> For the complete documentation index, see [llms.txt](https://yubico.gitbook.io/yubikey5/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yubico.gitbook.io/yubikey5/tutorials/battle.net-otp.md).

# Battle.net OTP

Instructions on setting your battle.net account up with Yubikey's authenticator app.

{% hint style="warning" %}
As of 08/15/2023 -- it has been confirmed that using the WinAuth program no longer works. Battlenet has changed their endpoint API and the program now times out when attempting to communicate with Battlenet.\
\
Additional means of adding Battlenet to your Yubikey, Bitwarden, and KeePassXC are currently being looked at.
{% endhint %}

##

## <mark style="color:red;">❊ What is Battle.net?</mark>

Battle.net is an Internet-based online game, social networking service, digital distribution, and digital rights management platform developed by Blizzard Entertainment.

The service was launched on December 31, 1996, followed a few days later with the release of Blizzard's [action-role-playing](https://en.wikipedia.org/wiki/Action_role-playing_game) video game [*Diablo*](https://en.wikipedia.org/wiki/Diablo_\(video_game\)) on January 3, 1997. Battle.net was officially renamed to "Blizzard Battle.net" in August 2017.

The platform currently supports storefront actions, social interactions, and matchmaking for all of Blizzard's modern [PC games](https://en.wikipedia.org/wiki/PC_game) including [*Hearthstone*](https://en.wikipedia.org/wiki/Hearthstone_\(video_game\)), [*Heroes of the Storm*](https://en.wikipedia.org/wiki/Heroes_of_the_Storm)*,* [*Overwatch 2*](https://en.wikipedia.org/wiki/Overwatch_2), and [*StarCraft: Remastered*](https://en.wikipedia.org/wiki/StarCraft:_Remastered), as well as various [*Call of Duty*](https://en.wikipedia.org/wiki/Call_of_Duty) games, and [*Crash Bandicoot 4: It's About Time*](https://en.wikipedia.org/wiki/Crash_Bandicoot_4:_It%27s_About_Time) from corporate sibling of Blizzard Entertainment, [Activision](https://en.wikipedia.org/wiki/Activision). The platform provides cross-game [instant messaging](https://en.wikipedia.org/wiki/Instant_messaging) and [voice chat](https://en.wikipedia.org/wiki/Voice_over_IP) service.

## <mark style="color:red;">❊ Battle.net Mobile Authenticator</mark>

The Battle.net Mobile Authenticator, simply called *Battle.net Authenticator* on the app stores, is a security mobile application.

The application is available for [iOS](http://en.wikipedia.org/wiki/iOS) and [Android](http://en.wikipedia.org/wiki/Android_\(operating_system\)) devices.

When you log in to your account, an authentication request is sent to your device. If the code on your device matches the one on your computer, press **Approve**.

If you want to login using the authenticator’s randomly-generated numeric code instead, click **Use Authenticator Security Code** on your computer. Then press **Enter code manually** on your device to generate an authentication code. Each code is unique and valid only once.

## <mark style="color:red;">❊ Battle.net Secret Key</mark>

The <mark style="color:red;">**battle.net authenticator secret key**</mark> is the key you are given that is used by the mobile authenticator in order to generate a OTP every 30 seconds. Battle.net does not provide an easy way to view your secret; and they really don't want you having it. However, once you obtain your secret; you can use that secret to add your Battle.net account to any authenticator, including the Yubikey.

## <mark style="color:red;">❊ Obtaining Battle.net Secret Key</mark>

{% hint style="danger" %}
Your secret key should be kept secret. Under no circumstances should you EVER give out your Secret Key to anyone, for any reason.

If someone obtains your secret key; they can then generate OTP codes and allow themself to access your battle.net account.
{% endhint %}

Since services like Steam and Battle.net do not want you having your secret key, we need to utilize a program called <mark style="color:red;">**WinAuth**</mark>. This is a free open-source application that has been around for years and is trusted. Using this application will allow you to obtain the secret key needed.

### <mark style="color:blue;">Download From Github</mark>

|                                                                               |                                                                       |
| ----------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| [**Official Website**](https://github.com/winauth/winauth/releases/tag/3.6.2) | Download the latest version of WinAuth from the official Github page. |

On the official website above, two versions available for download:

* [WinAuth-3.6.2.zip](https://github.com/winauth/winauth/releases/download/3.6.2/WinAuth-3.6.2.zip)
* [WinAuth-3.6.2-NET35.zip](https://github.com/winauth/winauth/releases/download/3.6.2/WinAuth-3.6.2-NET35.zip)

The first link appears to throw an error when you attempt to run it on Windows, and complains about a security certificate being expired.&#x20;

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FEAZUuxJIzLGi4KSO4mnV%2FIocKorx.png?alt=media&amp;token=c932c75c-6a49-44ae-b5d8-c92b7d0bd3c9" alt=""><figcaption><p>Error shows when attempting to run WinAuth-3.6.2.zip</p></figcaption></figure>

If WinAuth-3.6.2.zip does not work, download <mark style="color:red;">**WinAuth-3.6.2-NET35.zip**</mark>.&#x20;

At the time of writing this guide, the second file works fine.

### <mark style="color:blue;">Direct Download</mark>

The direct download has been provided here if you want to immediately download it. It is the latest version. The application has been marked as a Public Archive which means that no more versions of the program will release anymore by the original developer, however, the application still works as of 2023.

{% file src="/files/6No0Sw25PewGegn43H1h" %}

Once you have downloaded the exe file, execute it.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FiXIXy5eEuwyiXfvUbQ0V%2Fwa_1.png?alt=media&amp;token=afe0af2f-f510-4565-8b74-b8cfb844be94" alt=""><figcaption></figcaption></figure>

Then press ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F4OeucozAQaICsQsKukMl%2Fwa_3.png?alt=media\&token=971c00fd-b16d-4889-9863-04323deb021c) and select **Battle.net** from the dropdown.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FTrIn3Dz3jrNCRyOiGSxh%2Fwa_2.png?alt=media&amp;token=54450ae3-3218-492e-96df-3e05a7f26347" alt=""><figcaption></figcaption></figure>

You will see a dialog with a few questions and instructions:

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FNym9qABhyX5iswOb0Tkk%2Fwa_4.png?alt=media&amp;token=318caa61-e5fe-4b61-b50d-5f14f262d857" alt=""><figcaption></figcaption></figure>

Enter a name at the top, and select an icon.

Select the <mark style="color:red;">**New Authenticator**</mark> tab and follow the instructions on-screen; which will ask you to sign into your Battle.net account in your browser.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2F6iIrDBYZdtuLYglv2Uq8%2Fwa_5.png?alt=media&amp;token=dd8267e7-70cd-455b-9ad5-31562b256a45" alt=""><figcaption></figcaption></figure>

Out of the options at the bottom, select:

* <mark style="color:blue;">**Already enabled your Authenticator app? Link it to this Battle.net Account.**</mark>
