Two-factor authentication
Add a second step to sign-in using an authenticator app, an emailed code or an SMS code.
Two-factor authentication (2FA) asks for a one-time code in addition to your password, so a stolen password alone cannot open your account. You turn it on in Account Settings, in the Security section.
Choose a method
| Method | How you receive the code | Good to know |
|---|---|---|
| Authenticator app | Generated on your phone by an app such as Google Authenticator or Authy | Works offline. Comes with one-time recovery codes. |
| A 6-digit code sent to your account email at each sign-in | Needs access to your inbox. | |
| SMS | A 6-digit code texted to your mobile number | Needs a verified phone number in your profile. |
Turn it on
- Open Account Settings and find the Two-factor authentication card in the Security section.
- Choose Enable 2FA and pick a method.
- For an authenticator app: scan the QR code with the app, or type the secret key in by hand. Save the recovery codes shown on the same screen. They are displayed only once.
- For email or SMS: we send a code straight away. Use Resend if it does not arrive.
- Enter the first code to confirm. Two-factor authentication only becomes active after this last step.
Signing in with 2FA
After your password, enter the current code. With email or SMS you can request a fresh code from the same screen.
If you lost access to your authenticator app, switch the field to Use a recovery code and enter one of the codes you saved. Each recovery code works once.
Turn it off
In Account Settings choose Disable 2FA on the same card. You must enter your current password and a valid code, so nobody with only an open browser session can remove your protection.
Store the recovery codes in a password manager or print them and keep them somewhere safe. We cannot show them again.