Guide

Bitwarden TOTP codes in your Mac menu bar

Four ways to get your Bitwarden two-step codes on a Mac, from the simplest to the fastest.

Bitwarden can hold the keys for your two-step codes and make the six-digit codes for you. On a Mac there are four ways to get at them. The first three need nothing but Bitwarden.

Bitwarden stores authenticator keys on every plan. Showing the codes needs Premium or a paid organisation plan, according to Bitwarden’s help page.

At a glance

ExtensionDesktop appCommand lineCodeCatch
Works inThe browserAny appTerminalAny app
Steps per codeNone, it copies as it fillsOpen app, find login, copyType a commandShortcut, type a name, Return
Where the keys liveBitwardenBitwardenBitwardenBitwarden and your Mac’s Keychain
Works offlineIf the vault is unlockedIf the vault is unlockedIf the vault is unlockedYes

How these codes work

When you turn on two-step sign-in, the service gives you a secret key, usually as a QR code. An authenticator mixes that key with the current time and gets a six-digit code that changes every 30 seconds. Anything that holds the key can make the code: your phone, Bitwarden, or CodeCatch.

1. The browser extension

This is the least work. When the extension fills your username and password, it also copies the code. Press ⌘V in the code field.

If nothing is copied, open the extension and check Settings → Autofill → Copy TOTP automatically. Bitwarden says it is on by default.

2. The desktop app

Open the login in the Bitwarden app. The code is shown inside the item, counting down. Click it to copy.

This works for sign-ins outside the browser, but it means switching apps and searching each time.

3. The command line

With the Bitwarden CLI installed and unlocked:

bw get totp github.com

It prints the current code. Useful in scripts, less so when a code expires in 30 seconds.

4. The menu bar, with CodeCatch

CodeCatch puts your Bitwarden codes in the menu bar next to the codes you get by text and email. Press ⌃⌥⌘F, type a name, press Return, and the code is copied.

  1. Install the Bitwarden CLI: brew install bitwarden-cli
  2. Sign in once in Terminal: bw login
  3. In CodeCatch, open Settings → Sources → Bitwarden → Set Up… It checks each step for you.
  4. Enter your master password, review the list of logins, and save.

After you change two-step logins in Bitwarden, use Refresh… in the same place.

Once it is set up:

  • Search by service, account or site.
  • Pin the logins you use most, so they sit at the top.
  • See the time left on each code before it changes.
  • Steam codes work too.

If setup gets stuck

  • “bw: command not found”. The Bitwarden CLI is not installed. Run brew install bitwarden-cli, or get it from Bitwarden’s site.
  • “You are not logged in”. Run bw login in Terminal. It also handles your two-step login for Bitwarden itself.
  • Wrong server. If your account is on bitwarden.eu, pick it in the server step. Switching needs bw logout first.
  • Changed something in Bitwarden? Use Refresh… You see what was added, changed and removed before it is saved.

What CodeCatch keeps, and the trade-off

  • It saves each login’s name, username, site and authenticator key in your Mac’s login Keychain.
  • Codes are made on your Mac. No connection is needed.
  • Codes stay hidden until you unlock with Touch ID or your Mac password, and lock again on sleep.
  • Remove Saved Import deletes the saved keys.

The trade-off is plain: a copy of your authenticator keys now lives on this Mac, outside Bitwarden. If you would rather keep them only in your vault, use one of the first three ways.

Which one to use

  • Mostly in the browser: the extension.
  • Now and then, anywhere: the desktop app.
  • In scripts: the command line.
  • All day, in any app, with your text and email codes in one place: CodeCatch.

Questions

Does CodeCatch save my Bitwarden master password?

No. It is passed once to Bitwarden’s own command-line tool to unlock the vault for the import, and it is not kept. The vault is locked again afterwards.

Do the codes work without an internet connection?

Yes. A code is worked out from the saved key and the current time, on your Mac. Nothing is looked up online.

Is it safe to keep codes next to my passwords?

It is a trade-off. Keeping both in Bitwarden is convenient, but someone who gets into your vault gets both. Many people keep their most important accounts, such as email and banking, in a separate authenticator and use Bitwarden for the rest.

Why is the code different from the one on my phone?

Codes depend on the time. If your Mac’s clock is off, the code is wrong. Turn on Set time and date automatically in System Settings → General → Date & Time.

A login is missing from CodeCatch. Why?

Only logins with an authenticator key in Bitwarden are imported. Add the key to the login in Bitwarden, then use Refresh… in CodeCatch.

I use Bitwarden’s EU server. Does it work?

Yes. The setup checklist has a server step for bitwarden.com or bitwarden.eu. Switching server needs bw logout first.

CodeCatch app icon

Try CodeCatch.

Your next code, ready to paste.

macOS 15 or later · Apple silicon and Intel