> For the complete documentation index, see [llms.txt](https://yubico.gitbook.io/yubikey5/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yubico.gitbook.io/yubikey5/tutorials/bitwarden.md).

# Bitwarden

Useful information related to setting up your Yubikey with Bitwarden.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FkBEgY8r8p7Nqp7sLqg2N%2FBitwarden.jpg?alt=media&amp;token=84c585b9-7dc1-44d7-893a-d27e16661c60" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
This tutorial requires one device of any in the following categories:

* [x] [YubiKey 5 Series](https://www.yubico.com/store/#yubikey-5-series)
* [x] [YubiKey 5 FIPs Series](https://www.yubico.com/store/#yubikey-5-fips-series)
* [x] [YubiKey Security Series](https://www.yubico.com/store/#security-key-series)
  {% endhint %}

![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden** ](https://bitwarden.com)is a password management software title that stores sensitive information such as website credentials in an encrypted vault.

The primary authentication method that Bitwarden utilizes is a simple email and password. However, Bitwarden does support security devices such as the Yubikey.

In order to add a Yubikey to your Bitwarden vault, you must have a <mark style="color:red;">**Premium account**</mark>.

For pricing, visit the ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden Pricing Chart**](https://bitwarden.com/pricing/).

For documentation, visit the ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden Help Center**](https://bitwarden.com/help/).

## <mark style="color:red;">❊ tl;dr</mark>

Just wondering what provider you should use for two-step? we recommend ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [FIDO2 / Webauthn](#fido2-webauthn) or ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [DUO](#duo).

You can read a description for all of them below.

## <mark style="color:red;">❊ Bitwarden vs Vaultwarden</mark>

Vaultwarden is an unofficial self-hosted version of Bitwarden. It is compatible with the ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [official Bitwarden clients](https://bitwarden.com/download/), and is ideal for self-hosted deployments where running the official resource-heavy service is undesirable.

<table><thead><tr><th width="338.3333333333333"></th><th>Bitwarden</th><th>Vaultwarden</th></tr></thead><tbody><tr><td><mark style="color:red;"><strong>Type</strong></mark></td><td>Service</td><td>Self-Hosted</td></tr><tr><td><mark style="color:red;"><strong>Premium Features</strong></mark></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20(1).png?alt=media&amp;token=8ac71312-243b-4852-999d-74eaa595ec54" alt=""> <a href="https://bitwarden.com/pricing/">$10 / year</a></td><td>Free</td></tr><tr><td><mark style="color:red;"><strong>Open-source</strong></mark></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td></tr><tr><td><mark style="color:red;"><strong>Yubikey Support</strong></mark></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td></tr><tr><td><mark style="color:red;"><strong>Bitwarden Client Support</strong></mark></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FWtRVmoJu3cHGrnkRuLRu%2Fcheck.png?alt=media&amp;token=02ef37f6-5cb6-4b6e-916d-63a9c6433763" alt=""></td></tr><tr><td><mark style="color:red;"><strong>Difficulty</strong></mark></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FUUToFKEym4E6BWlKvpEK%2Fstar%20(1).png?alt=media&amp;token=93d6b36c-ca17-4349-87dc-0f4b8c53d39a" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FUUToFKEym4E6BWlKvpEK%2Fstar%20(1).png?alt=media&amp;token=93d6b36c-ca17-4349-87dc-0f4b8c53d39a" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FUUToFKEym4E6BWlKvpEK%2Fstar%20(1).png?alt=media&amp;token=93d6b36c-ca17-4349-87dc-0f4b8c53d39a" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FUUToFKEym4E6BWlKvpEK%2Fstar%20(1).png?alt=media&amp;token=93d6b36c-ca17-4349-87dc-0f4b8c53d39a" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FpYi5Pvae1iBOnVbdtX6e%2Fstar.png?alt=media&amp;token=6efa113b-a142-4dd6-a500-f6f58a788c8b" alt=""></td></tr><tr><td></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20(1).png?alt=media&amp;token=8ac71312-243b-4852-999d-74eaa595ec54" alt=""> <a href="https://bitwarden.com/"><strong>View</strong></a></td><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20(1).png?alt=media&amp;token=8ac71312-243b-4852-999d-74eaa595ec54" alt=""> <a href="https://github.com/dani-garcia/vaultwarden"><strong>View</strong></a></td></tr></tbody></table>

