Webroot account, keycode, devices and transfer guide
Webroot has more than one account generation, and a retail keycode may exist without an online account at all. Start with the purchase route, keep the account password separate from the product keycode, and verify both the device and portal after moving protection.

Fast route: use current My Account for a direct purchase after March 22, 2022 or a migrated subscription; use the legacy identity console for an older account; use the receipt or box card when a retailer never created an account. A Webroot keycode is a 20-character license—not the portal password or legacy personal security code.
Choose the correct Webroot account route
Don't begin by retrying the same password on every page named “Webroot login.” Start with when and where the subscription was purchased. Webroot's current account registration and login guide says direct purchases made after March 22, 2022 are already in the newer My Account environment, while retail licenses don't always create an online account.
| Your situation | Starting route | Credential to expect | Don't assume |
|---|---|---|---|
| Direct purchase after March 22, 2022 or migrated account | Current Webroot + Carbonite My Account | Email, password and optional phone verification | That a legacy security code is the keycode |
| Account created before March 22, 2022 | Legacy SecureAnywhere identity console | Email, password and selected personal-security-code characters | That current password reset controls the old console |
| Amazon, Best Buy, Walmart or other retailer | Receipt, email or box card first | 20-character product keycode | That checkout automatically created a Webroot account |
| Android, iPhone or iPad application | Current mobile sign-in path | Account email and password | That the desktop keycode replaces mobile login |
Official links sometimes display `account.webroot.com`, `myaccount.webroot.com` or a Carbonite account domain as the routed entry. That's a consequence of the shared Webroot/Carbonite account environment, not permission to trust any similarly named domain. Start from Webroot support or type the verified domain rather than following a sponsored “support” result.
Account password, keycode and security code are three different things
The account password authenticates the person. The product keycode identifies a SecureAnywhere license and consists of 20 alphanumeric characters. An older SecureAnywhere web account can add a third credential: a personal security code whose requested characters change at login. Confusing them produces convincing but meaningless “invalid” errors.
On Windows or Mac, SecureAnywhere normally asks for the keycode during activation. Mobile applications normally ask for the account email and password. The legacy website can ask for selected characters from the personal security code after the password; it's never asking the user to paste selected characters from the product license.
Keep all three out of screenshots and public support posts. A legitimate helper can diagnose the route from the account generation, purchase channel and masked last characters; they don't need a full keycode, password or one-time verification code posted in a forum.
Sign in to current Webroot My Account and recover the password
For a newer or migrated subscription, begin at account.webroot.com. Webroot's current sign-in documentation routes through the shared account environment, where the email address identifies the subscription and optional two-step verification sends a code to the enrolled phone. The portal provides subscriptions, payment options, downloads and feature access.
If the password is lost, use Webroot's current password-reset flow. Enter the account email, check the inbox and junk folder for a Carbonite-domain reset message, then verify by phone code or security questions according to the account setup. A Carbonite sender is expected here because the account infrastructure is shared; an attachment or request for remote access isn't.
No reset message can mean the email provider filtered it, but it can also mean no account exists under that address. That's especially plausible for a retail purchase. Search the purchase records before creating several accounts with slightly different email addresses, because ownership becomes harder to untangle when each account contains only part of the evidence.
Use the legacy SecureAnywhere console for an older account
An account created before March 22, 2022 may still use the legacy SecureAnywhere identity website. Webroot's legacy login guide asks for the registered email and password, then selected characters from the personal security code. Accounts with several consoles prompt the user to choose one before showing devices and keycodes.
Use the legacy recovery route rather than forcing the new My Account reset page. Webroot warns that four failed legacy login attempts lock the account for one hour. Security-question answers are case-sensitive, and the reset email can update the password or personal security code depending on which recovery option was chosen.
The personal security code has its own official reset procedure and length rules; it isn't the 20-character license. If the legacy account has already been migrated, follow the current account route instead of trying to recreate the old console. Support evidence should include the registered email, account age and exact message, never the unmasked credentials.
