Bitwarden can keep a site's time-based one-time-password secret beside its login and generate rotating codes. That makes routine sign-in easier, but it places the password and code seed behind the same vault access. For an especially sensitive account, a separate authenticator or hardware security key may give a stronger independent barrier. The service's recovery codes matter either way.
Before you start
Start with the site's own two-step-verification setup, not a QR code from an email. Check whether your Bitwarden plan can generate integrated TOTP codes; the vendor distinguishes storing a secret from generating codes in some plan tiers.Do it step by step
- Sign in to the service through its official address and begin adding an authenticator method. Keep the existing second factor active until the new method is confirmed.
- In the corresponding Bitwarden login item, add the TOTP seed using the official QR code or manual secret. Ensure you are editing the correct account, especially when you have work and personal logins on one domain.
- Generate one code from Bitwarden and enter it into the service's verification screen. Complete the setup only after the service confirms the method is active.
- Download or copy the service's one-time recovery codes, store them securely outside the same single device and mark them as sensitive. A recovery code is often the only practical route when the vault or phone is unavailable.
- Sign out and perform a normal login test, then verify the code shown in the vault actually works. If you have a second device, check that the secret syncs only where you intended.
- For the highest-risk accounts, revisit whether the integrated approach matches your threat model. Consider a separate authenticator or security key and remove superseded methods from the service after successful tests.