Turning it on
Open account settings and find Two-factor authentication. Because this changes how you sign in, the page asks you to have signed in recently; if it has been a while, sign in again first.1
Scan the code
Press Turn on two-factor. Scan the QR code with any authenticator app, or type the secret shown beside it into the app by hand.
2
Confirm with a code
Type the six-digit code the app shows. Nothing is active until a correct code confirms it, so an abandoned setup leaves your sign-in unchanged.
3
Keep your recovery codes
You are then shown a set of single-use recovery codes, once. Copy them or download them as a text file and store them somewhere safe — a password manager, a printed page in a drawer. They are never shown again.
Recovery codes
A recovery code opens the session when your phone is not at hand. Each one works exactly once, and after using one you are told how many remain. The settings page shows the count as well, and warns when none are left. Regenerate recovery codes issues a fresh set and kills the old ones; it asks for a current code from your app first.What requires it
- A workspace that requires it. An owner can switch on Require two-factor authentication on the workspace’s Members page. From then on, anyone in that workspace who has no second factor is sent to set one up before any page of that workspace opens; their other workspaces are unaffected, and new invitations say the requirement up front. Turning it off releases everyone; people who set it up keep it.
- Minting an API token in such a workspace. A token is a credential that skips the sign-in, so someone without a second factor cannot create one there; the refusal names the workspace. See Authentication.
- Single sign-on counts. A session opened through the organization’s identity provider has passed that provider’s own multi-factor policy, so it satisfies the requirement. See Single sign-on.