Two-Factor Authentication
Why turn it on
Your dashboard account controls servers, payment methods and personal data. A password alone can be phished or reused; a second factor means a stolen password is not enough on its own.
Setting it up
In the security section of your profile, enable two-factor authentication. You will be shown a QR code — scan it with an authenticator app such as Aegis, 1Password, Bitwarden or Google Authenticator — then confirm with the six-digit code the app generates.
From the next login onwards, that code is asked for after your password.
Recovery codes
When you enable 2FA you are given recovery codes. Save them somewhere that is not the phone holding the authenticator — a password manager, or printed and kept with your documents.
They are the way back in when the phone is lost, broken or wiped. Each code works once.
If you lose access
Use a recovery code to sign in, then disable and re-enable 2FA on the new device.
With no recovery codes left, contact support. Getting back in will require proving the account is yours, and that is deliberately not quick — which is exactly why the codes are worth storing properly.
Turning it off
2FA can be disabled from the same page, confirming with a current code. If you have a passkey, consider using that instead of removing your second factor altogether.
Related articles
Creating an Account
Signing up, verifying your email, and what to do if your first order is held for review.
Profile and Billing Details
Keeping your personal and invoicing data correct, and why it matters before an invoice is issued.
Passkeys
Signing in with your fingerprint, face or device PIN instead of typing a password.
