---
title: "Two-factor authentication"
description: "Secure your Edge Network account with TOTP-based two-factor authentication. Works with Google Authenticator, Authy, 1Password and other authenticator apps."
url: "https://edge.network/docs/account/two-factor-authentication"
section: "Account & support"
---

# Two-factor authentication

Add an extra layer of security to your account with TOTP-based 2FA.

## Overview

Two-factor authentication (2FA) requires both your password and a time-based one-time password (TOTP) from your authenticator app to sign in. Even if your password is compromised, attackers cannot access your account without the second factor.

> [!WARNING]
> We strongly recommend enabling 2FA for all accounts, especially those with access to production infrastructure.

- **Works with OAuth:** 2FA is enforced even when signing in with Google or GitHub.
- **Recovery codes:** Backup codes ensure you're never locked out of your account.
- **Industry standard:** TOTP-based, compatible with all major authenticator apps.

## Compatible authenticator apps

Any TOTP-compatible authenticator app will work. Popular options include:

- **Google Authenticator:** Available for iOS and Android
- **Authy:** Cross-device sync and desktop app
- **1Password:** Integrated password manager with TOTP
- **Microsoft Authenticator:** Works with Microsoft accounts too
- **Bitwarden:** Open-source password manager with TOTP

## Enabling two-factor authentication

1. Go to [Settings → Security](/console/settings/security) in your console.
2. Find the **Two-Factor Authentication** section and click **Enable**.
3. Scan the QR code with your authenticator app (or enter the secret manually).
4. Enter the 6-digit code from your app to verify.
5. **Save your recovery codes** in a secure location.

![Two-factor authentication setup in Control](/media/docs/control-account-2fa.svg)

> [!CAUTION]
> **Save your recovery codes.** Recovery codes are shown only once when you enable 2FA. Store them securely: they're the only way to access your account if you lose your authenticator device.

## Signing in with 2FA enabled

Once 2FA is enabled, the sign-in process requires an additional step:

1. Enter your email and password (or sign in with Google/GitHub).
2. You'll be prompted for your 6-digit authentication code.
3. Open your authenticator app and enter the current code.
4. You're now signed in.

The authentication code changes every 30 seconds. If a code doesn't work, wait for the next one and try again.

## Recovery codes

When you enable 2FA, you'll receive a set of recovery codes. Each code can only be used once and allows you to access your account if you lose your authenticator device.

### Best practices

- Store recovery codes in a password manager or secure vault
- Keep a printed copy in a secure physical location
- Never share recovery codes with anyone
- Generate new codes if you suspect they've been compromised

### Generating new recovery codes

If you've used most of your recovery codes or suspect they've been compromised, you can generate a new set:

1. Go to [Settings → Security](/console/settings/security).
2. In the 2FA section, you'll see how many recovery codes remain.
3. Click to generate new codes (requires your current 2FA code).

> [!WARNING]
> Generating new codes invalidates all previous codes.

## Disabling two-factor authentication

If you need to disable 2FA (not recommended):

1. Go to [Settings → Security](/console/settings/security).
2. Click **Disable 2FA**.
3. Enter your current authentication code or a recovery code to confirm.

> [!WARNING]
> Disabling 2FA significantly reduces your account security. Consider keeping it enabled and using recovery codes if you're concerned about device access.

## Troubleshooting

### Code not accepted

TOTP codes are time-based. Ensure your device's clock is accurate. Most authenticator apps handle this automatically, but if you're having issues, check your device's time settings.

### Lost authenticator device

Use one of your recovery codes to sign in. Once signed in, you can disable 2FA and set it up again with your new device.

### Lost device and recovery codes

Contact [support](/support). You'll need to verify your identity before we can help recover your account. This process may take several business days.
