Skip to main content

Two-Factor Authentication

Two-factor authentication adds another verification step after the primary sign-in method. Open Settings -> Security.

Choose a method​

Open the two-factor authentication settings and select an authenticator app or a confirmed email address.

Confirm your current password before enabling or disabling a method or replacing recovery codes. An unattended authenticated session alone cannot change this protection.

Authenticator app​

  1. Open an authenticator app on your phone.
  2. Scan the QR code. Add the displayed key manually when the camera is unavailable.
  3. Enter the current six-digit code.
  4. Select Confirm.

The app refreshes the code automatically. The same code cannot be used twice.

Email code​

This method requires a confirmed email address. The cabinet sends a one-time code to the linked address during sign-in. Resending is available only for the email method.

Enabling the email method also requires a code from the message. This confirms access to the address before the method becomes active.

Recovery codes​

After the first method is enabled, the cabinet creates ten one-time recovery codes.

  • store the codes in a password manager or download the file;
  • each code works once;
  • regenerating codes immediately invalidates every old code;
  • do not keep the file next to the account password.

During sign-in, choose an available method: authenticator app, email, or recovery code.

Disable a method​

Disabling requires the current password and a code from the selected method. Its secret is deleted immediately. When the last method is disabled, the cabinet also deletes all recovery codes and pending verification requests.

A passkey is a separate secure sign-in method configured on the same page. It does not replace two-factor authentication settings. See Authentication and Registration for all sign-in options.