Two-factor authentication: setup, recovery codes, and lockouts
Last updated: 2026-08-23
The two 2FA options
- Authenticator app (TOTP) — Google Authenticator, Authy, 1Password, etc. Strongest option; works offline.
- Email codes — a one-time code sent to your account email at login. Better than nothing, but only as strong as your inbox.
Enable either in Settings → Account → Two-factor authentication.
Setting up an authenticator app
- Settings → Account → Enable authenticator.
- Scan the QR code with your app.
- Enter the 6-digit code to confirm.
- Save your recovery codes. They are shown exactly once, at enrollment. Store them in a password manager — they are the only self-service way back in if you lose your phone.
Lost your phone? Use a recovery code
At the 2FA prompt, enter one of your saved recovery codes instead of the 6-digit code. Each recovery code works once and is burned after use. Once you're in, disable and re-enroll 2FA with your new device to get a fresh code set.
Lost the phone AND the recovery codes
Email [email protected] from your account email address. For your protection we verify identity before removing 2FA — expect verification questions (recent billing details, connected broker name, approximate signup date). We will never remove 2FA based on a request from a different email address.
Locked out for wrong passwords?
Five failed password attempts lock the account for 15 minutes — even the correct password is refused during the lockout. This is intentional (brute-force protection). Wait it out, then use Forgot password if needed.
Changing your password
Settings → Account → Change password (or ⌘K → "Change password"). Changing your password signs out all other devices automatically.