Two-factor authentication: setup and lost access
Turn it on in Profile → Two-factor auth with email, text message or an authenticator app, and keep the recovery codes it gives you.
What you see
You want to set up two-factor, a setup code is refused, or you've lost the device your codes come from.
- Invalid code. Check your authenticator app.
- Code has expired. Request a new one.
- We couldn't text a code to that number. Check it's correct (and verified, if we're on an SMS trial), or use email or an authenticator app instead.
- Incorrect password.
- That recovery code isn't valid, or has already been used.
- Too many codes requested. Please wait a few minutes before asking for another.
Why it happens
Two-factor asks for a code every time you sign in. Email and text-message setup codes last 10 minutes; authenticator codes change every 30 seconds, so your device clock must be right. If a text can't be sent at sign-in, the code goes to your email instead. Turning two-factor on also gives you 10 single-use recovery codes — they are the way back in if the device is gone, and they are shown once, because we store only their fingerprints and cannot show them again.
How to fix it
- Open Profile → Two-factor auth and choose email, phone or authenticator app.
- For an authenticator app, scan the QR code, then enter the 6-digit code it shows.
- Save the recovery codes it gives you somewhere only you can reach — a password manager, or printed and put away.
- If the app's code is refused, check the time on your phone is set automatically, then try the newest code.
- Lost the device? On the code screen choose “Lost your device? Use a recovery code” and enter one of the codes you saved. Each works once.
- Out of codes, or think they have been seen? Profile → Two-factor auth → Create new codes. That retires every earlier code.
- To turn two-factor off, enter your password in the same section. Your recovery codes stop working with it.