Turning 2FA on
Two-factor authentication adds a six-digit code from your phone to every sign-in. It uses standard TOTP, so any authenticator app works: Google Authenticator, Aegis, 1Password, Bitwarden.
- Go to Settings → Security → Two-Factor Authentication
- Press Enable MFA
- Reveal the QR code and scan it with your authenticator app, or copy the secret by hand
- Type the six-digit code the app shows to confirm it
- Save the backup codes you are given
The QR code is deliberately blurred until you press to reveal it: you are usually setting this up somewhere other people can see your screen.
Backup codes
You are shown a set of one-time codes when 2FA is enabled. Each works once, in place of your authenticator.
Trusted devices
Check Remember this device during a 2FA prompt and that browser skips the code for 30 days. Settings → Security lists every device you have trusted, with the option to remove any of them: removing one means the next sign-in from it asks for a code again.
The trust is stored in that browser only. Clearing site data, or signing out, drops it.
Turning it off
Settings → Security → Disable MFA. If you started enabling 2FA and never finished, the same card shows a Continue Setup button rather than leaving you stuck halfway.