Account & security

Two-factor authentication

Protect your account with an authenticator app code, backup codes, and "trust this browser" — and what a workspace that requires it means.

1 min readUpdated 27 Sept 2026

Two-factor means signing in needs something you know (your password) and something you have (your phone's authenticator app or a passkey).

Turn it on

  1. Open Settings → Security → Two-factor authentication and choose Set up. You'll confirm it's you first.
  2. Scan the QR code with an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy, Bitwarden…) — or on a phone, tap Open in app.
  3. Enter the 6-digit code the app shows.
  4. Save your ten backup codes — copy, download or print them. Each works once, for when you don't have your phone.

Turning it on can also sign out your other devices.

Signing in with two-factor

After your password (or Google/GitHub, or a password reset) you're asked for a code. You can use the authenticator, a passkey, or a backup code. Tick Trust this browser for 30 days on your own computer to skip the code there.

Backup codes

  • Make a fresh set in Settings → Security any time — it cancels the old set.
  • We alert you when a backup code is used, and when only three or fewer are left.

When a workspace requires it

A Team workspace can require two-factor for every member. Until you turn it on you'll see an explanation instead of that workspace's projects — you can still leave the workspace. You also can't turn two-factor off while a workspace you're in requires it.

A passkey is two factors in one — and never needs a code.

Still have a question about this?

Assist answers from this article — in any language.

More in Account & security