Two-factor authentication means a password alone is not enough to sign in: a code from something you have is needed as well. It is off until you turn it on, under Account.
Two ways to get the code
- An authenticator app such as Google Authenticator, Authy or 1Password. Setting it up shows a QR code to scan; the app then generates a 6-digit code every 30 seconds. Enter one to prove it works, and it is on.
- A code by email. At sign-in a 6-digit code is emailed to you automatically. Turning this on, or off, needs a confirmation code from your inbox first, and your address has to be verified.
You can have both on. At sign-in, either kind of code is accepted, and there is a resend for the emailed one, once a minute.
What signing in looks like afterwards
Enter your password, or use Sign in with Google, as usual. The app then asks for the code. A code is good for a few minutes and can be used once. Passkeys skip this step, because a passkey already proves you have the device.
Turning it off
Under Account, with a current code. If the authenticator app is gone, an emailed code will do if that method is on. If neither is available, see I cannot sign in.
Changes are always announced. Turning two-factor on or off sends a security notice to your email and your other signed-in devices, and that notice cannot be muted. Whoever turns the switch off is not necessarily the account's owner, so the alarm has to ring regardless.
Where else the code is asked for
With an authenticator on, a code is also needed to change your email address and to delete the account. Both move or end every way of recovering the account, so a signed-in session on its own is not enough.
Still stuck? Write to us and we will answer.