After adding yubikey, that’ll be an optional login everywhere?

I’ve held off using my yubikey because:

  1. it could help against a keylogger on macOS that doesn’t have fingerprint login, but if there’s a keylogger it’s already too late?

  2. I’m worried if I add the yubikey, I’ll be forced to use it and could make a mistake. Can I confirm that once added, the yubikey is optional and that I’ll still be able to use totp google authenticator?

  3. although it’s nfc, I think it would slow me down on iOS and not add much security anyway

Do you find a hardware key more useful than totp codes for your Bitwarden login?

I find my Yubikey easier (and it’s more secure) than using a TOTP code (though my TOTP codes come from the Yubikey authenticator for sites or applications where direct hardware keys aren’t supported for login).

You can enable or disable different 2FA methods independently. So if you leave your TOTP authenticator enabled as a two-step login method for Bitwarden, and additionally enable the use of a Yubikey as a 2FA passkey, you will be able to use either method. The only wrinkle is that the most secure 2FA method (the Yubikey) is what you are initially prompted for; if you then prefer to supply a TOTP code, you need to first click the “Use another two-step login method” link at the bottom of the 2FA prompt, and then select the TOTP authenticator method from the presented list of alternative methods.

@kinship4465 Sidenote: I changed the category of your topic from “Authenticator” to “Password Manager”.

The “Authenticator” category is mainly for the TOTP authenticator app from Bitwarden, but also for the integrated authenticator of the password manager.

Your question seems to be more about 2FA for the Bitwarden account, so I think the “Password Manager” category fits better.