Two-factor authentication
Two-factor authentication (2FA) adds a second step to signing in. After your password, you also enter a short code from an app on your phone. That way, even if someone learns your password, they still cannot get into your account without your device.
Turning it on
- Open your account settings and choose Enable 2FA.
- Click Set up. A QR code appears.
- Scan the QR code with an authenticator app.
- Enter the code your authenticator app shows and click Activate.
From now on, every login asks for a code from your authenticator app in addition to your password.
If you lose access to your 2FA authenticator
The codes live only on your authenticator app, so if you lose that device you recover your account the same way as a forgotten password: through your recovery kit.
Start at the password recovery page and follow the steps. If you cannot get back in, contact support and we will help.
Where the codes come from
The code changes every 30 seconds and is generated from a secret shared between your account and your authenticator app when you scan the QR code. Nothing is sent by SMS or email, the code is computed on your device, which is why 2FA keeps working even without a signal.
This is the standard time-based one-time password scheme (TOTP, RFC 6238), so any common authenticator app works with zeitkapsl.