Find the Webroot keycode without exposing it
If SecureAnywhere still opens on a computer, select My Account to view the active keycode and subscription state. The portal can also show the product, keycode, installed computers, expiration and device capacity. Webroot's retail keycode guide points to the instruction card in a physical box, purchase email, receipt or trial email.
For a direct purchase, search for the latest invoice or renewal email rather than the oldest Webroot message in the mailbox. A renewal or replacement purchase can issue a different keycode, which explains why an apparently valid code still shows expired in the installed application. Record the seller, purchase date, product and masked last four characters alongside the code in a password manager.
Don't publish the whole keycode to prove ownership. It's a transferable activation credential within its device limit. When submitting a support ticket, use the protected form reached from Webroot's official support site and provide only the information that form explicitly requests.
Add a keycode to the account only after confirming ownership
In the current account, open Downloads and use Add a Keycode when the subscription is absent. Webroot's current add-keycode instructions say that the email used for a Webroot.com purchase must match the email on the online account. That rule prevents a valid code from being casually attached to an unrelated profile.
Legacy accounts can manage multiple keycodes and consoles, and an installed device reports to the website after a scan. Don't add the same code to speculative accounts merely to see which one accepts it. Preserve the purchase email and let official support resolve an email mismatch when ownership is genuine.
Adding a keycode to a portal and activating an endpoint are related but separate events. The computer must use the correct code, finish a scan and report status before it appears as expected. Our Webroot installation guide covers the product-specific Windows, Mac and mobile activation paths.
Read device capacity before removing anything
The Keycodes or Security area shows the subscription and covered computers. Compare the licensed capacity with active physical devices, not merely the number of rows: renamed, replaced or offline computers can remain visible, and a new PC may take up to 15 minutes after its first scan to report into the portal.
Device count and feature count are different. An Essentials license may cover one, three or five devices; Premium and Total Protection have other individual/family capacities. Our plan comparison maps those current limits without assuming that every service follows the antivirus seat count.
Create a simple inventory before a transfer: device name, owner, operating system, last use, installed Webroot product and whether the machine is still accessible. That list prevents removing a similarly named family laptop and makes the irreversible remote-uninstall warning meaningful.
Remove Device and Hide Device don't mean the same thing
Webroot's current device-removal instructions say current Essentials and Total Protection licenses can expose Remove Device. That control sends a command for Webroot to uninstall on the selected endpoint. If the machine is offline, the command waits until it reconnects; support can't stop the uninstall command after it has been issued.
Confirm the exact computer before clicking. A family may have several nearly identical device names, and the currently offline machine can execute the queued removal weeks later. When the old device is available, a normal local uninstall followed by portal cleanup gives the owner immediate visual confirmation.
Other subscription types may expose Hide rather than Remove. Hiding clears the normal console view, but it isn't proof that software disappeared from the endpoint or that every license counter changed. Verify locally and then recheck the portal capacity instead of treating a cleaner list as the security outcome.
Transfer Webroot to a new computer in six controlled steps
A transfer preserves the subscription; it doesn't clone the old application state. Webroot requires an active license and capacity within the device limit. Keep the old computer protected until the account, keycode and new installer are ready, unless the old machine is lost or compromised.
Confirm the subscription and device capacity
Record the exact Webroot product, expiration state and number of licensed devices. Make sure the subscription is active and determine whether an unused seat exists before changing the old computer.
Open the correct account and locate the keycode
Use the current My Account route for a direct post-March 22, 2022 purchase or migrated account, the legacy SecureAnywhere console for an older account, or the retailer receipt and installation card when no portal account was created.
Uninstall Webroot from the old computer
Use the normal local uninstaller while the old computer is available. Keep the account and keycode records, and log out of or uninstall Secure VPN separately because VPN devices don't appear in the antivirus device list.
Remove or hide the old device in the portal
Use Remove Device when the current subscription offers it, understanding that this sends an uninstall command that can't be cancelled. A legacy Hide action only changes the console view and isn't proof of remote uninstallation.
Install the correct Webroot product on the new computer
Download SecureAnywhere or Total Protection from the verified route for the subscription. Activate SecureAnywhere with the 20-character keycode or follow the account-linked Total Protection installation flow.
