Two-factor authentication adds a second check at sign-in: alongside your password, you enter a 6-digit code from an authenticator app on your phone. This makes account takeover via a leaked password significantly harder.
Enabling TOTP
Go to Settings → Security → Two-factor authentication. Click Enable. You'll see a QR code — scan it with any TOTP-capable authenticator app (Google Authenticator, 1Password, Authy, Bitwarden, Yubico Authenticator, Aegis, Raivo, etc.). Enter the 6-digit code your app shows to confirm the link, and 2FA is on.
Recovery codes
When you enable 2FA we show you a one-time set of 10 recovery codes. Save them somewhere you can find them without your phone — a password manager, a piece of paper in a drawer, a printout in a safe. Each code works exactly once. If you ever lose your authenticator device, you can sign in using a recovery code in place of the TOTP digits.
Sign-in flow with 2FA
Once 2FA is enabled, sign-in becomes a two-step flow: email + password first, then a screen asking for your 6-digit code. You can choose to trust the device you're currently signing in from — that suppresses the 2FA prompt on that browser for 30 days. New devices and incognito sessions always re-prompt.
Disabling 2FA
In Settings → Security, click Disable. We'll ask for your password and a fresh TOTP code (or a recovery code) before turning it off. Recovery codes are invalidated as soon as 2FA is disabled.