# Two-factor authentication (2FA)

> Turn on two-factor authentication with an authenticator app or passkeys, save recovery codes, and enforce 2FA for every member of your analytics workspace.

## Turn it on

**Account settings → Security → Two-factor authentication → Set up.**

1. Scan the QR code with an authenticator app (1Password, Google
   Authenticator, Authy, Microsoft Authenticator…).
2. Enter the six-digit code to confirm.
3. **Save your recovery codes.** Each works once, if you lose your device.
   You can regenerate them (which invalidates the old ones).

From then on, after your password, email link or social sign-in, you're
asked for a code, a passkey or a recovery code.

## Passkeys

Add passkeys (Touch ID, Face ID, Windows Hello, a security key or a
password manager) under **Account settings → Security → Passkeys**. A
passkey can sign you in on its own, and counts as the second factor.

## Enforce it for everyone

On the **Business** plan, owners and admins can require 2FA for all members
in **Workspace settings → Security**. Members without it are asked to set it
up at their next sign-in. If the workspace moves to a lower plan, the
setting is kept but stops applying until it's back on Business. The Members
list shows each member's 2FA status on every plan.

## Lost access?

Use a recovery code. If you have none left, ask a workspace owner to
contact support from their account. We verify ownership before removing
2FA.
