Authenticator codes
Last updated October 2, 2026
MoatKey can make the six- or eight-digit codes that websites ask for after your password. In a shared Castle, everyone sees the current code, so a login never waits on whoever has the phone. Codes are made on each person's own device.
Add an authenticator
When you add a login, choose + Add authenticator. For a login you already saved, open it and choose + Add shared authenticator.
Browser extension
- Paste the Setup key or authenticator link. On the website's QR screen, look for "can't scan?" or "enter key manually" to see the key.
- Or use the QR code itself: paste a screenshot (Ctrl+V), drop an image, or Choose image. It is read on your device. The extension can't use your camera.
Android app
- Scan QR with your camera, or pick an image From screenshot or From a file.
- Or type the key under Or enter the setup key.
MoatKey checks the key and shows Valid authenticator key. Choose Save authenticator (or Use this authenticator inside the add form). Most sites use the defaults; Advanced settings lets you change the algorithm, digits and how often the code changes, if the site says so.
Finish turning on two-factor at the website
After saving, enter the code MoatKey shows on the website, so the website knows the setup worked. If the website rejects it, remove the authenticator and try again.
Delete the QR image
Anyone who sees the QR image can make your codes. MoatKey doesn't keep the image. If you used a screenshot or file, delete it, and also empty Recently Deleted or the trash. Android app MoatKey reminds you with Delete the QR image now?
Use a code
- Browser extension On the website's code page, open the popup and choose Code to fill it, or copy it from the item.
- Android app Open the item and copy the code.
Not supported yet
Google Authenticator's "export accounts" QR code can't be imported in bulk. Add each account with its own setup key. Authenticator keys from a Bitwarden CSV are imported (see Import and export).