Finish the scan and verify both device and account
Complete the initial scan, confirm the new computer shows active protection and allow up to 15 minutes for it to appear in the account portal. Recheck browser protection and any separately licensed VPN session.

If the old computer is lost or stolen, change the account password, review two-step verification and remove the known endpoint from the portal as the subscription allows. Don't wait for physical access that will never return. The replacement still needs the correct installer and an independent post-install verification.
VPN and mobile devices don't follow the same device list
Webroot's transfer guide says Secure VPN and the older WiFi Security devices aren't listed in the antivirus My Account portal. Check the old physical device, log out of or uninstall the VPN application, then activate the replacement within the VPN's own device capacity. Removing an antivirus computer doesn't automatically release or terminate that separate VPN session.
Mobile security also authenticates differently from desktop SecureAnywhere. Android and iOS normally use the account email and password, while Windows and Mac SecureAnywhere use the keycode. A phone can therefore be signed in correctly even when it never appears beside the desktop endpoints in the way an old console guide suggests.
Inventory services, not just hardware: antivirus endpoint, mobile app, browser extension, VPN, password manager and identity portal. Total Protection bundles several of them, but one Remove Device control should never be assumed to log out every related application.
Change a SecureAnywhere keycode; reinstall Total Protection
Webroot's new-keycode guide applies to SecureAnywhere on Windows and Mac. Open My Account or Update Keycode, enter the new 20-character code, activate it and allow the scan to finish. The new code should then appear inside the application.
Total Protection is the important exception. Webroot says it doesn't expose the same keycode-change function and must be reinstalled to apply a new code. Use the installer assigned to the new entitlement rather than placing a SecureAnywhere build over Total Protection and assuming the portal will reconcile it.
Before replacing a code, compare product, device capacity and remaining term. A new keycode may represent a separate subscription rather than an extension of the existing one. Our dated Webroot pricing and renewal guide explains why renewal, repurchase and plan switch aren't interchangeable billing events.
Fix a wrong expiration date or renewal prompt methodically
First compare the keycode on the current receipt with the one shown under My Account in SecureAnywhere. Webroot says the application can report expired when it references the wrong code. If the codes differ, activate the new code; if they match, check for software updates and complete a fresh scan so the endpoint reports status.
Allow for synchronization without waiting indefinitely. Webroot's paid-but-still-prompted guidance says a normal renewal can take up to 24 hours to appear on the computer. If more than 24 hours pass after a confirmed payment and update/scan, preserve the receipt and open an official ticket.
A third-party-provided subscription can show only “Active” instead of days remaining. Webroot directs the user to that provider for the exact expiration record. Total Protection Backup + Restore has another narrow case: after restart or a recent renewal, its subscription-date data can take a few hours to reconnect and update even when the main entitlement is valid.
Receipt and app codes differ
Activate the new keycode in SecureAnywhere. For Total Protection, reinstall using the installer tied to the new entitlement.
Codes match
Wait within the documented window, check application updates, finish a scan and verify the portal. Escalate with the receipt after the window expires.
Retail, Best Buy and Geek Squad subscriptions need their own trail
A store purchase may provide a box card, receipt, email delivery or digital-library entry without creating a Webroot password. That isn't evidence the keycode is invalid. Use Webroot's official retail locator guidance and the retailer's signed-in order history before attempting current or legacy password recovery.
Best Buy has a dedicated Webroot download route documented in Webroot's Best Buy installation article. Retrieve the keycode from the Best Buy account, receipt or digital library and keep proof of purchase. Don't call a number copied from an unofficial “Webroot setup” page in search results.
Third-party billing also changes where expiration and cancellation evidence lives. If SecureAnywhere displays only Active, the provider may own the remaining-time record. Keep the seller, order ID and renewal terms with the masked keycode so future transfers don't begin with an account Webroot never created.
Secure the Webroot account before it controls more devices
Use a unique password and enable Webroot's two-factor authentication on the current account. Webroot supports phone verification by text or call. Update security questions with answers stored in a password manager and verify the recovery email and phone before decommissioning an old device.
