# Two-factor sign-in

> Turn on a second step at sign-in with an authenticator app, keep recovery codes for a lost phone, and what happens when a Team requires it.

## What it does

With two-factor on, signing in takes two things: the way you already sign in
(Google, Apple or an email link) and a 6-digit code from an authenticator app
on your phone. Someone who gets into your email still can't get into your
account without your phone.

It is free on every plan.

## Turn it on

1. Open **Settings → Security** and choose **Set up two-factor**.
2. If you don't have an authenticator app, install a free one from your
   phone's app store first, such as Google Authenticator or Microsoft
   Authenticator. A password manager with codes built in, like 1Password,
   works too.
3. In the app, add an account and scan the QR code. If you can't scan it,
   copy the key shown beside it into the app. Reading this on the phone that
   has the app? Choose **Reading this on your phone? Add it to your app**
   instead.
4. Type the 6-digit code the app shows and choose **Turn on two-factor**.
5. Save the ten recovery codes you are shown. This is the only time they
   appear. **Download** saves them as a text file; a password
   manager or a printout works too. Don't keep them only on the phone that has
   your authenticator.

## Signing in

After the usual sign-in, you land on **One more step**. Type the code from your
app. Codes change every 30 seconds and each one works once.

Lost your phone? Choose **Use a recovery code** and type one of
your saved codes. Each recovery code works once. When you are down to three or
fewer, make a new set.

Limits that keep guessing slow:

- One sign-in stays open for 15 minutes and allows five tries. After that,
  sign in again from the start.
- Ten wrong codes in a row pause two-factor sign-in on your account for 15
  minutes, recovery codes included.

## New recovery codes, or turning it off

Both are in **Settings → Security** and both ask for a current
code first, so someone at your unlocked computer can't quietly remove your
second step.

- **Make new recovery codes** replaces all ten. The old ones
  stop working at once.
- **Turn off** removes two-factor. If a Team you belong to
  requires it, that workspace closes to you until you turn it back on, and the
  page says so first.

If you have lost both your phone and your recovery codes, write to
<hello@themarginapp.com>. Someone who has your email could write too, so a
person checks it is really you in other ways before removing two-factor. That
takes longer than a normal reply, on purpose.

## When a Team requires it

Owners and admins of a Team workspace can require two-factor for every member
under **Team → Access**, in **Two-factor sign-in**. See
[Team hub](https://themarginapp.com/docs/team-hub#two-factor-for-every-member).

If you don't have it on, you keep your place in the team, but the workspace
won't open or sync for you. Your workspace list shows it as **Turn on
two-factor to open**, which takes you to Settings. Once you turn it on, the
workspace comes back on its own.

## What it covers

- Every way of signing in to the web app and the installed web app. The phone
  apps sign in through the same page, so the second step applies there too.
- Connections you approve for an assistant over MCP are approved from a signed-in
  browser, so approving one after you turn two-factor on needs the code.
- Devices that were already signed in before you turned it on stay signed in.
  Sign out of them, or remove a phone or assistant under
  **Settings → Integrations**, under **Connected apps**, to
  make them sign in again with the code.

Passkeys and single sign-on through SAML are not available yet.

## How it is kept safe

The key behind your codes is encrypted before it is stored, with a key that
is not kept in the database. Recovery codes are stored only as one-way hashes,
so we can check one but can't show it to anyone, including you. Every time
two-factor is turned on or off, a code is wrong, or a recovery code is used,
the event is written to the security log of each Team you belong to.


---

Section: Control and connections. Checked against the running product on October 3, 2026.
Web page: https://themarginapp.com/docs/two-factor-sign-in. Every docs page: https://themarginapp.com/docs/llms.txt
