Two-factor authentication (2FA) requires a one-time code from your phone in addition to your password. Even if your password leaks, an attacker can't sign in without the code.
Set it up
- Open the dashboard → Security → Two-factor authentication → Enable.
- Scan the QR code with your authenticator app (1Password, Authy, Aegis, Google Authenticator, or any RFC 6238-compliant app).
- Enter the six-digit code from your authenticator to confirm the link.
- Save the recovery codes shown next — print or store them in a password manager.
After it's enabled
Every sign-in from a new device asks for a code. Already-signed-in devices keep working without prompting.
If you lose the authenticator
Use one of the recovery codes you saved. If you don't have any, email hello@securefox.xyz from the address on the account — we have an identity-verification flow to recover the account.