Set up two-step verification
Add a second factor to your sign-in, even if you use a passkey.
- Updated
- Updated
- Reading time
- 4 min read
- Tags
- mfa2fasecurity
Even if you use Google or a passkey, adding a second factor protects you in the rare case your primary method is compromised.
Choose a second factor
Authenticator app (recommended), text message, or backup codes. Authenticator apps work offline and resist SIM-swap attacks — pick this if you have any choice. Text messages are convenient but a determined attacker can social-engineer your carrier; backup codes are perfect as a fallback when your phone is lost. You can have all three on the same account.
Setup steps
Authenticator app · works offline · resists SIM-swap
Step 1 - scan
Open your authenticator and tap +. Point the camera at the code.
Step 2 - confirm
No camera? Use code: PXLT 4ZXM ABRT 6YMR
Account → Security → Add second step. Scan the QR code with your authenticator (1Password, Authy, Google Authenticator, Microsoft Authenticator), enter the 6-digit code that appears on your phone to confirm the link, then save the backup codes somewhere safe. The whole flow takes under a minute the first time.
Save your backup codes
k4f9-q2m1p7x3-r8z6b1n5-w9c4h2j8-d6t0v5g7-l3y2s8e1-u4o9a6m2-i9k7f3d5-n0p8Print, save in a password manager, or screenshot to a secure album. Generating new codes invalidates this set.
EnWella generates 8 single-use backup codes when you finish setup. Each one signs you in once if you lose access to your authenticator (phone stolen, app glitched, traveling without your device). Print them and tuck them in a wallet, save them in a password manager, or screenshot to a secure album — whatever works for you. Generating a new set invalidates the old codes; do that immediately if you ever think a copy was exposed.