Skip to content

Adding Your First Account

An account in Private Authenticator is one website or app that you get codes for, such as your email, a game, a bank or a social network. This page shows the three ways to add one. The first is by far the most common.

Scanning a QR code

  1. On the website or app you want to protect, find its two-step verification setting. It is usually under Security, Sign-in, Password or Two-factor authentication. Choose the option for an authenticator app. The site shows a square barcode, a QR code.
  2. In Private Authenticator, tap the orange + at the top right (or New in the menu). The camera opens. The first time, iOS asks whether the app may use the camera; tap Allow.
  3. Point the camera at the QR code. As soon as it reads it, the New Item form opens with the name and description filled in from the code, and the words QR code scanned. The setup key inside the code is saved securely without ever being shown.
  4. Give the account a friendly name if the one filled in isn't clear (the form takes whatever you type), add a description if it helps, for example the email address you use there, and tap Save.
  5. Back on the website, it will ask you to type the current code to prove the scan worked. Tap your new account in Private Authenticator, confirm with Face ID or Touch ID, and type the six digits you see. Signing In with a Code explains that screen.

[Screenshot: the camera screen with the white scanning frame and the two buttons below it]

Keep the website's backup codes too

Most websites also offer a short list of one-time backup codes when you turn on two-step verification. Save them somewhere safe. They are your way back in if you ever lose your phone and your Private Authenticator backup. This app can't replace them.

The QR code is on this same phone

If the website is open on the iPhone you're holding, the camera can't see its own screen. Take a screenshot of the QR code (press the side button and volume-up together), then in the camera screen tap Choose Photo Instead and pick the screenshot. The app reads the QR code from the picture and carries on as if you had scanned it. You can delete the screenshot afterwards; it contains your setup key.

Typing a setup key instead

Some sites offer a text key instead of, or as well as, a QR code, usually behind a link such as can't scan the code? or enter the key manually. The key is a run of capital letters and digits.

  1. Tap +, then Enter Manually Instead at the bottom of the camera screen.
  2. Type a name and, if you like, a description.
  3. Type or paste the key into the Setup Key field. Spaces don't matter.
  4. Leave the Code Settings as they are unless the site tells you otherwise. Almost every site uses 6 digits, SHA-1 and 30 seconds, which is what the form starts with. A site that needs something different says so next to its key.
  5. Tap Save, then type the code the site asks for, as above.

[Screenshot: the New Item form for manual entry, showing the Setup Key field and the Code Settings section]

Steam Guard accounts are added this way too, with one difference in the settings. See Adding a Steam Account.

Some apps and password managers offer an add to authenticator link rather than a QR code. Tapping such a link opens Private Authenticator on the same New Item form, filled in from the link.

This works once you have told iOS which app should handle these links, because iOS sends them to the Passwords app unless you say otherwise. Open the iPhone's Settings app, then General → AutoFill & Passwords → Verification Codes → Set Up Codes In, and choose PrivAuth.

What you can change later

After saving, you can change an account's name, description and tags at any time. The setup key and the code settings are fixed; if a website gives you a new key, add it as a new account. Editing an Account has the details.


Continue to Adding a Steam Account, or skip to Signing In with a Code.