Account & security
Two-factor authentication
Protect your account with an authenticator app code, backup codes, and "trust this browser" — and what a workspace that requires it means.
Two-factor means signing in needs something you know (your password) and something you have (your phone's authenticator app or a passkey).
Turn it on
- Open Settings → Security → Two-factor authentication and choose Set up. You'll confirm it's you first.
- Scan the QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy, Bitwarden…) — or on a phone, tap Open in app.
- Enter the 6-digit code the app shows.
- Save your ten backup codes — copy, download or print them. Each works once, for when you don't have your phone.
Turning it on can also sign out your other devices.
Signing in with two-factor
After your password (or Google/GitHub, or a password reset) you're asked for a code. You can use the authenticator, a passkey, or a backup code. Tick Trust this browser for 30 days on your own computer to skip the code there.
Backup codes
- Make a fresh set in Settings → Security any time — it cancels the old set.
- We alert you when a backup code is used, and when only three or fewer are left.
When a workspace requires it
A Team workspace can require two-factor for every member. Until you turn it on you'll see an explanation instead of that workspace's projects — you can still leave the workspace. You also can't turn two-factor off while a workspace you're in requires it.
A passkey is two factors in one — and never needs a code.
Still have a question about this?
Assist answers from this article — in any language.
Was this helpful?