Enable two-factor authentication (2FA) and passkeys

Two-factor authentication asks for a code from your phone in addition to your password, so a leaked password alone can't unlock your account.

Turn on 2FA

  1. Install an authenticator app on your phone: Google Authenticator, Microsoft Authenticator, Authy or 1Password all work.
  2. Go to Dashboard → Settings → Two-Factor Authentication and click Enable.
  3. Scan the QR code with your authenticator app. Can't scan? Type in the secret key shown below the QR code instead.
  4. Enter the 6-digit code your app shows and click Verify.

From now on, you'll enter a code from the app each time you sign in.

Save your backup codes

Backup codes let you in if you lose your phone.

  1. On the same Settings page, click Generate Backup Codes.
  2. Download or copy them and store them somewhere safe - a password manager or a printed copy.

Add a passkey

Passkeys let you sign in with your fingerprint, face or device PIN.

  1. On Settings, find Passkeys and click Register (for example Register with Windows Hello).
  2. Confirm with Windows Hello, Touch ID or Face ID.

You can remove a passkey from the same section at any time.

Turning 2FA off

You can disable 2FA from Settings, but we don't recommend it. We email you whenever 2FA is disabled - if you get that email and didn't do it, reset your password and contact support immediately.


Still stuck? Open a ticket on Discord - run /ticket in any channel, pick a department, and include your Server ID or Invoice ID so we can jump straight in.