# Two-factor authentication

Ask for a code from your authenticator app every time you sign in. A stolen password is then not enough to open your knowledge base. It is optional, and on every plan.

## Turn it on

1. Open **Settings**, find **Two-factor authentication** and press **Enable**.
2. Scan the QR code with your authenticator app. Can't scan it? Type the key shown under the code instead.
3. Enter the six-digit code your app shows and press **Turn on**.
4. Save the ten recovery codes somewhere safe, then press **I've saved them**.

Use an authenticator app such as 1Password, Google Authenticator, Authy, Microsoft Authenticator, Bitwarden Authenticator or Apple Passwords.

If you signed in more than ten minutes ago, Hjarni asks you to sign in again before it shows the QR code. That way someone who finds your laptop unlocked later cannot turn it on and lock you out. Nothing changes on your account until a code matches, and Hjarni emails you once it is on.

## Signing in

Sign in the way you always do. After your password, or after Google, Apple, GitHub or your team's SSO, Hjarni shows one more step and asks for the code from your app.

Codes change every 30 seconds. A code from just before or just after the current one is accepted, so a small clock difference on your phone does not lock you out. Each code works once.

The mobile apps ask for the code the same way. Hjarni limits code attempts to slow down guessing.

The one sign-in that does not ask for a code is a [passkey](https://hjarni.com/docs/passkeys): your device already verified it was you before it signed, so it counts as both factors.

## Recovery codes

When you turn it on you get ten recovery codes, shown once. Store them where you keep other important passwords. If you lose your phone, type a recovery code instead of a code from the app. Each one works a single time, and Hjarni tells you how many are left.

New phone

Sign in with one recovery code. In Settings, use a second unused recovery code to turn two-factor authentication off, then turn it back on with the new phone.

Running low on codes

Open Settings, choose **New recovery codes**, enter a code from your app or an unused recovery code, and press **Replace codes**. The old codes stop working.

Lost phone and codes

There is no self-service reset. Email [evert@hjarni.com](mailto:evert@hjarni.com) from the address on your account to ask for help.

## What it covers

### Asks for a code

- Signing in on hjarni.com, with a password, Google, Apple, GitHub or SSO.
- Signing in to the iPhone, iPad, Mac and Android apps.
- Connecting a new assistant, unless that browser is already signed in.
- Turning two-factor authentication off, or replacing recovery codes.

### Keeps working as before

- ChatGPT, Claude and other assistants you already connected.
- REST API tokens you already created.
- Public links you shared.
- Browsers where you are already signed in.
- Signing in with a passkey, which is already two factors.

Claude, ChatGPT and other connected assistants use separate credentials, and so do API tokens. To cut one off, revoke it in **Settings > Connections**. See [Privacy, permissions, and AI boundaries](https://hjarni.com/docs/privacy-and-permissions#connections).

## Turn it off

Open **Settings**, choose **Turn off** under Two-factor authentication, and enter a code from your app or a recovery code. Hjarni asks for a code rather than your password, because someone at your unlocked laptop may know that too.

Turning it off deletes your recovery codes, and Hjarni emails you. You can turn it back on at any time with a new QR code.

Common questions

## FAQ

**Which authenticator apps work?**

Use an authenticator app such as 1Password, Google Authenticator, Authy, Microsoft Authenticator, Bitwarden Authenticator or Apple Passwords. Scan the QR code, or type the key shown under it.

**Is two-factor authentication a Pro feature?**

No. It is on every plan, Free included, and off until you turn it on.

**Does it work with Google, Apple, GitHub or SSO sign-in?**

Yes. Once it is on, Hjarni asks for a code after any sign-in, not only after a password.

**Will my ChatGPT or Claude connection stop working?**

No. Claude, ChatGPT and your API tokens use their own credentials and keep working. Connecting a new assistant needs you signed in, so a stolen password alone cannot connect one.

**What if I lose my phone?**

Sign in with one recovery code. In Settings, use a second unused recovery code to turn two-factor authentication off, then turn it back on with your new phone. Each recovery code works once.

**What if I lose my phone and my recovery codes?**

There is no self-service reset. Email [evert@hjarni.com](mailto:evert@hjarni.com) from the address on your account to ask for help.

**Does Hjarni support passkeys?**

Yes. A passkey signs you in with Face ID, Touch ID, a fingerprint or your device PIN, and it counts as both factors, so it does not ask for a code on top. See [Passkeys](https://hjarni.com/docs/passkeys).

## Related docs

[Privacy, permissions, and AI boundaries](https://hjarni.com/docs/privacy-and-permissions) | [Passkeys](https://hjarni.com/docs/passkeys) | [Single sign-on (SAML + SCIM)](https://hjarni.com/docs/sso) | [Security](https://hjarni.com/security) | [Announcement: Two-factor authentication](https://hjarni.com/changelog/two-factor-authentication)

Questions about signing in?

Email [evert@hjarni.com](mailto:evert@hjarni.com)
