Skip to content

Two-Factor Authentication — Authenticator Codes, Backup Codes, Trusted Devices

August 9, 2026

You can now protect your Alfrada OS account with an authenticator app. Enable it once in Settings and every new sign-in asks for a 6-digit code on top of your password — with backup codes for lost phones and a "remember this device" option so your own machines stay friction-free.

What you can do

  • Enroll from Settings → Account → Security: scan a QR code with any TOTP app (Google Authenticator, 1Password, Authy, Apple Passwords) and confirm one code to switch it on.
  • Get 10 one-time backup codes at enrollment — shown once, each usable a single time when you don't have your phone.
  • Check "Remember this device for 30 days" at sign-in so your daily machines skip the code prompt; every device gets its own 30-day window, counted from the moment you trust it.
  • Revoke all trusted devices in one click from the Security tab — every device is asked for a code on its next login.
  • See your 2FA state at a glance: enabled/disabled, backup codes remaining, trusted devices outstanding.
  • Disable 2FA any time by entering a current authenticator code or a backup code — never silently.

Where this shows up

You sign in from a new laptop. After your password, Alfrada OS asks for the 6-digit code from your authenticator app — a stolen password alone no longer opens your account, your sessions, or your connected tools.

Your phone dies mid-trip. Enter one of your backup codes instead, then regenerate a fresh set from the Security tab when you're home.

You don't have 2FA on yet. After signing in you'll see a one-time setup nudge — enable it in under a minute, or snooze the prompt for 30 days.

Try it

  • Open Settings → Account → Security, click Enable two-factor authentication, and scan the QR code with your authenticator app.
  • Store the backup codes somewhere safe (password manager, printed copy) — they are shown only once.
  • On your next sign-in, tick Remember this device on the machines you own.

Heads up

  • Login challenges expire after 5 minutes and allow 5 attempts before you must sign in again.
  • Backup codes are single-use and only displayed at enrollment — if you run low, disable and re-enable 2FA to mint a fresh set.

Built for Alfrada OS.