Reviewed guide | 2026-09-30
Passkey or Authenticator App First: A Sensible Setup Order for Bitget
A practical order for registering a passkey and an authenticator app on a new Bitget account, so you add both credentials without locking yourself out halfway through setup.
Bitget | the reader's region | the reader's funding currency | independent comparison and evidence
When you open a new Bitget account, the security settings usually offer more than one way to prove it is you: a passkey tied to your device, and a time-based code from an authenticator app. Both are useful, and neither replaces the other. The confusion starts when people add one, log out, and then discover the second method cannot be registered without passing a check they no longer have. This guide walks through a sensible order for the first setup session, what to confirm at each step, what to write down, and when to stop and look something up in the help centre rather than guessing. It is written for readers anywhere who are setting up a personal account, and it assumes you are working on the device you actually plan to use. Treat every screen as something to read carefully rather than click through quickly, because the exact labels and available options can change and may differ between the web version and the app.
Why the order matters more than the choice
A passkey and an authenticator app both act as a second factor, but they behave differently when something goes wrong. A passkey lives on a device or in a password manager and is unlocked with your fingerprint, face or device PIN. An authenticator app generates rotating codes from a secret that is stored on the phone itself. If you register the passkey first and then lose access to that device before you have a working authenticator app, you may have to go through account recovery to get back in. If you register the authenticator app first and then set up the passkey, you keep a code generator available while you test the newer method.
The practical rule is simple: establish the method that is easiest to keep working independently of the other one, then add the second method while you are still logged in. Do not close the browser tab, log out or switch devices in the middle of the process. If a step asks you to confirm an email or a code, complete it before moving on, because some flows expect the confirmation to happen in the same session.
Before you start, decide where the authenticator secret will live. A dedicated authenticator app on your main phone is the common choice. Some password managers can also store time-based codes, which can be convenient but concentrates everything in one place. Whichever you pick, make sure you can open it on the same device you are using for Bitget, or on a second device that will be nearby.
Check the account settings area first to see which methods the platform currently offers and how they are labelled. The help centre explains the general flow, but the exact wording on screen is what you will be following, so read it as it appears rather than from memory.
Step one: register the authenticator app
Open the security or two-factor section of your account settings and choose the authenticator option. The platform will show a secret, usually as a QR code plus a text string you can type manually. Scan the QR code with your authenticator app, or enter the text string if scanning is not possible. Then type the current six-digit code from the app back into the platform to prove the pairing worked.
Before you confirm, check that the code in the app is actually changing. Watch it for one full cycle so you know the app is generating fresh codes rather than showing a frozen one. If the code is rejected, wait for the next cycle and try again rather than retyping the same digits. Repeated failures usually mean the phone clock is out of sync, which most authenticator apps let you correct in their own settings.
This is also the moment to deal with the recovery codes, if the platform offers them. Write them down on paper, or store them somewhere that is not the same phone that holds the authenticator app. A recovery code kept only in the app you might lose is not a recovery code. Keep the record offline and somewhere you will still have it months from now.
Once the authenticator is active, log out and log back in using it at least once. This confirms the method works end to end before you add anything else. If you skip this test, you may only discover a problem later, when a second method is already in play and the troubleshooting path is less obvious.
Step two: add the passkey while you are still signed in
With the authenticator working, go back to the security settings and register the passkey. The platform will ask your device or browser to create a credential, which normally means confirming with your fingerprint, face or device PIN. Follow the prompt on the device you intend to use as your main one, and give the passkey a recognisable name if the flow offers that option, so you can tell it apart later.
After the passkey is created, test it in a fresh session. Log out completely, then sign in and choose the passkey option when it is offered. If the passkey prompt appears and completes, you now have two independent ways in: the passkey on this device and the code from your authenticator app. If the passkey prompt does not appear, or the browser does not offer it, note what happened and check the help centre before removing or re-adding anything.
Resist the temptation to remove the authenticator app once the passkey works. The passkey is tied to a device, and devices get replaced, repaired or reset. Keeping the authenticator as a second route is what makes the setup resilient. If the security settings show a default or preferred method, decide deliberately which one you want to be prompted for first, and remember that changing that preference later is usually a small settings change rather than a full re-registration.
If the platform lets you register more than one passkey, consider adding a second one on a backup device you control, such as a spare phone or a hardware security key. Do this only after the first passkey is confirmed working, and label each one clearly so you can tell which is which during sign-in.
What to record and when to stop
Keep a short written record, separate from your devices, with the date you registered each method, the name you gave the passkey, and where the recovery codes are stored. Do not write down the authenticator secret in a place where it sits next to your password, and do not photograph recovery codes and leave them in your camera roll or cloud photos. The goal is a record that helps you remember what you set up, not a copy of the credentials themselves.
Stop and check the help centre if any of the following happens: the authenticator code is rejected several cycles in a row, the passkey prompt never appears on a device that should support it, the platform asks for a verification step you did not expect, or you are unsure whether a step completed. Do not keep retrying the same action, and do not start removing methods to see what happens. Removing a working method while the other one is unconfirmed is the most common way people lock themselves out during setup.
If you are setting up an account to use futures or other products, remember that security setup is separate from product access and eligibility checks. The futures documentation and the fee page cover those topics, and the account settings cover your credentials. Keep the questions separate so you do not confuse a security prompt with a product requirement.
Finally, revisit the setup after a device change. When you move to a new phone, register a new passkey and confirm the authenticator app is working there before you wipe or trade in the old device. A few minutes of checking at the right moment saves a much longer recovery process later.
Risk boundary: Bitget Independent Review
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.
Scenario checkpoint
- Register the authenticator app first and confirm a fresh six-digit code is accepted before adding anything else.
- Log out and log back in using the authenticator to prove the method works end to end.
- Write recovery codes on paper or store them offline, away from the phone that holds the authenticator app.
- Add the passkey while still signed in, then test it in a new session before changing any preferences.
- Keep the authenticator app active even after the passkey works, since a passkey is tied to one device.
- Record the registration dates, passkey names and recovery-code location in a note kept away from your devices.
Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.