> For the complete documentation index, see [llms.txt](https://docs.enapi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.enapi.com/advanced-features/two-factor-authentication.md).

# Two-Factor Authentication

Protect your ENAPI portal account with an authenticator app and recovery codes.

Two-factor authentication (2FA) adds a second step to your sign-in. After your password, ENAPI asks for a one-time code from an authenticator app on your phone. Someone who learns your password still cannot sign in without that phone.

You can also keep a set of **recovery codes**, so you can still sign in if you lose access to your phone.

{% hint style="info" %}
Two-factor authentication is a personal setting. Each member of your team turns it on for their own account.
{% endhint %}

## What you need

An authenticator app on your phone, for example Google Authenticator, Microsoft Authenticator, 1Password or Authy. Any app that supports time-based one-time passwords (TOTP) works.

## Turn on two-factor authentication

1. Click **Settings** at the bottom of the sidebar and open **Profile**.
2. Under **Two-factor authentication**, click **Set up authenticator app**.
3. If you signed in a while ago, ENAPI asks for your password again first.
4. Open your authenticator app and scan the QR code on the screen. If you cannot scan it, choose the option to enter the key by hand instead.
5. Enter the six-digit code your app shows. You can also give the device a name, such as "Work phone", so you can recognise it later.
6. Confirm. You return to your profile page, where two-factor authentication now shows **Enabled**.

![Two-factor authentication on the profile page, with an authenticator app set up](https://303450155-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FheBP0sH0U1Rrp1jIot9S%2Fuploads%2FU70zuc2KgEI9lzDuv3YY%2Ftwo-factor-profile.webp?alt=media)

From now on, ENAPI asks for a code from your authenticator app every time you sign in.

## Generate recovery codes

Recovery codes let you sign in when you do not have your phone. We strongly recommend that you generate them as soon as you have set up your authenticator app.

1. On your profile page, in the **Recovery codes** box, click **Generate recovery codes**.
2. ENAPI shows a set of single-use codes. Copy, download or print them, and keep them somewhere safe, such as your password manager.
3. Confirm that you have saved them.

{% hint style="warning" %}
The codes are shown only once. ENAPI cannot show them to you again later.
{% endhint %}

Each code works once. Your profile page shows how many codes you have left. When you run low, click **Generate new codes**. A new set replaces the old one, and the old codes stop working.

## Sign in with two-factor authentication

1. Sign in with your email address and password as usual.
2. ENAPI asks for a **One-time code**. Open your authenticator app and enter the code it shows for ENAPI.
3. Click **Sign in**.

![The one-time code step at sign-in](https://303450155-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FheBP0sH0U1Rrp1jIot9S%2Fuploads%2FXiWHZjz3atzJSuyRkWxQ%2Ftwo-factor-sign-in.webp?alt=media)

Codes change every 30 seconds. If a code is rejected, wait for the next one and try again.

### Sign in with a recovery code

If you do not have your phone, choose **Try another way** on the one-time code step, select the recovery code option and enter one of your recovery codes.

Once you are signed in, remove the lost device from your profile page and set up your new phone.

## Add another device

You can use more than one authenticator app, for example on a phone and a tablet. On your profile page, click **Add another device** and follow the same steps as above. Any of your devices can then give you a code at sign-in.

## Remove an authenticator app

1. On your profile page, click **Remove** next to the device.
2. Confirm. ENAPI asks you to confirm your identity first.

The device can no longer be used to sign in.

{% hint style="info" %}
If you remove your last authenticator app, two-factor authentication is turned off and your recovery codes are deleted too. You then sign in with your password only, until you set up an authenticator app again.
{% endhint %}

## Lost your phone and your recovery codes?

Contact ENAPI support. Once we have confirmed your identity, we remove the authenticator app from your account. You can then sign in with your password and set up two-factor authentication again.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.enapi.com/advanced-features/two-factor-authentication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
