How to disable two-step login?

I use bitwarden as the backup place, for my codes and passwords, if I lost my phone during traveling. This is the only reason to have bitwarden instead of Google Passwords. If I lose my phone, I lose also my access to my email and authenticator app and so also to bitwarden.

How to disable two-step login from bitwarden?

Welcome, @KPelto to the community! Here are the instructions for all-things two-step login, including disabling it.

If you keep your TOTP secret keys on your emergency sheet, it is a simple matter to install it into any authenticator app on your new phone and bootstrap your way back in. The advantage to this approach is that your vault does not need to permanently live with lesser security.

@KPelto Welcome to the forum!

I assume that you are aware that what you are proposing is extremely risky, and exposes your vault to access by unauthorized parties if your master password is ever leaked by inadvertent disclosure (including “social engineering” attacks), observation of password entry (“should surfing” attacks), phishing attacks, attacker-in-the-middle schemes, and/or info-stealing malware (including, but not limited to key loggers).

To disable Two-Step Login, first log in to the Web Vault (vault.bitwarden.com or vault.bitwarden.eu), navigate to Settings > Security, and then open the “Two-Step Login” tab. In the list of “Providers”, look for any two-step login methods that have a green check mark :check_mark:, and click the Manage button for those. You will now see “Remove” links for individual 2FA factors, as well as a Disable button to fully remove all 2FA factors in this “provider” category. Repeat for any other providers that have a green check mark.

A quicker alternative would be to get your Recovery Code, and to submit the code as described here — this immediately disables all of your two-step login methods, and also invalidates your recovery code for future use.

To solve your original problem, you would likely also need to disable New Device Verification, which you can do from the Web Vault by going to Settings > Account, and clicking on the button Turn off new device login protection.