A strong password on its own is no longer enough to protect an online account. Reused credentials, phishing pages and large-scale data breaches mean that a leaked password can be tried against your other accounts within minutes. Two-factor authentication (2FA) closes most of that gap, and Bitwarden offers two separate ways to run it in New Zealand.
This guide explains the difference between the free, open-source standalone Bitwarden Authenticator app and the Premium time-based one-time password (TOTP) generator built into the Bitwarden password manager. It covers how each one works, how to protect your Bitwarden account itself, how to move your existing codes across from Google Authenticator, and how authenticator codes fit with everyday Kiwi services. Every figure below was checked against Bitwarden’s own documentation.
What Bitwarden Authenticator Is and How 2FA Works
Two-factor authentication (also called multi-factor authentication, or MFA) asks for a second proof of identity on top of your password. The most common form is a TOTP: a six-digit code that changes every 30 seconds, generated on your device from a shared secret and the current time. Because the code rotates and is calculated locally, a stolen password is not enough to log in on its own.
The standard behind this is RFC 6238, which defines TOTP as an HMAC-based algorithm (by default using SHA-1) seeded by a secret key you scan as a QR code when you set up 2FA on a website. This is a different technology from passkeys and FIDO2/WebAuthn, which replace passwords entirely; if you want to compare that approach, see our guide to Bitwarden passkeys. An authenticator app simply stores those TOTP secrets and shows you the current code.
The Two Products: Vault-Integrated Codes vs the Standalone App
Bitwarden splits this into two distinct tools, and the right choice depends on how much you value convenience versus keeping factors separate.
| Aspect | Integrated vault TOTP generator | Standalone Bitwarden Authenticator app |
|---|---|---|
| Cost | Part of Bitwarden Premium (US$19.80/year in 2026) | Free for everyone |
| Account required | Yes — a paid Bitwarden account | No account needed to generate codes |
| Where it runs | Inside the Bitwarden apps and browser extensions | A separate app on iOS and Android |
| Where codes are stored | Encrypted inside your main vault entry | On the device, with optional vault sync |
| Autofill | Copies the code to your clipboard during autofill | Manual copy from the app |
| Best for | Speed across many everyday logins | Keeping high-value codes isolated from passwords |
The Integrated Vault TOTP Generator (Premium)
Inside a Premium vault, a login entry can hold more than a username and password — it can also store the TOTP secret for that site. Bitwarden then generates the rotating six-digit code client-side, right next to the credentials it belongs to. When you autofill a login through the browser extension, Bitwarden fills the username and password and copies the current verification code to your clipboard, so you can paste it into the site’s 2FA field without reaching for your phone.
This feature is part of Bitwarden Premium, which costs US$19.80 per year (US$1.65 per month) as of 2026, after the price rose from US$9.99 in January 2026. Premium also adds encrypted file storage, vault health reports, emergency access and hardware-key support. If you want the full breakdown, see our guide to Bitwarden pricing and plans.
The Convenience Versus Isolation Trade-Off
Security specialists often flag a structural downside to storing the password and its 2FA secret in the same place, sometimes called “fate-sharing”: if that single vault is ever compromised, both factors fall together.
- The single point of failure: keeping the password and the TOTP seed in one encrypted entry means both factors share the same lock.
- The case for separation: for online banking, primary email and other high-value accounts, storing the second factor in a different app is the safer design.
- Where integration is fine: for lower-risk retail sites, forums and streaming logins, the speed of clipboard autofill is a reasonable trade for most people.
- If you do centralise: use a long, unique master passphrase and protect the account with its own two-step login (covered below).
The Standalone Bitwarden Authenticator App (Free)
Launched in May 2024, the standalone Bitwarden Authenticator is a free, open-source app for iOS and Android. It needs no Bitwarden account and no subscription, so you can use it purely as a code generator even if your passwords live somewhere else. It scans a site’s QR code and produces a standard six-digit TOTP that refreshes every 30 seconds, using SHA-1 by default — the settings almost every website expects.
Because it is open source, the code for both platforms is published on GitHub for anyone to inspect. In its default setup, your codes are backed up through your phone’s own operating-system backup (iCloud on iOS, Google’s backup on Android) rather than to a Bitwarden server.
