@MFKDGAF I guess @triceps-tamale is talking about FIDO2 WebAuthn 2FA for Bitwarden. (though just speaking of “logging in with a security key” is open for interpretation as it could also mean “login with passkey”)
@triceps-tamale I guess @MFKDGAF is right, that the current mobile apps do have passkey support, but the new native mobile apps that are in Beta now, don’t have passkey support at the moment. (the blog post @MFKDGAF linked shows that)
Passkey autofill is not yet implemented in the native mobile apps. This means that you cannot use the passkeys stored in Bitwarden to log into apps and websites using the native apps yet.
@triceps-tamale are you talking about this, or about using your security key for 2FA when logging into the Bitwarden app?
Thanks for the clarification @Micah_Edelblut and @Nail1684, indeed my post was ambiguous.
I was specifically talking about logging in to Bitwarden in the new beta native Android app using a FIDO2 security key.
I basically want to ditch all other means of 2FA from my Bitwarden account and have security keys as the only option. It works on desktop browser, but in the new Android app it doesn’t work for me.
Hey, it seems clear now what you mean, but for the sake of “clear expression of what one means”… as you just wrote that here it still can mean two things:
FIDO2 WebAuthn as 2FA for Bitwarden can be done via a security key (like a YubiKey) as the second step for the login process to Bitwarden.
Creating a passkey for the Bitwarden account (“login with passkeys”) is also “FIDO2” - and if you created that passkey on your security key, that would also be “using a FIDO2 security key for login”.
Right, I am trying to use security key (Yubikey) as a 2FA to log in to my Bitwarden account. I actually haven’t tried “login with passkeys” yet but will give it a try
Yeah, and now you know that “logging in with FIDO2 security key” can actually mean both - as both is FIDO2 and both can be used with security keys and both are (at least part of) “logging in”.
“Login with passkeys” is great - but be aware, that it still - unfortunately - only works for the web vault.
PS: I just added the “as 2FA” in the title of the thread…
Not directly related to the topic of this thread but I actually just tried passwordless login registration in webvault with my two different security keys
Yubico Security Key NFC - U2F and FIDO2
FEITIAN ePass K9
I was able to register the Yubico key but not the Feitian key. It is giving me “Your device can’t be used with this site” error
@triceps-tamale Hey, great question - and I don’t know the FEITIAN keys, so I have no immediate answer. But since that goes further away from the “Beta” and 2FA questions/problems, I recommend using the same post to open a new thread as “ask the community”.
On Android 14 Pixel 5
During login with FIDO2 key I’m stuck in the loop - credentials then key.
After master password provided WebAuthn appears. After the button Authenticate WebAuthn is pressed and the NFC key provided it asks to return back to the application. After that it shows the error.
Same account, same key on iPad OS works as expected from the first try.