Overview
An authenticator app — like Google Authenticator, Authy, or 1Password — adds a second step to sign-in: after your magic link, you’ll also enter a 6-digit code. Setting one up is the fastest way to turn on two-factor authentication.
Steps
- Click your avatar in the top-right corner and choose Profile.
- Select the Security sub-tab.
- Under Authenticator app, click Set up.
- A QR code appears. Open your authenticator app and scan it — or, if you can’t scan, use the key printed next to “Or enter this key:” and type it into your app manually.
- Your authenticator app now shows a 6-digit code that refreshes periodically. Type the current code into the field below the QR code.
- Click Verify & enable.
- If this is the first second factor on your account, a “Save your recovery codes” screen appears immediately — finish that step before closing it (see Save and use your recovery codes).
- Back in Security, Authenticator app now reads “On,” with a Turn off button in place of Set up.
Good to know
- If you start setup and change your mind, click Cancel instead of scanning — nothing is enabled until you verify a code.
- The QR code and key are only shown once, at setup. If you lose them before finishing, click Set up again to generate a fresh pair.
- Setting up an authenticator app is enough on its own to satisfy your workspace’s “require two-factor authentication” policy, if the owner has turned that on — you don’t also need a passkey.
- Owners: you must set up your own two-factor method here before you can require it for the rest of the team, under Settings → Profile → Security → “Require all agents to set up two-factor authentication.”
Related articles
See also Sign in with a passkey, Save and use your recovery codes, and Turn off or reset two-factor authentication.