Skip to content
Knowledge base

Turn on two-factor authentication

Add an authenticator app, save your recovery codes, and make every sign-in ask for a second factor.

1. Open Account, then Security

Two-factor authentication is set up per person, not per company. What you turn on here protects your own sign-in on every account you belong to, and an account owner cannot turn it on or off for you: it is your credential, not the company's.

2. Add an authenticator app

Choose Set up an authenticator app. On a phone, tap Open in authenticator app and your app (1Password, Authy, Google Authenticator, and the rest) offers to add the account. On a desktop app or password manager, type the setup key in by hand. Then enter the 6-digit code your app is showing to prove the enrolment worked.

3. Save the ten recovery codes

Activation issues ten single-use recovery codes and shows them once. We store only a hash, so we cannot show them again and cannot recover them for you: print them or put them somewhere that is not the phone your codes come from. Each one signs you in once. We email you whenever one is used.

4. Turn on Require a second factor

Having an authenticator app does not by itself change how you sign in. Turn on Require a second factor to make it count. From then on, signing in with a password -- or with Google, GitHub, or Apple, or through a password reset or an invitation link -- stops at a challenge page and asks for a code, a recovery code, or a passkey before any session exists. Five wrong codes end that attempt.

5. Know what a passkey does instead

Signing in with a passkey never asks for a second factor, because a passkey already is one: it proves both possession of the device and you, through Touch ID, Face ID, Windows Hello, or a security key. If you have a passkey, you can turn the requirement on without setting up an authenticator app at all. Provider sign-ins are not exempt for the opposite reason: whatever protection your Google or GitHub account has is theirs to change, not ours to rely on.

6. Changing or turning it off later

Issuing new recovery codes and turning the authenticator app off both ask for a current code (or a recovery code) in the same step -- a live session is not enough, because a stolen session is exactly what this protects against. Turning the app off deletes your recovery codes with it, and if nothing else is left that could answer a challenge, the requirement switches off too rather than locking you out.

Go deeper

The full reference lives in the docs: Getting started documentation. Error codes named above are each explained in the error-code reference.