How do I turn on two-factor authentication?
Short answerOpen Account in your dashboard, press "Set up 2FA" under Two-Factor Authentication, scan the QR code with an authenticator app and type the code it shows. Save the eight recovery codes you get, because they are shown only once.
Set up 2FA
Log in and open Account in the menu of your dashboard.
Scroll to Two-Factor Authentication and press "Set up 2FA".
Scan the QR code with an authenticator app such as Google Authenticator, Authy or 1Password. If you cannot scan it, type the code under it into the app by hand.
Type the six digit code your app shows into "Code from your app" and press "Confirm and turn on".
Save the eight recovery codes somewhere safe, away from your phone, and press "I saved these, done". Each code lets you in once if you lose the app.
What changes after you turn it on
Every login asks for your password and then for a current code from the app. The code is also asked when you delete your account.
Turning 2FA off needs the same proof as turning it on: your password and a current code. That way somebody who gets into an open session cannot switch it off quietly.
Lost your phone
Use one of your recovery codes at the login step instead of the app code. Each one works once. Once you are in, turn 2FA off and set it up again on your new phone, which gives you a fresh set of codes.
Questions people also ask
Which authenticator apps work?
Any app that reads a standard QR code for time based codes: Google Authenticator, Authy, 1Password, Microsoft Authenticator, Bitwarden and the like.
Does 2FA also protect my server panel?
Yes. The panel uses the same login, so nobody reaches your server without the second step either. People you invited as staff have their own login and can turn on 2FA for themselves.