# Two-Factor Authentication

Add a one-time code from an authenticator app on top of your password. Two-factor auth is set per account.

## Turn it on

1. Open **Account settings**.
2. Go to **TWO-FACTOR AUTH**.
3. Select **SET UP TWO-FACTOR AUTH**.
4. Scan the **QR code** with an authenticator app such as Google Authenticator, 1Password, or Authy. If you cannot scan it, enter the **SETUP KEY** by hand instead.
5. Enter the current **6-DIGIT CODE**.
6. Select **VERIFY & ENABLE**.

## Recovery codes

After enabling, ContextOwl shows recovery codes once. Select **COPY CODES** and store them somewhere safe. Each code works once if you lose your authenticator. Use **REGENERATE RECOVERY CODES** to replace them.

## Turn it off

In **TWO-FACTOR AUTH**, enter your **PASSWORD** and an **AUTHENTICATOR OR RECOVERY CODE**, then select **DISABLE 2FA**.

## Require it for admins

Admins can require two-factor auth for the whole organization. Open **Admin > Settings > Security** and turn on **Require two-factor auth for admins**. If you sign in with Google or GitHub, add a password through password reset first, then enroll.
