Two-factor authentication
An authenticator app, backup codes, or a passkey as a second factor.
Turning it on
From Dashboard → Settings → Security, confirm your password, then scan the QR code with an authenticator app (1Password, Authy, Google Authenticator, or any RFC 6238 TOTP app). Enter the 6-digit code it shows to confirm.
Backup codes
Once confirmed, you get 10 single-use backup codes, shown exactly once. Download them and store them somewhere safe: each one works once, if you lose access to your authenticator app. Regenerate a fresh set anytime from Security settings; the old set stops working the moment you do.
Signing in with two-factor on
After your password, you're asked for a code (or a backup code, or a passkey, see below). A wrong code enough times in a row temporarily locks that check, separately from the account's own sign-in rate limit.
Trust this device
Checking "trust this device" at the challenge skips the second factor on that exact browser for up to 30 days. It's tied to the device, not the account: signing in from anywhere else still asks for it, and it never replaces the first factor (your password, passkey, or Google/Microsoft sign-in).
A passkey as the second factor
If you have a passkey registered (see /docs/passkeys), you can use it in place of a code at the two-factor challenge. A passkey requires your device's own biometric or PIN check, which this app treats as already satisfying two-factor assurance for that sign-in.
Turning it off
- Requires confirming your password.
- Requires a step-up check (a fresh password or code) if it's been a while since you last verified, see Sessions and devices.
- You get an email the moment it's turned off, in case it wasn't you.