# 2FA (Two Factor Auth / Two Step Auth) is finally available!

**URL:** <https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032>\
**Category:** Changelog\
**Tags:** announcements, security, bitriseio\
**Created:** [March 3, 2017, 3:31pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032 "2017-03-03T15:31:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![viktorbenei](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.bitrise.io/viktorbenei/32/18_2.png) [@viktorbenei](https://discuss.bitrise.io/u/viktorbenei)\
**Post date:** [March 3, 2017, 3:31pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/1 "2017-03-03T15:31:31Z")

</div>

We are pleased to announce that **2FA (two-factor authentication or two step authentication)** is available on [Bitrise.io](https://www.bitrise.io/) 🎉

**Two-factor authentication** gives another layer of security to your account, so if your password is compromised or stolen, only you can log in. With **2FA** enabled, you’ll be asked to provide your 2FA authentication code, as well as your password, when you access [Bitrise.io](https://www.bitrise.io/).

* * *

Let’s see how it works:

At first you have to navigate to your [Account settings](https://www.bitrise.io/me/profile) page and click on **[Security tab](https://www.bitrise.io/me/profile#/security)**.

* * *

 ![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/abbc1b090016e94157b40f59f0a7521a386ddb1f.png)

* * *

A pop-up will appear when you click on the **Enable** button.

 ![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/b4c2d037b896e33f4f0e48ef662b9cb8bdba7177.png)

Here you have to scan the displayed QR code.

You can do it with [Google Authenticator app](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2) (available as Chrome Web Browser [extension](https://chrome.google.com/webstore/detail/authenticator/bhghoamapcdpbohphigoooaddinpkbai) too), or with any other [TOTP](https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm) compatible app.

_[Install Google Authenticator - Google docs](https://support.google.com/accounts/answer/1066447?hl=en)_

* * *

After entering the 6-digit code which was generated by the app you will got your recovery codes.

 ![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/6ba58edb25a8d03bfe4e0eb591ea87e4a732783e.png)

Recovery codes are used to access your account in the event you cannot receive two-factor authentication code.  
Treat your recovery codes with the same level of attention as your password. **Save it to a safe place, away from curious eyes.** Also important to note that **these codes are single-use codes, once you signed in with a backup code that code is invalidated immediately and you can’t use it again!**

At this point you can download them if you click on **Download** button or you can copy to clipboard then paste and save wherever you want.

_Note, you can’t view your backup codes again, but you can generate new ones as far as you’re authenticated, e.g. in case you just signed in with the last backup code._

_Copy button is not available on mobile, under screen size 768px and it doesn’t work with Safari \<10.0, but of course you can just select+copy+paste these as any other text._

If the **2FA** was activated successfully and you clicked on the **Done** button the popup will disappear and you will see some changes on the page.

 ![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/9298eba075d3b5205b8755ed32e8aa1d6df2bc55.png)

* * *

By clicking on **Disable** button a warning popup will appear where you can cancel or confirm your action.

![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/8eaf1f3293940fa3e30ecb6ee8fe738b4ec7ad71.png)

Also you can **Generate new recovery codes** - in this case the popup with **Recovery codes** will appear and you can save them. Important, **when you generate new recovery/backup codes, the previously generated codes are invalidated and can’t be used for login anymore!**

_This action have to be confirmed in a warning popup._

![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/064e19039f473de72cd689d61f54fe9c1f4c57d4.png)

* * *

If **2FA is enabled** [Bitrise.io](https://www.bitrise.io/) will ask you to provide your 2FA authentication code during logins; if you’ve logged out, are using a new device, or your session expires.

After you entered your username and password or you signed in with your git provider, you have to enter the authentication code to verify your identity.

![](https://us1.discourse-cdn.com/flex016/uploads/bitrise/original/1X/fdf344638209c3c9e1c3ccaa141e212e8cd44ecd.png)

You can enter your **recovery codes** here instead of the 2FA code to access your account in the event you cannot receive two-factor authentication codes, but recovery codes are single-use codes, you can only use a specific code once! If you’re close to using your last codes please generate new ones!

