Turning on two-factor authentication

Protect your account in under 60 seconds with Authy, 1Password, Google Authenticator, or any TOTP app.

The short version

Open Account settings, choose two-factor authentication, and scan the QR code with any TOTP app: Authy, 1Password, Google Authenticator or similar. Enter the six-digit code to confirm and save your recovery codes somewhere that is not the same phone. It takes under a minute.

Dashboard → Account → Two-factor authentication → Enable.

You'll see a QR code. Scan it with your TOTP app (Authy, 1Password, Google Authenticator, Bitwarden - any works). The app starts generating 6-digit codes that rotate every 30 seconds.

Enter the current code on the setup page to confirm everything's working. We'll show 10 recovery codes - save these somewhere safe. Each one works once and lets you sign in if you lose your phone.

From the next login onwards, we'll ask for the 6-digit code after your password.

#Turning it off

Account → Two-factor → Disable → enter your password. We wipe the secret and the recovery codes.

#Frequently asked questions

Which authenticator apps work with Hostd?

Any TOTP app. Authy, 1Password, Bitwarden, Google Authenticator and Microsoft Authenticator all work, because the standard is the same everywhere. There is no Hostd-specific app to install.

What happens if I lose my 2FA device?

Use one of the ten recovery codes you saved when you set it up. Each works once. If those are gone too, contact support and expect to prove account ownership, because an account-recovery route that is easy for you is also easy for someone impersonating you.

Does 2FA protect destructive actions too?

Yes. Destructive actions such as deleting a server prompt for a step-up check rather than relying on the session being old and trusted.

Written and maintained by the Hostd engineering team. Last updated 2026-04-24. Notice a mistake? Tell us.