> ## Documentation Index
> Fetch the complete documentation index at: https://docs.codecobra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

> Add a second step to your CodeCobra sign-in with an authenticator app, backup codes and trusted devices.

Two-factor authentication means a stolen password isn't enough to get into your account. CodeCobra uses time-based codes from an authenticator app — Google Authenticator, 1Password, Authy, or any other.

## Turning it on

<Steps>
  <Step title="Open Settings → Security">
    Find the Two-factor authentication section.
  </Step>

  <Step title="Scan the QR code">
    Your authenticator app adds CodeCobra and starts generating six-digit codes. If you can't scan, there's a text key to type in instead.
  </Step>

  <Step title="Confirm with a code">
    Enter the current code to prove the app is set up correctly. Two-factor is now active.
  </Step>

  <Step title="Save your backup codes">
    You get a set of one-time backup codes. **Save them somewhere you can reach without your phone** — a password manager, or printed and filed.
  </Step>
</Steps>

## Backup codes

Each backup code works once, and gets you in when your authenticator isn't available — phone lost, replaced, or simply not with you.

If you use several, or you think the list has been seen by someone else, regenerate them from Settings → Security. Regenerating invalidates every previous code.

<Warning>Backup codes are the only way back into your account if you lose your authenticator. Store them before you need them — we cannot recover an account without them.</Warning>

## Trusted devices

After signing in with a code, you can mark that browser as trusted so it stops asking every time. Convenient on your own laptop; don't do it on a shared machine.

Settings → Security lists every trusted device. You can revoke one, or revoke all of them at once — worth doing if a laptop goes missing.

## Turning it off

You can disable two-factor from Settings → Security, confirming with a current code.

If your organization requires two-factor, you can't turn it off while you're a member. See [requiring 2FA for your organization](/security/enforce-2fa-for-your-org).
