extmoney
Back to help center

Security and privacy

Two-factor authentication (2FA)

This translation was produced automatically and hasn't been reviewed yet.

Key points at a glance

  • 2FA adds a second login step to your password—a one-time 6-digit code from an authenticator app on your phone. Even if your password is stolen, this code is needed to log in.
  • When you enable it, you get backup codes—save them: they will help you log in if your phone is unavailable.
  • You can enable and disable 2FA in Settings → Security (on the web and in the mobile app).

How to enable

  1. Go to Settings → Security and click “Enable” next to two-factor authentication.
  2. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, etc.)—or enter the displayed secret manually.
  3. Enter the 6-digit code from the app to confirm. 2FA is now enabled.
  4. Save the backup codes that were displayed during setup (more on this below).

Logging in with 2FA enabled

After entering your login and password, the app will ask for a confirmation code. Enter the current 6-digit code from your authenticator app (it changes every 30 seconds)—and you'll be logged in. You can enter any backup code instead of the code from the app.

Backup codes

  • This is a list of one-time codes in case your authenticator phone is unavailable (lost, battery dead, device changed).
  • Each code works once. Save them in a secure place (password manager, printout).
  • How many codes are left is visible in Settings. When there are few left, generate a new set.

Regenerating backup codes requires confirmation

When you generate a new set of backup codes, all old codes immediately become invalid. Therefore, before issuing new codes, the app will ask you to enter the current authenticator code or one of the active backup codes.

This way, someone who has somehow gained access to an open session cannot secretly re-issue your backup codes—a second factor is still needed for this.

Disabling 2FA

In Settings → Security, click “Disable” and enter the current authenticator code or a backup code. After that, the second login step is removed, and all backup codes are deleted.

I lost my phone / access to the authenticator

Log in by entering a backup code at the confirmation step instead of the code from the app. After logging in, go immediately to Settings → Security and:

  • either regenerate backup codes (old ones will become invalid),
  • or reconnect the authenticator on a new phone (disable and re-enable 2FA).

I lost access to both my phone and backup codes

If you have neither the authenticator nor backup codes left, you won't be able to log in on your own (this is the point of the protection). Contact support. Resetting your password in this case does not disable 2FA—see password-reset-user-guide.md.


See also: password-reset-user-guide.md (password reset and how 2FA behaves during it), two-factor.md (technical description).


Was this helpful?
Back to help center