Two-factor authentication
Two-factor authentication uses an authenticator app. Find it under Security and sessions in the account menu.
Turning on two-factor#
Confirm your password
You are asked for your current password before anything changes.
Scan the QR code
Use any standard authenticator app. Codes are six digits and rotate every thirty seconds. If you cannot scan, the secret is shown as text to enter manually.
Enter a code to prove it works
This confirms your app is generating correct codes before two-factor is enforced, so you cannot lock yourself out at setup.
Save your backup codes
Ten codes are shown once. You must confirm you have saved them before finishing.
Backup codes#
Store them somewhere you can reach without your phone. A password manager is the usual answer; a screenshot in the phone that holds your authenticator is not.
Signing in with 2FA on#
After your password is accepted you are asked for a code. You can switch to entering a backup code instead. No session exists until this step completes, so an attacker with your password alone gets nothing.
Trusting a device#
The code screen offers to trust the device, which is ticked by default and skips the code on that browser for thirty days. It is per browser, so a different browser or a private window asks again.
Untick it on any machine that is not yours. Turning two-factor off clears every trusted device.
Disabling and regenerating#
Both live in the same Security and sessions panel, and both require your password again.
- Disable turns two-factor off and clears trusted devices.
- Regenerate backup codes issues a fresh set and invalidates every previous code immediately. Do this if you think your saved list has been exposed, or once you have used several.