Two-factor authentication
Account
Lock down your account
Two-factor authentication (2FA) requires both your password and a one-time code from your phone to log in. Strongly recommended.
Setting it up
- Go to Dashboard → Two-factor auth.
- Install an authenticator app on your phone if you don't have one — Google Authenticator, Microsoft Authenticator, Authy, or 1Password all work.
- Scan the QR code shown on the page with the app.
- The app shows a 6-digit code that changes every 30 seconds.
- Enter the current code on the page to confirm.
- 2FA is now active.
Backup codes
After enabling, you'll see 10 backup codes. Save these somewhere safe — printed in a safe, in a password manager, anywhere except your phone. Each code works once if you ever lose access to your authenticator app.
Using 2FA
Next time you log in, after entering your password, you'll be asked for a 6-digit code. Open the authenticator app, enter the code, you're in.
Lost your phone?
Use one of your backup codes — works exactly like a 2FA code. Then immediately go to Two-factor auth and disable / re-enable to generate fresh codes for your new device.
Disabling 2FA
Dashboard → Two-factor auth → Disable. You'll need to enter your current password to confirm. Note that disabling makes your account significantly less secure.