Knowledge base
Turning on two-factor authentication
The single most useful thing you can do for your account, and it takes two minutes.
A password can be guessed, reused or phished. A second factor means a stolen password on its own is not enough.
Setting it up
Account settings → Sign-in & security. You have two choices:
A passkey — your device's fingerprint, face or PIN. Nothing to type, nothing to lose, and it cannot be phished because it only works on the real site. Choose this if your device supports it.
An authenticator app — a six-digit code that changes every thirty seconds. Works on any device, including one that does not support passkeys.
Recovery codes
You are shown a set of one-time recovery codes. Save them somewhere that is not the device you just enrolled — a password manager, or printed. They are how you get in when the phone is lost, and they are shown once.
Requiring it for everybody
If you have a team, Organisation → Security lets you require two factor for every member. Existing members are prompted at their next sign-in; nobody is locked out mid-session.
If you lose your device
Use a recovery code. If you have none, open a ticket — we can verify you by other means, and that process is deliberately slower than a code, because anything faster would be a way in for someone else.
Still stuck?
Support is included on every plan and answers in your own language.
Contact support → All articles →