# Use Two-Factor Authentication

Turn two-factor authentication on or off for your account, and sign in with an authenticator code or a recovery code.

Source: https://docs.deepinfo.com/guide/basics/two-factor-authentication/

Last updated: 2026-09-24

---
Two-factor authentication (2FA) adds a second step to signing in: after your password, you enter a
6-digit code from an authenticator app on your phone. Any authenticator app that supports TOTP works, for
example Google Authenticator. The app shows a new code every 30 seconds.

## Before You Start

- Install an authenticator app that supports TOTP on your phone.
- Any role can turn on 2FA for their own account. Admins can also require it for everyone in the
  organization: see [Require two-factor authentication](/guide/settings/require-two-factor-authentication/).

## Where to Find It

**Sidebar:** **SETTINGS** › **USER SETTINGS** › **Security** ·
https://platform.deepinfo.com/app/settings/user-security

The settings are in the **Two Factor Authentication** card, below **Change Password**.

Next to the card title, the status reads **Enabled** (green dot) or **Disabled** (red dot).

## Turn On Two-Factor Authentication

1. Go to **SETTINGS** › **USER SETTINGS** › **Security**.
2. In the **Two Factor Authentication** card, select **ENABLE TWO FACTOR AUTHENTICATION**.
3. Scan the QR code with your authenticator app. If you cannot scan it, select **COPY SECRET KEY** and
   add the key to the app by hand.
4. Enter the 6-digit code that the app shows. The code is sent as soon as all six digits are in. You can
   also select **VERIFY**.
5. The recovery codes appear. Select **DOWNLOAD CODE AND CLOSE**. This saves the codes to a text file named
   `recovery-code-<your e-mail address>.txt`, one code per line, and closes the window.
6. Keep the file somewhere safe, away from your phone.

The status now reads **Enabled**.

> [!IMPORTANT]
> Save your recovery codes when they appear. The platform has no screen to show them again or to create new
> ones later. Each code works only once.

## Sign In With a Code

1. Sign in with your e-mail address and password.
2. On **Two-Factor Authentication Verification**, enter the 6-digit code from your authenticator app. You
   can type or paste it. It is sent as soon as all six digits are in, or select **VERIFY**.

You then continue to the page you were opening, which is the Global Dashboard unless you followed a link
to another page.

## Sign In With a Recovery Code

Use a recovery code when you do not have your phone.

1. Sign in with your e-mail address and password.
2. On **Two-Factor Authentication Verification**, select **Use a Recovery Code**. The input changes to
   eight boxes.
3. Enter one of your recovery codes.

That code is now used up. To go back to the app code, select **Use Token**. If you have neither your phone
nor a recovery code, contact [support@deepinfo.com](mailto:support@deepinfo.com).

## Turn Off Two-Factor Authentication

1. Go to **SETTINGS** › **USER SETTINGS** › **Security**.
2. In the **Two Factor Authentication** card, select **DISABLE TWO FACTOR AUTHENTICATION**.
3. Confirm with **DISABLE**.

If your organization requires 2FA, you cannot turn it off. The platform shows "Two Factor Authentication
is required in your organization." and 2FA stays on.

## When Your Organization Requires 2FA

When an admin requires 2FA and you have not set it up, the platform stops you after you sign in, or on
your next page load, with a **Two-Factor Authentication** page. It explains that your organization
requires 2FA.

1. Select **ENABLE TWO FACTOR AUTHENTICATION**. The **Verify Your Identity** window opens.
2. Scan the QR code with your authenticator app, or select **COPY SECRET KEY** and add the key by hand.
3. Enter the 6-digit code from the app and select **VERIFY**.
4. Save your recovery codes with **DOWNLOAD CODE AND CLOSE**.

You then continue to the page you were opening, or to the Global Dashboard. Until you finish, the only
other option on the page is **Sign Out**.

## Good to Know

- **A new QR code every time.** Each time you turn 2FA on, the platform creates a new secret, so you scan a
  new QR code. You can then remove the old Deepinfo entry from your authenticator app.
- **Shared screens.** The QR code, the secret key and the recovery codes let someone else pass your second
  step. Do not show them on a shared screen or in a screenshot.
