Two-factor authentication

Two-factor authentication means signing in needs your password and a code from an authenticator app. It’s the single most effective thing you can do to protect an account holding research data.

Turning it on

  1. Open Account from your user settings.
  2. Find 2FA Authentication and expand it.
  3. Scan the QR code with an authenticator app, or enter the secret by hand.
  4. Type the six-digit code the app shows, and confirm.

Then generate recovery codes — properly

As soon as two-factor is on, the Account page tells you to generate recovery codes, and you should do it immediately. These are one-time codes that get you in when you don’t have your authenticator.

Two things people get wrong:

  • Freshly generated codes don’t work until you press Confirm. Save them somewhere safe first, then confirm. Until you do, they’re inert.
  • Codes are shown once. Store them somewhere that isn’t the device with the authenticator on it — a password manager, or printed and filed.

Without recovery codes, losing your phone locks you out of your account permanently.

Signing in with it on

After your password you’re asked for a code. If you can’t reach your authenticator, choose to use a backup recovery code instead. Each code works once.

Turning it off

Unlinking the authenticator from the Account page turns it off. Recovery codes stay visible after unlinking because they remain a live second factor until you remove them too.

Studies that require it

A study can require two-factor for its own members. If you’re a member of one, you’ll be asked to enrol before you can reach that study’s data, whatever your personal setting.

Related articles