We're on Product Hunt today! Leave a comment

Bybit authenticator app

Bybit calls it Google Authenticator, but its 2FA uses standard codes that any authenticator app produces — including one in your browser. Go to Account → Security, click “Settings” next to Google Two Factor Authentication, and scan the QR code from the screen with the Authenticator extension.

Bybit urges every trader to keep 2FA bound at all times, and for good reason: the code is what Bybit asks for when you withdraw and when you create an API key — the two ways a stolen password turns into emptied funds or a bot trading on your account. With the authenticator bound, a password alone is not enough for either.

Bind Google Authenticator on Bybit

Bybit shows the Recovery Key Phrase only once, while you bind — write it down before you click “Confirm”. Bybit’s help names Google Authenticator, but its troubleshooting page speaks of codes from “Google Authenticator or other 2FA apps”, and the extension reads the same QR code.

  1. Sign in at bybit.com on your computer.
  2. Hover over the “Profile” icon and click “Account” → “Security”.
  3. Click “Settings” next to “Google Two Factor Authentication” — or “Set up Google Authenticator” on the Bybit Protect banner.
  4. Enter the verification code Bybit sends to your registered email address or mobile number.
  5. When Bybit shows a QR code, leave that page open and add it to the extension as described below — then write down the Recovery Key Phrase, enter the 6-digit code from the extension and click “Confirm”.
Bybit’s own instructions

Add Bybit to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Bybit page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Bybit and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Bybit confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Bybit’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Write down your Bybit Recovery Key Phrase

The Recovery Key Phrase (RKP) is shown once, at binding, as a QR code or a string of letters and numbers — and Bybit does not keep a copy. It is the key your codes are made from: typed into any authenticator as the key, it brings the codes back on a new device. Bybit suggests encrypted storage or another secured device; keeping it on paper, away from this computer, works just as well. Without the RKP, a lost authenticator has to be unbound through Bybit’s verification, and withdrawals stop for 24 hours afterwards.

The code is not accepted?

Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.

Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Do I need Google Authenticator for Bybit?
No. Bybit’s steps name Google Authenticator, but the codes are the standard time-based kind (TOTP), and Bybit’s own troubleshooting mentions “other 2FA apps”. Any authenticator that scans the QR code works — including the Authenticator extension, which reads it straight off the Bybit page in Chrome, so no phone is needed.
How do I move Bybit 2FA to a new phone?
With the old phone, Google Authenticator can export it: “Transfer accounts” → “Export accounts”, then scan that QR code on the new phone. With your Recovery Key Phrase, add an account manually in the new app and enter the RKP as the key. If you have neither, at sign-in click “Having problems with verification” → “Google Authenticator not working” → “Confirm”, then enter the code Bybit sends to your email and mobile number; Bybit may ask for more by email, with support replying in 1–3 working days. Bind a new authenticator right away.
Is 2FA required for Bybit withdrawals and API keys?
Bybit asks for the 2FA code when you make a withdrawal, and creating an API key — possible only on the Bybit website, not in the app — asks for your Google Authenticator code before the key is made. Disabling or resetting the authenticator locks withdrawals and P2P transactions for 24 hours, so set it up before you need to move funds.
Why does Bybit say “Invalid Code”?
Check that the code comes from the entry for Bybit with your registered email or phone number, not another account. If the QR code changed because the setup page was reloaded or opened again, add the one on the screen now and use the newest entry. If the authenticator was bound in another app, the codes come from that app — and Bybit’s last suggestion is to unbind and bind again.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free