Turning on two-step verification
Setting it up with an authenticator app, backup codes, resetting after changing phones, and turning it off. Step by step.
Last updated: September 30, 2026
Setting it up with an authenticator app, backup codes, resetting after changing phones, and turning it off. Step by step.
Last updated: September 30, 2026
If you want your account to hold even when your password is stolen, two-step verification is the most effective route: at sign-in it asks for the 6-digit code from an app on your phone in addition to your password. This guide walks through the setup, explains why the backup codes matter, and shows what to do when you change phones.
💡 Two-step verification is not compulsory, but without it the panel's sensitive screens are closed to you: Connection settings, moving an account, deleting an account and deleting a portfolio all require a security method. The alternative is a passkey; see Passkeys.
Two-step verification needs an authenticator app running on your phone. The app generates a new 6-digit code every 30 seconds and needs no internet connection.
Common ones: Google Authenticator, Microsoft Authenticator, 1Password, Authy. It doesn't matter which you use; they all follow the same standard. If you use a password manager (such as 1Password), keeping the codes there is the most practical.
Don't start the steps below before installing the app; the setup screen will leave you stranded.
A "Two-step verification enabled." notice appears and the badge in the heading turns On.
Scanning doesn't work on every device, and it's awkward if you're on a computer without your phone in hand. There is a way out under the square code: "If you can't scan the code, enter this key into the app manually:" followed by a key in text form.
Find the "enter setup key manually" option in the app and paste that text. The result is the same.
Once verification succeeds, the panel gives you a list of backup codes. The note is clear: "If you can't reach your phone you can sign in with these codes. Keep them somewhere safe; they are never shown again."
Don't skip this step. If you lose, wipe or have your phone stolen, your authenticator app goes with it; the backup codes are your only way into your account.
Practical advice on where to keep them:
Each code works once. If you've used most of them, or you doubt their secrecy, you can generate new ones: press Generate new backup codes in the Backup codes section. As the note warns: "Generating new codes invalidates the old ones." Store the new ones with the same care.
At your next sign-in the panel asks for your e-mail and password, then the 6-digit code. You can type two things into the code field:
abcde-12345).The panel tells from the format which you typed; you don't have to say.
The same field turns up on sensitive screens inside the panel. Entering Connection settings, moving an account or deleting one asks for the same code. See The security verification screen.
If you moved to a new phone and can no longer reach the app on the old one, use Reset and set up again.
The section's description: "If you changed phones: the current setup is removed and you're asked to set it up with the new app straight away."
The steps:
⚠️ Resetting only helps while you can still reach the old phone or have a backup code, because you have to be signed in to start. If you lost both your phone and your backup codes, contact our support team.
The Turn off section states the consequence: "Two-step verification is switched off; sign-in is by password alone."
Think about two things before you do:
If you are thinking of turning it off because you changed phones, don't; Reset and set up again exists for exactly that.
Moving on without saving the backup codes. They are never shown again, and they are your only way out if the phone is lost.
Pressing "Turn on" before installing the app. You'll sit on the setup screen with nothing to scan the code with and abandon the process.
Typing the code with a space. The app shows it as 123 456 but the field takes it without the space.
Typing an expired code. The code refreshes every 30 seconds. If it expires while you type, wait for the next one.
A phone clock that has drifted. Authenticator apps generate codes from the device clock. If codes keep being rejected, set your phone's clock to automatic.
E-mailing the backup codes to yourself. If your e-mail is compromised, the protection means nothing.
Trying to turn it off and back on after changing phones. Turning it off also requires signing in; the right route is resetting.
If your codes are rejected and you can reach neither your phone nor your backup codes, there is nothing left to do in the panel. Contact our support team.
For code-free sign-in see Passkeys, for the whole Security screen see Account security, and for where the code is demanded inside the panel see The security verification screen.
Was this article helpful?