Two-factor authentication
Add an authenticator app code to your sign-in, keep recovery codes, and require two-factor authentication for your organization.
Two-factor authentication adds a second step to signing in: after your password, you enter a six-digit code from an authenticator app on your phone. A password can be guessed, reused or phished, but a code that changes every 30 seconds on a device in your pocket can’t be used by someone far away.
Who can use it#
Everyone can turn on two-factor authentication for their own account under SettingsSecurity. No permission is needed.
Permissions
organization.manageA passkey works as a second factor too, and either one satisfies an organization that requires two-factor authentication.
Set it up#
Choose Set up
In SettingsSecurity, the Two-factor authentication section shows Off. Choose Set up.
Scan the QR code
Open an authenticator app that makes six-digit codes, such as Google Authenticator, 1Password, Authy or Bitwarden, and scan the square. If you can’t scan, type the key shown under Or enter this key by hand. The key is shown only once; if you leave before finishing, start again for a new one.
Enter a code to prove it works
Type the code the app shows into Code from the app and choose Turn on. Choose Cancel to stop without turning it on.
Save your recovery codes
The Save your recovery codes dialog shows ten codes. Each one signs you in once if you lose your phone. Choose Copy and keep them somewhere other than your phone, such as a password manager, then choose I’ve saved them.
Recovery codes are shown only once
Recovery codes are stored in a form that can’t be read back, so nobody can show them to you again. If you lose them, generate a new set while you still have your phone.
Signing in with a code#
After your password, enter the current code from your app, or one of your recovery codes, and choose Verify. See Signing in.
- Each code can be used only once, even within its 30 seconds.
- Each recovery code can be used only once.
Manage recovery codes or turn it off#
When two-factor authentication is On, the section shows how many recovery codes you have left. When two or fewer remain, it reminds you to generate a new set.
Enter a current code
Both actions need a working code in Current code, so someone with access to your signed-in browser can’t remove your protection.
Choose what to do
New recovery codes replaces your codes with a fresh set of ten and shows them once. Your old codes stop working.
Turn off asks you to confirm in Turn off two-factor authentication?. Your password alone will then be enough to sign in, and your recovery codes stop working. Choose Keep it on to back out.
Require it for everyone in the organization#
Set it up on your own account first
The requirement takes effect immediately, so it can’t be turned on by someone who doesn’t have a second factor. The screen reminds you if you haven’t.
Turn on Require it of everyone here
The switch is at the bottom of SettingsSecurity. A message tells you how many members will be asked to set it up, or that everyone already has.
What happens to members without a second factor:
- They keep their membership and their work.
- Until they set up an authenticator app or passkey, they see This organization requires two-factor authentication instead of the app, with the setup controls on that screen.
- Their access to other organizations is unaffected.
- The requirement doesn’t apply to API keys or service accounts, which are protected by their scopes instead.
Frequently asked questions#
“That code has already been used. Wait for the next one.”
The code was right but had already been used, for example in a sign-in a few seconds earlier. Wait for your app to show the next code.
I have lost my phone and my recovery codes.
Use a passkey if you added one. Otherwise, nobody can retrieve your authenticator secret, which is what stops anyone impersonating you. Ask an Owner or Admin of your organization; recovering an account in this state is a support matter.
Does requiring it remove members who don’t have it?
No. They are simply asked to set it up before they can carry on in that organization.
I have a new phone. What do I do?
Many authenticator apps can move codes to a new phone. If yours can’t, sign in with a recovery code, turn two-factor authentication off using a code from your old phone if you still have it, and set it up again on the new one.
Related pages#
Still stuck? Search the docs with ⌘K, open Help inside UnitX, or contact support.