Quick facts
| Developer | Bitwarden, Inc. |
|---|---|
| Official download | bitwarden.com/products/authenticator (App Store & Google Play) |
| Platforms | iOS and Android (iOS/Android 12+ needed for vault sync) |
| Price | Free |
| Licence | Free and open source (code published on GitHub) |
| Account required | No — only needed for optional vault sync |
| Default code | 6 digits, 30-second refresh, SHA-1 (TOTP / RFC 6238) |
Syncing Codes With Your Bitwarden Vault
If you use both the Authenticator app and the Bitwarden Password Manager app, you can link them so codes appear in both. The behaviour is worth understanding clearly:
- Vault to Authenticator: once you turn on “Allow authenticator syncing” in Password Manager (Settings → Account security), TOTP codes saved in your vault appear automatically in the Authenticator app.
- Local to vault: codes that exist only in the Authenticator app can be sent to your vault with a one-time “copy to Bitwarden vault” action — this is a transfer, not continuous two-way sync.
- Requirements: both apps installed, iOS or Android 12 or newer, and a Bitwarden account you are logged into.
- Important limit: synced codes are not stored independently in the app, so if you log out of Password Manager they become unavailable in Authenticator until you log back in.
Security and Customisation Settings
The app is deliberately lean, but it still offers the controls most people need:
- Biometric app lock: require Face ID or a fingerprint before the app will display your codes.
- Algorithm and format options: when editing a local code you can change the algorithm from the default SHA-1 to SHA-256 or SHA-512, adjust the digit count and change the refresh period — only do this if a specific service asks for it.
- Favourites: pin your most-used codes to the top of the home screen.
- Usernames: add a username label to tell apart several codes for the same website.
How to Protect Your Bitwarden Account With 2FA
The most valuable single upgrade is turning on two-step login for your Bitwarden account itself, because that vault holds the keys to everything else. There is a useful point many guides miss: two-step login using an authenticator app (or email) is free on Bitwarden. Premium is only required for the separate feature of storing other sites’ TOTP seeds inside your vault entries, and for hardware-key methods such as YubiKey and FIDO2.
To avoid a circular trap — where the code you need to open the vault is stored inside that same vault — generate your Bitwarden account’s 2FA code in the standalone Authenticator app or another independent app, not in the vault you are trying to unlock.
Step-by-Step: Turning On Two-Step Login
- Sign in to the web vault at vault.bitwarden.com on a computer.
- Open Settings → Security → Two-step login.
- Choose Authenticator app (free) and select Manage.
- Scan the on-screen QR code with your standalone Bitwarden Authenticator app on your phone.
- Type the six-digit code the app shows to confirm the link, then enable it.
- Save and print the recovery code Bitwarden displays, and store it somewhere safe offline.
Migrating From Google Authenticator and Other Apps
Moving away from closed-source options such as Google Authenticator or Microsoft Authenticator is straightforward. The Bitwarden Authenticator app can import from Google Authenticator (via its transfer QR code), and from LastPass, 2FAS, Aegis (Android) and Raivo (iOS) using their export files. Note that 2FAS backup files must not be password-protected for the import to work.
Importing From Google Authenticator
- Open Google Authenticator, go to its menu and choose Transfer accounts → Export to generate a migration QR code.
- Open the Bitwarden Authenticator app and go to its import or “scan” option in settings.
- Point your camera at the migration QR code so the app can read the accounts.
- Check that every site, label and rotating code has come across correctly.
- Only once you have confirmed the codes match, remove the accounts from — or uninstall — the old app.
Before you delete anything, it is worth confirming your accounts are secure in the first place; a quick check with Have I Been Pwned shows whether any of your logins have appeared in a known breach.
Using Authenticator Codes With New Zealand Services
Because Bitwarden Authenticator produces standard TOTP codes, it works with any site or service that accepts an authenticator app — the codes are not tied to any one provider. That covers a growing list of local services as two-step verification becomes the norm.
- Government and tax: Inland Revenue’s myIR now supports an authenticator app as a two-step verification method, and two-step verification is being made compulsory for myIR users.