To host your own Bitwarden server on a spare computer or virtual machine, you can use Vaultwarden as an alternative. However, since Vaultwarden does not store your vault data on Bitwarden's servers; you are responsible for the security. The machine you host Vaultwarden on is the machine that will store your vault data. If your Vaultwarden server is compromised, it's game over.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FnehE9nx4NaWwy5IubJDc%2F1_fAmMWzAQEyzQnr0Kejr7pA.gif?alt=media&amp;token=f34ecab6-44ab-41d2-9128-0d7be899de77" alt=""><figcaption></figcaption></figure>

Should you decide on a self-hosted Vaultwarden solution, all the features of Bitwarden will be available. Including the ability to utilize a Yubikey to secure your account. However, on Vaultwarden, these Premium features are free.

## <mark style="color:red;">❊ Adding a Yubikey to your Account</mark>

{% hint style="warning" %}
If using Bitwarden, please remember that you must have a **premium account** in order to add two-step authentication such as a Yubikey. Otherwise, these features will be greyed out.
{% endhint %}

Login to your ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Bitwarden ](https://vault.bitwarden.com/#/login)/ Vaultwarden account.

On upper-right side, locate circular avatar with a dropdown arrow and click.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FAUwTTdtId8jSnaZVE0eD%2Fvw_1.png?alt=media&amp;token=37e4cdba-a4d6-4dd8-8b10-7cca5028251e" alt=""><figcaption></figcaption></figure>

From here, select <mark style="color:red;">**Account Settings**</mark>**.**

Locate **Account Settings** menu on the left and select <mark style="color:red;">**Security**</mark>.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2Fca2p4wRrrOoAGhcWjKsb%2Fvw_2.png?alt=media&amp;token=3da7a754-adbd-4b71-8d5e-408a63415d67" alt=""><figcaption></figcaption></figure>

Middle of screen, select <mark style="color:red;">**Two-step Login**</mark>.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2Fchu5fAxsaC5V6nMAQYdo%2Fvw_3.png?alt=media&amp;token=88b1cafa-2672-4f5c-99e8-aaaa540bfe97" alt=""><figcaption></figcaption></figure>

Center screen, you should see a list of providers you can use for Two-step Authentication.

<figure><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FmnkOXuuZPQXludEyp0cL%2Fvw_4.png?alt=media&amp;token=fa89ead0-8e81-4ccd-bec5-79f29b51ea5b" alt=""><figcaption></figcaption></figure>

### <mark style="color:blue;">Authenticator App</mark>

Authenticate using programs such as ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Microsoft Authenticator](https://www.microsoft.com/p/authenticator/9wzdncrfj3rj) or ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Authy](https://authy.com/). When signing into Bitwarden, you will be asked to open your authenticator app and copy a code which you will then paste into Bitwarden to finish signing in.\
\
For instructions on setting up an Authenticator app, visit the ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden documentation**](https://bitwarden.com/help/setup-two-step-login-authenticator/).

### <mark style="color:blue;">Yubikey OTP Security Key</mark>

Authenticate with Yubikey's OTP feature. By default, when you press the gold button on your Yubikey, a generated string is spit out. You will need to touch your key and provide the generated Yubikey passcode each time you sign in. This method requires SLOT 1 of your Yubikey to be configured for OTP.&#x20;

Generated string looks similar to: <mark style="color:red;">**`vvcccacrtduerauianecrdrfakitaigitkglfutbvngn`**</mark>

This feature communicates with Yubico OTP validation servers. Your Yubikey OTP must be registered with their servers in order to work. You can test this on the official ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Yubikey OTP Demo page**](https://demo.yubico.com/otp/verify).

