticator app. Here’s what it means to users. | Bitwarden Blog",
"description": "BlogBitwarden just launched a new authenticator app. Here’s what it means to users.Available for iOS and AndroidBoost your security and download Bitwarden Authenticator today.Storing 2FA codes is just the...",
"links": [
"https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/"
],
"image": "https://res.cloudinary.com/bw-com/image/upload/v1/ctf/7rncvj1f8mw7/Wq6bSqKCLFOs0pFKK2dbQ/34c585e2479a007a9c7566be142c2f43/Bitwarden_Auth_blog_card_2.png?_a=DATAdtfiZAA0",
"content": "<div><ol><li><a target=\"_blank\" href=\"https://bitwarden.com/blog/\" title=\"Blog\"><b>Blog</b></a></li><li><span></span>Bitwarden just launched a new authenticator app. Here’s what it means to users.</li></ol><section><p><a target=\"_blank\" href=\"https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/#available-for-ios-and-android\" title=\"#available-for-ios-and-android\"><svg></svg></a></p><h2>Available for iOS and Android</h2><p></p><blockquote><p>Boost your security and <a target=\"_blank\" href=\"https://bitwarden.com/download/#bitwarden-authenticator-mobile\">download Bitwarden Authenticator</a> today.</p></blockquote><h4>Storing 2FA codes is just the beginning. Bitwarden aims to add defense in depth to authentication. </h4><p>Bitwarden products equip <a target=\"_blank\" href=\"https://bitwarden.com/products/business/\">enterprises</a> and <a target=\"_blank\" href=\"https://bitwarden.com/products/personal/\">individuals</a> with the ability to securely manage and share sensitive information online: password management for everyone, secrets management for developer and DevOps teams, and software developer tools for passwordless experiences such as passkeys and magic links. These solutions work together, adding protection across organizations that rely on passwords, machine credentials, and passkeys to safeguard sensitive applications and data.</p><p>Today, Bitwarden strengthens this security product portfolio with a new authenticator app that protects online services and applications from unauthorized access. Bitwarden Authenticator generates and stores time-based one-time passwords, aka TOTP, which adds another layer of user verification, ensuring identities are confirmed before users gain access to critical data. Released in app stores, Bitwarden Authenticator is available for everyone, even if they are not currently Bitwarden customers.</p><h4>A new authentication approach that's dynamic and adaptive</h4><p>This offering signals the future of advanced authentication where enterprises can deliver security at scale, elevate convenience, while embracing passwordless. Though <a target=\"_blank\" href=\"https://bitwarden.com/blog/top-10-burning-questions-on-2fa/\">multi-factor authentication</a> (MFA) is a core defense strategy, some implementations have limitations. The infamous SolarWinds attack occurred after cybercriminals took advantage of employees' MFA requests to gain access to internal accounts. In short, traditional multi-factor authentication is susceptible to phishing attacks, code interceptions, stolen SIM cards, and other vulnerabilities. </p><p>Today, Bitwarden Authenticator is available for everyone to store and generate TOTP codes. Looking forward, Bitwarden aims to expand the product roadmap, providing enterprises with more granularity and policy controls around how they manage workforce authentication. </p><p>Just like logins and passwords, workforce authentication itself needs additional verification steps. Here’s an overview of what that future horizon looks like:</p><h4>Authentication that aligns to custom enterprise policies</h4><p>Generally, users are required to provide their identities and <a target=\"_blank\" href=\"https://bitwarden.com/help/about-sso/\">SSO access</a> when accessing cloud applications. A modern authentication approach would require authorized users to provide additional verification or meet certain requirements before accessing their Windows or MacOS workstations, as well as any other service used within their domain. </p><h4>Authentication that integrates with your IT infrastructure</h4><p>Adopting modern authentication solutions can often mean overhauling existing applications and identity infrastructure. By leveraging widely adopted standards such as TOTP, Bitwarden can work seamlessly everywhere, including legacy applications. Enterprises can remain nimble, without having to re-architect current systems while adopting strong passwordless options such as <a target=\"_blank\" href=\"https://bitwarden.com/blog/how-do-passkeys-work/\">passkeys</a>, <a target=\"_blank\" href=\"https://bitwarden.com/blog/fido2-webauthn-2fa-in-all-bitwarden-plans/\">FIDO2 hardware keys</a>, <a target=\"_blank\" href=\"https://bitwarden.com/blog/bitwarden-magic-links-api/\">magic links</a>, <a target=\"_blank\" href=\"https://bitwarden.com/help/biometrics/\">biometrics</a>, and beyond. </p><h4>Authentication that makes passkeys even more phishing resistant</h4><p>With passkeys<strong> </strong>-- already more secure and simpler than passwords -- the user experience is greatly improved and human error is nearly eliminated. Even so, passkeys only remain phishing resistant as long as your device or browser remains uncompromised. With a need to further strengthen passkeys, Bitwarden envisions enterprises adding comprehensive policies that are dynamic to how employees use passkeys and the services they’re allowed to access.