- Banking: most New Zealand banks run their own in-app approval or SMS second factor; where a bank or investment platform offers an authenticator-app option, Bitwarden Authenticator can hold it.
- Global accounts used from NZ: Google, Microsoft, Facebook, Amazon and similar services all accept standard TOTP codes.
Adding 2FA to your important logins is one of the most effective steps in a wider cyber security routine, alongside a password manager and vigilance about phishing.
Key points
- The standalone Bitwarden Authenticator app is free, open source and works without an account.
- Storing other sites’ TOTP codes inside your vault is a Premium feature (US.80/year in 2026) and adds clipboard autofill.
- For sensitive accounts, keep the 2FA code separate from the password to avoid “fate-sharing”.
- TOTP works offline; save your recovery codes, because zero-knowledge means support cannot reset your 2FA.
- The codes are standard TOTP, so they work with any service that accepts an authenticator app, including myIR two-step verification.
Common Mistakes and Best Practices
A frequent misconception is that an authenticator app needs an internet connection to work. It does not: TOTP is calculated offline from the stored secret and your phone’s clock, with nothing sent over the network. A second misconception is that support can restore your 2FA if you lose your phone. Because Bitwarden uses zero-knowledge encryption, no employee holds your secrets, so without your recovery codes you can be locked out permanently.
- Keep the clock accurate: enable “set time automatically” on your phone, because even a few seconds of clock drift can make TOTP codes fail.
- Store recovery codes offline: print or write down the recovery codes each service gives you and keep them somewhere secure at home.
- Isolate high-value accounts: use the standalone app for email, banking and your password vault so the second factor is separate from the password.
- Review active sessions: periodically check the login and device history on your key accounts and remove anything you don’t recognise.
Limitations to Be Aware Of
No tool is perfect. The standalone Bitwarden Authenticator is still a relatively young app, and it lacks some of the folders, tags and advanced search found in longer-established alternatives. Moving codes between different operating systems — say, from an iPhone to an Android tablet — can be more manual than transferring within the same platform, and synced codes depend on staying logged in to Password Manager.
These are usability rough edges rather than security flaws, and Bitwarden continues to add features to the app. For most people the trade-offs are minor next to the protection that any properly configured authenticator provides.
Reference sources
- Bitwarden Authenticator — product page
- Bitwarden Help — Bitwarden Authenticator
- Bitwarden Help — Sync Verification Codes
- Bitwarden Help — Import & Export Authenticator Data
- Bitwarden — pricing and plans
- Bitwarden Blog — launch of the Authenticator app
- Inland Revenue — set up two-step verification for myIR
- IETF RFC 6238 — TOTP: Time-Based One-Time Password Algorithm
Frequently Asked Questions (FAQ)
Is the standalone Bitwarden Authenticator app free?
Yes. The standalone app is free and open source on iOS and Android, needs no subscription, and works without a Bitwarden account. You only pay if you want Bitwarden Premium to store other sites’ TOTP codes inside your password vault.
Does the app need an internet connection to generate codes?
No. TOTP codes are calculated on your device using the stored secret and your phone’s clock, following the RFC 6238 standard. No data is sent over the network to produce a code, so it works fully offline.
What is the difference between the vault generator and the standalone app?
The vault generator is a Premium feature that stores TOTP codes inside your login entries and copies them to your clipboard during autofill. The standalone app is a free, separate tool that keeps your 2FA codes isolated from your passwords.
What happens if I lose the phone with my codes?
Because Bitwarden uses zero-knowledge encryption, support cannot reset your two-step login for you. You regain access using the recovery codes you saved when you set up 2FA, which is why storing them offline is essential.
Do I need Premium to protect my Bitwarden account with 2FA?
No. Two-step login using an authenticator app or email is free for all Bitwarden accounts. Premium is only needed for hardware-key methods such as YubiKey and FIDO2, and for storing other sites’ TOTP codes in your vault.
Why do my codes suddenly stop being accepted?
This is almost always clock drift on your phone. Because TOTP relies on accurate time, turning on “set time automatically” in your phone’s date and time settings usually fixes it straight away.




