VIRTLIX
🔐 Account & Security
Two-Factor Authentication
Docs / Account & Security / Two-Factor Authentication

Two-Factor Authentication

Two-Factor Authentication adds a TOTP (time-based one-time password) code requirement to login, on top of your regular password - the same standard supported by apps like Google Authenticator, Authy, or 1Password's built-in TOTP support.

Enabling 2FA from your Profile settings shows a QR code to scan with your authenticator app, then asks you to confirm with a code from that app before it's actually turned on - this confirms the app is set up correctly before your account starts requiring it on every login.

Recovery codes are generated when you enable 2FA - store them somewhere safe outside your authenticator app. If you lose access to the device generating your codes, a recovery code is the only way back into your account without contacting support.

Disabling 2FA requires re-entering your password, same security bar as enabling it, so a session left logged in on a shared machine can't be used to silently turn off your account's two-factor protection.