All Yubikey devices shipped brand new are registered with Yubikey's OTP server. However, if you re-configure SLOT 1 of your Yubikey using the ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Yubikey Manager**](https://www.yubico.com/support/download/yubikey-manager/) application, you must re-configure SLOT 1 with OTP and register your new key with their servers.

This is more secure than email, but still vulnerable to phishing. It's recommended to use ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**FIDO2 / Webauthn**](#fido2-webauthn) over this.

For instructions on setting up Yubikey OTP, please visit the official ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden documentation**](https://bitwarden.com/help/setup-two-step-login-yubikey/).

### <mark style="color:blue;">DUO</mark>

This method requires you to register an account with ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**DUO**](https://signup.duo.com/).

DUO is a secure method for two-step authentication, however, ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**FIDO2 / Webauthn**](#fido2-webauthn) is far less complicated according to some people. This is all based on your own perspective.

For detailed instructions on setting up DUO, visit the official ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden documentation**](https://bitwarden.com/help/setup-two-step-login-duo/).

### <mark style="color:blue;">FIDO2 WebAuthn</mark>

This is the most recommended method for two-step login. It is secure, and is the most recent FIDO protocol. it is made up of two components:

* **CTAP**: Client to Authenticator Protocol&#x20;
* **WebAuthn**: WC3 Web Authentication

For detailed instructions on setting up FIDO2 WebAuthn, visit the official ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**Bitwarden documentation**](https://bitwarden.com/help/setup-two-step-login-fido/).

If you've like to learn about FIDO2, head over to our ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**FIDO2 introduction**](https://yubico.gitbook.io/yubikey5/fido2/).

### <mark style="color:blue;">FIDO U2F Security Key</mark>

This method is now **deprecated** and only available on older version of Vaultwarden. You should not use this. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**FIDO2 / WebAuthn**](#fido2-webauthn) is far superior and more recent technologies.

### <mark style="color:blue;">Email</mark>

Allows you to access your Bitwarden account by confirming your login via an email. This is not secure compared to other providers.

{% hint style="warning" %}
Two-step login via email is not recommended if you are using ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [**login with SSO**](https://bitwarden.com/help/using-sso/)**,** as using multiple methods will cause errors. Consider setting up ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [two-step login via a free authenticator](https://bitwarden.com/help/setup-two-step-login-authenticator/) instead.
{% endhint %}

## <mark style="color:red;">❊ Priority</mark>

If you decide to enable multiple providers for two-step authentication, please be aware that Bitwarden will determine which one to use based on priority that is internally programmed. The following is the order of priority:

1. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Duo (Organizations)](#duo)
2. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [FIDO2 WebAuthn](#fido2-webauthn)
3. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [YubiKey OTP](#yubikey-otp-security-key)
4. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Duo (Individual)](#duo)
5. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Authenticator App](#authenticator-app)
6. ![](https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20\(1\).png?alt=media\&token=8ac71312-243b-4852-999d-74eaa595ec54) [Email](#email)

## <mark style="color:red;">❊ Master Password</mark>

Your master password is the main password you use to login to your Bitwarden account. It is what gives access to your vault all-together.&#x20;

Ensure that your master password is completely different from any other password you have used for any website or service. It must be something that cannot be leaked, and it must be strong.

If you use the same password for both Bitwarden and a website such as "Kinky Midget Kingdom" and the website ends up suffering a data breach, your Bitwarden vault password is potentially at risk because of a website that is completely unrelated to Bitwarden due to carelessness on the companies' part. If the password on the website is not stored using a hash, or is stored in the website's database as a plain-text field, the password will now be available for all to see and it is only a matter of time before they match your email address and password to any other service that you may use the same credentials for.

Should you use the same password for multiple layers of security, this defeats the purpose of those layers.
