{% extends "base.html" %} {% block content %}
{{ icon('shield') }}
Secure your account

{{ 'Replace your authenticator' if replacement else 'Set up your authenticator' }}

{% if replacement %}

Your current authenticator stays active until you verify the new one below. Completing this change signs out other sessions and replaces all recovery codes.

{% endif %}

Scan this QR code with Bitwarden or another authenticator that supports SHA-256, then enter its current 6-digit code below.

Can't scan? Set up manually

In Bitwarden, paste the complete setup URI into Authenticator key (TOTP). A setup key alone defaults to SHA-1 and will produce codes that PKIMaster cannot accept.

Copy the entire URI, including all parameters. If your app only accepts a setup key, use these settings:

Account
{{ current_user['username'] }} — {{ settings.organization }}
Setup key
{{ secret }}
Algorithm
SHA-256
Digits / interval
6 digits / 30 seconds

{{ 'Save the new recovery codes shown after verification.' if replacement else 'After activation, open Account security to create one-use recovery codes and store them in a safe place.' }} A password reset does not remove the authenticator requirement.

{% if replacement %}
{% endif %}

Enrollment expires after 10 minutes. The QR code and setup details are shown only until enrollment is completed. Keep your device and server clocks synchronized.

{% endblock %}