</p><h4>Bitwarden Authenticator for everyone</h4><p>Multi-factor authentication isn't just for businesses. An authenticator that supports cloud and mobile across devices helps everyone stay more secure online. Bitwarden Authenticator helps reduce your risk of fraud and data breaches at home, at work, and everywhere you go. </p><p>“Bitwarden Authenticator provides immediate value to the Bitwarden user base who has been asking for a standalone app for several years. Stay tuned for upcoming new features that will help enterprise organizations enforce <a target=\"_blank\" href=\"https://bitwarden.com/help/policies/\">security policies</a> to protect and monitor authentication to business applications,\" said Kyle Spearrin, founder and CTO of Bitwarden.</p></section><figure><img alt=\"Use Bitwarden Authenticator to easily generate 2FA verification codes\" src=\"https://res.cloudinary.com/bw-com/image/upload/f_auto/v1/ctf/7rncvj1f8mw7/wIUzVLJhd6V619ZC4TTo5/aa2986c6232cb49ea2292a371a06c53c/resized_authenticator-verification-codes__1_.png?_a=DAJAUVWIZAA0\" /><figcaption>Use Bitwarden Authenticator to easily generate 2FA verification codes</figcaption></figure><section><p><a target=\"_blank\" href=\"https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/#faqs\" title=\"#faqs\"><svg></svg></a></p><h2>FAQs</h2><p></p><p><strong>Is Bitwarden Authenticator part of Bitwarden Password Manager?</strong></p><p>Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.</p><p><strong>What does Bitwarden Authenticator do?</strong></p><p>In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.</p><p><strong>Isn't this the same as storing TOTP authentication codes in Bitwarden Password Manager?</strong></p><p>Integrated TOTP authentication is a premium feature in Bitwarden Password Manager. Bitwarden Authenticator is a standalone mobile app that generates TOTP codes for any online service that supports them. Bitwarden Authenticator can be used without a Bitwarden account.</p><p><strong>Should I use both? When should I use the integrated authentication  feature? When should I use Bitwarden Authenticator?</strong></p><p>Integrated authentication in Bitwarden Password Manager offers a convenient way for users to add 2FA to their online accounts. This popular feature will remain available across paid plans. </p><p>Bitwarden Authenticator can be used to store your verification codes to access your Bitwarden account, as well as other online applications you use. </p><p>They can be used together, or separately, depending on your security preferences. </p><p><strong>Can I use the Bitwarden Authenticator to add 2FA to my Bitwarden account?</strong></p><p>Yes! Many Bitwarden users have asked for a standalone authenticator in which to store their verification codes used to access their Bitwarden account. </p><p><strong>Will Bitwarden be removing the TOTP feature in Bitwarden Password Manager? </strong></p><p>The integrated authenticator will continue to be available in paid plans.</p><p><strong>Can I use different logins for Bitwarden Authenticator and Bitwarden Password Manager?</strong></p><p>Yes, users can set up different accounts for Bitwarden Authenticator and Bitwarden Password Manager.</p><p><strong>How do I backup my data in Bitwarden Authenticator?</strong></p><p>Mobile OS: Your data will be backed up through the mobile operating system's backup services. Please make sure your device is configured for backups. Bitwarden Authenticator data is included in the OS backups and will be restored with them.</p><p>Data exports: You can export your data and store the file in a safe location, such as an encrypted thumb drive, as a backup that can be imported when needed.</p><p><strong>Is Bitwarden Authenticator open source?</strong></p><p>Yes! Bitwarden Authenticator is open source and available at the following GitHub repositories for <a href=\"https://github.com/bitwarden/authenticator-android\" target=\"_blank\">Android</a> and <a href=\"https://github.com/bitwarden/authenticator-ios\" target=\"_blank\">iOS</a>.</p></section><section><p><a target=\"_blank\" href=\"https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/#bitwarden-authenticator-roadmap\" title=\"#bitwarden-authenticator-roadmap\"><svg></svg></a></p><h2>Bitwarden Authenticator roadmap</h2><p></p><p>Bitwarden Authenticator is now released with Phase 1 functions for local authenticator codes. There is a comprehensive roadmap planned with additional functionality including a longer term focus on business offerings for workforce authentication.</p></section><figure><img alt=\"Bitwarden Authenticator Roadmap\" src=\"https://res.cloudinary.com/bw-com/image/upload/f_auto/v1/ctf/7rncvj1f8mw7/4MZrdp7qAhlrhLfMkZYFXg/5c10705895b2045c421b652f171f8a38/Bitwarden_Authenticator_Roadmap.png?_a=DAJAUVWIZAA0\" /><figcaption>Bitwarden Authenticator Roadmap</figcaption></figure><section><p><strong><i>Editor's note:</i></strong><i> Updated June 13, 2024 with information on importing into and exporting from Bitwarden Authenticator</i></p></section></div>",
"author": "",
"favicon": "https://bitwarden.com/favicon-32x32.png?v=470f020c101877a6a1c4cc95d7464f51",
"source": "bitwarden.com",
"published": "",
"ttr": 199,
"type": "article"
}