Documentation

User guide

Create an account, manage teams, view and add 2FA codes, invite members, follow the access log and billing.

Share Auth lets a team keep and share time-based authentication codes (TOTP) from a common vault.

This service shares 2FA codes used on other websites. Two-factor authentication for your own account is set up separately, in your profile.

Getting started

Create an account

  1. Open the Sign up page.
  2. Enter your name, your email address and a password.
  3. Once signed in, a personal team is ready for your secrets.

If you received an invitation, open the link in the email. Sign in, or create an account with the address the invitation was sent to.

Sign in

Enter your email address and your password. If 2FA protection is enabled on the account, then provide the code from your authenticator app or a recovery code.

If you have forgotten your password, use Forgot your password? on the sign-in page.

Understand the dashboard

The dashboard summarises the currently selected team:

  • number of secrets stored;
  • seats left on the plan;
  • number of members;
  • active plan.

It offers shortcuts to viewing codes and, depending on your role, to managing secrets.

Switch teams

The name of the active team appears in the navigation bar. Open that selector to move to another team.

Every secret, member, integration, limit and log shown depends on the active team. Check its name before copying or adding a code.

The Teams page also lets you select or manage your workspaces.

View a 2FA code

  1. Select the right team.
  2. Open Secrets.
  3. Search for an account by service, account name or description.
  4. Copy the code shown with the Copy button.

An indicator shows the time left. The code refreshes automatically when it expires.

Only ever share a code within the service it belongs to. Do not put it in an email, a conversation or a support ticket.

Add a 2FA account

This is available to owners, administrators and editors, within the limits of the team’s plan.

From Secrets, choose Add a secret. Two methods are offered.

Import a configuration

You can:

  • scan a QR code with the camera;
  • upload an image containing a QR code;
  • paste a URI starting with otpauth://;
  • import a Google Authenticator transfer QR code and select several accounts;
  • import a Bitwarden JSON or CSV export.

A custom name can be given before importing. For camera scanning, use an HTTPS connection and allow camera access in the browser.

A QR code or a configuration URI grants access to the same 2FA secret. Only import one from a source you trust, and do not keep a copy of it longer than needed.

Enter details by hand

Choose Manual entry, then fill in:

  • the account name;
  • an optional description;
  • the secret key provided by the service;
  • the algorithm, period and number of digits given by the provider.

Keep the default values when the provider does not specify particular parameters.

Edit or delete a secret

Open Secrets, then Manage secrets.

  • Owners, administrators and editors can edit a secret.
  • Only owners and administrators can delete one.

The edit page can also show a QR code, allowing the same account to be added to another authenticator app. Only display it on a device you trust.

Deletion is permanent. Check that the team no longer uses this account, or has another way in, before confirming.

Working as a team

Roles

Role View codes Add/edit Delete Manage the team
Owner yes yes yes yes
Administrator yes yes yes no
Editor yes yes no no
Viewer yes no no no

The owner also controls billing, invitations, ownership transfer and the access log.

Invite someone

The owner opens Teams, chooses Manage, then enters the person’s email address and role.

Pending invitations can be resent or withdrawn. An expired invitation has to be sent again. The recipient must accept it with the email address that was invited.

Change a role or remove a member

The owner can change a member’s role or remove them from the team settings. Removal cuts off their access to the shared codes immediately.

The owner cannot be removed. They must first transfer ownership to another member.

Leave, transfer or delete a team

  • A member can leave a shared team from their settings.
  • The owner can transfer the team to an existing member; they then become an administrator.
  • A personal team cannot be left, transferred or deleted.
  • Deleting a shared team permanently erases its secrets, members, invitations and integrations.

Protect your account

Open the menu bearing your name, then Profile.

Change your profile or password

You can change your name, your email address and your password. Use a long, unique password stored in a password manager.

Turn on two-factor authentication

  1. In your profile, choose Set up two-factor authentication.
  2. Scan the QR code with your authenticator app, or enter the key.
  3. Enter a code produced by the app.
  4. Confirm activation.
  5. Store the recovery codes somewhere safe and separate.

Each recovery code works only once. Generating new ones invalidates all the previous ones.

Delete your account

The danger zone in your profile permanently deletes the account after you confirm your password. This removes the resources you own and revokes API tokens. Transfer any teams that should be kept beforehand.

Messaging integrations

The site supports Slack, Discord and Microsoft Teams. An integration lets you ask for the list of accounts, or for a code, from the platform you configured.

Creating, editing, enabling and deleting an integration is reserved to the team owner. The creation page shows where to find the credentials needed, and provides the webhook URL to copy into the platform.

The stored token is never shown again. To replace it, enter a new one on the edit page. An integration can be disabled temporarily rather than deleted.

The detail page shows its recent activity. Access coming from bots is kept separate from the human access log.

Access log

The owner can open Access log to find out:

  • who listed or opened the vault;
  • which secret a code was given out for;
  • whether the access came from the website or the API;
  • when it happened, and from which IP address.

The log can be filtered by secret, action and channel. Commands run by bots appear in each integration’s activity.

Plans and billing

The owner opens Billing to see the team’s plan, its secret and member limits, and to move up to a higher plan.

Paid subscriptions are billed on the number of members in the team. The Stripe portal then handles the subscription and payment details.

When a limit is reached, the site prevents new secrets or members from being added. If the plan drops below current usage, some secrets may be temporarily hidden until usage comes down or the plan changes.

Language and mobile use

The language selector sits in the navigation bar. The interface adapts to mobile screens; open the main menu to reach teams, secrets, integrations and profile settings.

Good practice

  • Turn on 2FA for your own account.
  • Always choose the least privileged role that will do.
  • Check the active team before viewing or editing a secret.
  • Revoke access promptly for anyone leaving the team.
  • Never send a seed, a configuration QR code or a one-time code over messaging.
  • Review the access log and integration activity regularly.
  • Disable or delete integrations you no longer use.

If something goes wrong

  • The code is rejected: wait for it to refresh, check the team and account selected, then check that your device’s clock is correct.
  • The camera does not work: use HTTPS, allow the camera, or upload an image of the QR code.
  • A menu is missing: your role most likely does not allow that action; contact the team owner.
  • The limit is reached: delete a resource you no longer use, or ask the owner to change the plan.
  • You have lost your authenticator: use a recovery code. With no code available, contact the service administrator.

For a problem with a third-party account protected by a code from the vault, contact the owner of that account or the support team of the service concerned first.