Two-factor sign-in
Turn on a second step at sign-in with an authenticator app, keep recovery codes for a lost phone, and what happens when a Team requires it.
Checked against the running product on 3 min readMarkdown
On this page
What it does#
With two-factor on, signing in takes two things: the way you already sign in (Google, Apple or an email link) and a 6-digit code from an authenticator app on your phone. Someone who gets into your email still can't get into your account without your phone.
It is free on every plan.
Turn it on#
- Open Settings→Security and choose Set up two-factor.
- If you don't have an authenticator app, install a free one from your phone's app store first, such as Google Authenticator or Microsoft Authenticator. A password manager with codes built in, like 1Password, works too.
- In the app, add an account and scan the QR code. If you can't scan it, copy the key shown beside it into the app. Reading this on the phone that has the app? Choose Reading this on your phone? Add it to your app instead.
- Type the 6-digit code the app shows and choose Turn on two-factor.
- Save the ten recovery codes you are shown. This is the only time they appear. Download saves them as a text file; a password manager or a printout works too. Don't keep them only on the phone that has your authenticator.
Signing in#
After the usual sign-in, you land on One more step. Type the code from your app. Codes change every 30 seconds and each one works once.
Lost your phone? Choose Use a recovery code and type one of your saved codes. Each recovery code works once. When you are down to three or fewer, make a new set.
Limits that keep guessing slow:
- One sign-in stays open for 15 minutes and allows five tries. After that, sign in again from the start.
- Ten wrong codes in a row pause two-factor sign-in on your account for 15 minutes, recovery codes included.
New recovery codes, or turning it off#
Both are in Settings→Security and both ask for a current code first, so someone at your unlocked computer can't quietly remove your second step.
- Make new recovery codes replaces all ten. The old ones stop working at once.
- Turn off removes two-factor. If a Team you belong to requires it, that workspace closes to you until you turn it back on, and the page says so first.
If you have lost both your phone and your recovery codes, write to [email protected]. Someone who has your email could write too, so a person checks it is really you in other ways before removing two-factor. That takes longer than a normal reply, on purpose.
When a Team requires it#
Owners and admins of a Team workspace can require two-factor for every member under Team→Access, in Two-factor sign-in. See Team hub.
If you don't have it on, you keep your place in the team, but the workspace won't open or sync for you. Your workspace list shows it as Turn on two-factor to open, which takes you to Settings. Once you turn it on, the workspace comes back on its own.
What it covers#
- Every way of signing in to the web app and the installed web app. The phone apps sign in through the same page, so the second step applies there too.
- Connections you approve for an assistant over MCP are approved from a signed-in browser, so approving one after you turn two-factor on needs the code.
- Devices that were already signed in before you turned it on stay signed in. Sign out of them, or remove a phone or assistant under Settings→Integrations, under Connected apps, to make them sign in again with the code.
Passkeys and single sign-on through SAML are not available yet.
How it is kept safe#
The key behind your codes is encrypted before it is stored, with a key that is not kept in the database. Recovery codes are stored only as one-way hashes, so we can check one but can't show it to anyone, including you. Every time two-factor is turned on or off, a code is wrong, or a recovery code is used, the event is written to the security log of each Team you belong to.