# Two-factor authentication

Your knowledge base holds what you would not paste into a public chat. A password alone is one leak away from someone else reading it.

You can now turn on two-factor authentication. Once it is on, signing in asks for a six-digit code from an authenticator app such as 1Password, Google Authenticator or Authy. It asks every time, whether you sign in with a password or with Google, Apple, GitHub or your team's SSO, on the web and in the mobile apps.

**Turn it on in Settings.** Open Settings, find Two-factor authentication and press Enable. Scan the QR code with your app and enter the code it shows. If you signed in a while ago, Hjarni asks you to sign in again first.

**Save your recovery codes.** You get ten, shown once. Lose your phone and each one works a single time in place of a code. Replace the set from Settings whenever you like.

**Your AI stays connected.** Claude, ChatGPT and your API tokens keep working after you turn it on, because they connect with their own credentials. Connecting a new assistant needs you signed in, so a stolen password alone cannot connect one.

It is off until you turn it on, on every plan. Hjarni emails you whenever it is turned on or off.

[Open Settings.](/settings) The details, including what to do if you lose your phone, are in [Two-factor authentication](/docs/two-factor-authentication).