_Notice: If your authentication fails several times, you may wish to synchronise your phone’s clock with your mobile provider. Often, this involves checking the “Set automatically” option on your phone’s clock, rather than providing your own time zone._

Last but not least, **if you enable 2FA and you lose your device as well as your backup codes, we can’t reset it for you!** Please be very careful with backing up these codes!

Thank you everyone who voted on the related feature request ([Two-factor authentication](http://discuss.bitrise.io/t/two-factor-authentication/469)), it helped a lot to prioritize this long awaited feature! 😉

As always, if you’d have any questions just let us know, and Happy Building! 🚀

---

<div class="post-metadata">

**Author:** ![bootstraponline](https://avatars.discourse-cdn.com/v4/letter/b/c68b51/32.png) [@bootstraponline](https://discuss.bitrise.io/u/bootstraponline)\
**Post date:** [March 3, 2017, 3:56pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/2 "2017-03-03T15:56:25Z")

</div>

- Are yubikeys supported (as implemented by GitHub)?
- Is there a way to force 2FA on organizations (as implemented by GitHub)?

---

<div class="post-metadata">

**Author:** ![viktorbenei](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.bitrise.io/viktorbenei/32/18_2.png) [@viktorbenei](https://discuss.bitrise.io/u/viktorbenei)\
**Post date:** [March 3, 2017, 4:21pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/3 "2017-03-03T16:21:17Z")

</div>

Not yet, but feel free to create a new #feature-request - we definitely plan to provide the “force” feature, but for now we want to see how 2FA is utilized, and optimize the UX.

---

<div class="post-metadata">

**Author:** ![bootstraponline](https://avatars.discourse-cdn.com/v4/letter/b/c68b51/32.png) [@bootstraponline](https://discuss.bitrise.io/u/bootstraponline)\
**Post date:** [March 3, 2017, 4:51pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/4 "2017-03-03T16:51:00Z")

</div>

I opened a feature request:

> [@Yubikey support](http://discuss.bitrise.io/t/yubikey-support/1033):
>
> Support Universal 2nd Factor authentication & Yubikeys as GitHub does.

The UX of authentication codes is awful.

---

<div class="post-metadata">

**Author:** ![viktorbenei](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.bitrise.io/viktorbenei/32/18_2.png) [@viktorbenei](https://discuss.bitrise.io/u/viktorbenei)\
**Post date:** [March 3, 2017, 4:51pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/5 "2017-03-03T16:51:58Z")

</div>

> [@bootstraponline](#):
>
> The UX of authentication codes is awful.

Can you be a bit more specific? 😉

---

<div class="post-metadata">

**Author:** ![bootstraponline](https://avatars.discourse-cdn.com/v4/letter/b/c68b51/32.png) [@bootstraponline](https://discuss.bitrise.io/u/bootstraponline)\
**Post date:** [March 3, 2017, 4:54pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/6 "2017-03-03T16:54:45Z")

</div>

Have you used them…? U2F enables pressing a button for signing in. It’s both more secure and easier than generating random codes on a potentially insecure cellphone.

Google also has great support for them.

> **[Google Account Security with YubiKey | Yubico](https://www.yubico.com/works-with-yubikey/catalog/google-accounts/)**
>
> Learn how adding a YubiKey to your Google account's 2-step verification will help you protect and secure your experience on Mail, YouTube, Hangouts & more.

---

<div class="post-metadata">

**Author:** ![viktorbenei](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.bitrise.io/viktorbenei/32/18_2.png) [@viktorbenei](https://discuss.bitrise.io/u/viktorbenei)\
**Post date:** [March 3, 2017, 4:57pm UTC](https://discuss.bitrise.io/t/2fa-two-factor-auth-two-step-auth-is-finally-available/1032/7 "2017-03-03T16:57:16Z")

</div>

Ahhh, sorry, I completely misunderstood you - I thought you meant the UX/design (of 2FA) on [bitrise.io](http://bitrise.io) specifically is awful / that you had issues with setting up 2FA on [bitrise.io](http://bitrise.io).

Re U2F vs 2FA (UX) - I agree 😉
