Two-Factor Authentication (2FA)

What two-factor authentication does and why we recommend turning it on

Last updated May 2, 2026

What Is 2FA?

Two-factor authentication adds a second verification step when you sign in. Even if someone obtains your password, they cannot access your account without the second factor — a time-based code from your authenticator app.

We strongly recommend enabling 2FA. For the click-by-click walkthrough — including saving your recovery codes — see setting up two-factor authentication.

Quick Setup Summary

  1. Go to Settings > Security
  2. Select Enable Two-Factor Authentication
  3. Open your authenticator app (Google Authenticator, Authy, or any TOTP-compatible app)
  4. Scan the QR code displayed on screen
  5. Enter the six-digit code from your authenticator app to confirm
  6. Save your recovery codes — store them somewhere secure

Recovery Codes

During setup, you receive a set of one-time recovery codes. These are critical:

  • Each code can be used once to sign in if you lose access to your authenticator app
  • Store them in a safe place — a password manager, a printed copy in a secure location, or both
  • If you run low, generate a new set from Settings > Security — generating new codes invalidates the old ones

Do not share your recovery codes with anyone.

Trusted Device

When signing in, you can tick Trust this device for 3 days to skip 2FA on the same browser for that window. After three days, or if you clear cookies, sign out, or change your password, the trust expires. Do not trust shared or public devices.

Step-Up Verification for Bank Linking

Once 2FA is enabled, connecting a new bank account through Plaid asks you to re-verify with a fresh authenticator code, even inside an existing session. Linking a bank is a high-risk action so we add this extra check. Most other actions in the app rely on your normal session — if you signed in with 2FA, you stay signed in until your session expires.

Supported Authenticator Apps

Any TOTP (Time-based One-Time Password) compatible app works:

  • Google Authenticator (Android, iOS)
  • Authy (Android, iOS, Desktop)
  • Microsoft Authenticator (Android, iOS)
  • 1Password, Bitwarden, and other password managers with TOTP support

Disabling 2FA

If you need to turn off 2FA:

  1. Go to Settings > Security
  2. Select Disable Two-Factor Authentication
  3. Confirm with your current authenticator code

We recommend keeping 2FA enabled for the strongest account security. See data security overview for our broader security practices.

#2fa#security#authentication

Still have questions?

Contact us