Why enable it
2FA adds a second security barrier: on top of your password, a temporary 6-digit code, generated by a dedicated app, is required at each sign-in. Even if someone guesses or steals your password, they can't sign in without that code.
Enabling 2FA
- Go to the Security section of your profile.
- Install an authenticator app if you don't have one: Google Authenticator, Authy, or any password manager that supports TOTP.
- Scan the displayed QR code with the app.
- Enter the generated 6-digit code to confirm activation.
Recovery codes
On activation, a list of single-use recovery codes is shown.
Changing phones
Before resetting or switching phones, disable 2FA from your account (or move the TOTP entry to the new device if your app allows it). If you've already switched phones without thinking of it, use a recovery code to sign in and set 2FA up again on the new device.
Disabling 2FA
From the Security section, disabling 2FA requires confirmation with a valid code or a recovery code — it can't be removed with the password alone, for the same security reason.