Treat a keycode like a license credential, not a serial number suitable for screenshots. Treat a one-time phone code like a password. An unsolicited helper who asks for both, requests remote control or insists on a payment to “unlock” a valid subscription has stepped outside the official self-service and ticket workflow.
Review devices after a transfer and after any lost-computer incident. Remove only the verified target, check for unknown subscriptions or downloads and retain purchase evidence offline. Account hygiene is part of endpoint protection because the portal can distribute installers, expose entitlements and send device commands.
Webroot account, keycode and device-transfer FAQ
What is the correct Webroot account login?
For a direct Webroot purchase after March 22, 2022 or a migrated account, use the current Webroot + Carbonite My Account route reached through account.webroot.com. A legacy account created before that date may still use the SecureAnywhere identity console. Retail purchases don't always create an online account, so a valid keycode can exist even when password reset finds no account.
Is my Webroot keycode the same as my account password?
No. The keycode is the 20-character product license used to activate SecureAnywhere on a PC or Mac. The account password signs in to the portal or mobile application. Older SecureAnywhere portal accounts can also have a separate personal security code whose selected characters are requested during login.
Where can I find my Webroot keycode?
Check My Account inside the installed SecureAnywhere application, the Webroot account portal, the purchase or renewal email, a retailer receipt, or the installation card inside a physical box. Copy the code rather than retyping it, but don't place it in a public screenshot, support forum post or shared document.
Can I add a Webroot keycode to a different email account?
Webroot's current add-keycode instructions say the email used for a Webroot.com purchase must match the email on the online account. A retailer-issued keycode or legacy console can follow a different registration path. Don't create several speculative accounts; preserve the receipt and ask official support to resolve a genuine ownership mismatch.
How do I transfer Webroot to a new computer?
Confirm the subscription is active and has capacity, locate the account and keycode, uninstall Webroot from the old computer, remove or hide the old entry as the portal allows, install the correct product on the new computer and finish a scan. A new PC can take up to 15 minutes after that scan to appear in the portal.
Does Remove Device free a Webroot license immediately?
Remove Device is more than a visual cleanup: Webroot says it issues a command to uninstall on the device when that device is online. If it's offline, the command waits for a later connection, and support can't cancel it. Confirm the exact target before using the control and then verify the account capacity rather than assuming an instant seat change.
Why can I only hide a Webroot device?
Webroot says current Essentials and Total Protection licenses can offer Remove Device, while other subscription types may expose only Hide. Hiding removes the entry from the normal console view; it isn't evidence that Webroot was uninstalled on the computer. Remove the software locally when the device is still available.
Why does Webroot still say expired after I renewed?
A renewal can take up to 24 hours to reach SecureAnywhere. Compare the receipt keycode with the code shown under My Account: if they differ, activate the new code. If they match, check for application updates and complete a scan. A third-party subscription may show only Active, with the provider retaining the exact expiration date.
Can I enter a new keycode in Webroot Total Protection?
Not through the same Update Keycode control used by SecureAnywhere. Webroot's current support article says a new keycode can be entered in SecureAnywhere on Windows or Mac, but Total Protection must be reinstalled to apply a new keycode. Use the installer assigned to the new entitlement.
Why are my Webroot VPN devices missing from My Account?
Webroot says Secure VPN and the older WiFi Security device sessions aren't listed in the antivirus My Account device list. Check the physical devices, log out of or uninstall the VPN on the old one, then activate it on the replacement according to the VPN device limit. Removing an antivirus computer entry doesn't manage that separate session.
Bottom line: route first, move second, verify last
Identify whether the subscription belongs to current My Account, the legacy console or a retailer receipt before touching the old computer. Keep the account password, 20-character keycode and legacy personal security code separate, then confirm the licensed capacity and exact device target.
Transfer protection in a controlled sequence and respect the product boundary: SecureAnywhere can accept a replacement keycode, while Total Protection requires reinstalling for a new one. Finish with a scan and a portal check; a clean device list or successful installer alone doesn't prove the replacement is licensed and protected.