{% extends "base.html" %} {% block content %}
{{ icon('shield') }}
Secure your account

Set up your authenticator

Scan this QR code with Bitwarden or another authenticator that supports SHA-256, then enter its current 6-digit code below.

Can't scan? Set up manually

In Bitwarden, paste the complete setup URI into Authenticator key (TOTP). A setup key alone defaults to SHA-1 and will produce codes that PKIMaster cannot accept.

Copy the entire URI, including all parameters. If your app only accepts a setup key, use these settings:

Account
{{ current_user['username'] }} — {{ settings.organization }}
Setup key
{{ secret }}
Algorithm
SHA-256
Digits / interval
6 digits / 30 seconds

Store a protected backup of this setup key before continuing. There are no recovery codes or automated MFA resets in this version. A password reset does not remove the authenticator requirement.

Enrollment expires after 10 minutes. The QR code and setup details are shown only until enrollment is completed. Keep your device and server clocks synchronized.

{% endblock %}