Setting Up Multi-Factor Authentication (MFA)

MFA two-step verification security TOTP
Who this article is for
For anyone who wants to strengthen their account security. It's essential for anyone with an important role, such as a store owner, business account owner, or developer.

When you enable multi-factor authentication (MFA), you'll need a code from an authenticator app in addition to your password, so your account stays protected even if your password leaks.

Supported methods

  • TOTP (recommended): Google Authenticator, Microsoft Authenticator, Authy, 1Password, iCloud Keychain, and the like
  • FIDO2 / passkeys (recommended): YubiKey, Touch ID, Windows Hello, and the like
  • SMS: not recommended (vulnerable to SIM-swap attacks)

Setup steps (TOTP)

  1. Avatar at the top right → "Settings" → "Security"
  2. "Enable multi-factor authentication"
  3. Scan the QR code with your authenticator app
  4. Enter the 6-digit code shown in the app to verify
  5. Recovery codes (10 of them) are shown → print them or store them somewhere safe
  6. "Done"

Storing your recovery codes

Important: Recovery codes are your lifeline if you lose your MFA device. Keep them somewhere safe.
  • Save them in a password manager
  • Print them and keep them in a fireproof safe
  • An encrypted folder in cloud storage
  • You can regenerate new codes if you use them all up

What happens at login

  1. Enter your email and password
  2. You're taken to the "code entry screen"
  3. Enter the 6-digit code from your authenticator app
  4. Login complete

Trusted devices

If you check "Trust this device for 30 days," you can skip entering the code when logging in again from the same browser. Don't check this on a shared PC.

If you lose your MFA device

  1. Log in with a recovery code
  2. Go to "Security" → "Reset MFA" and switch to a new device
  3. If you've also lost your recovery codes → contact support for an identity verification process

Related guides

Published: 2026-04-27 Updated: 2026-07-05