# Setting up two-factor authentication

> Turn on two-factor authentication so signing in to Hiresweep needs a code from your authenticator app as well as your password.

With two-factor authentication on, signing in with your password also asks for a 6-digit code from an authenticator app, such as Google Authenticator, Microsoft Authenticator, 1Password or Authy.

## Before you start

Two-factor authentication protects password sign-in, so your account needs a password. If you signed up with Google, GitHub or LinkedIn, the **Two-factor authentication** row is hidden until you set one:

1. Go to **Settings** → **Sign-in & security**.
2. In the **Password** row, which shows **Not set**, select **Set password**.
3. Enter your email address, select **Send reset link** and open the **Reset your password** email.
4. Select **Create New Password**, enter a **New password** and select **Save new password**.

## Turn it on

<Steps>
  <Step title="Open Sign-in & security">
    Select **Settings** in the dashboard sidebar, then **Sign-in & security** under **Account**.
  </Step>
  <Step title="Select Turn on">
    In the **Two-factor authentication** row, which shows **Off**, select **Turn on**.
  </Step>
  <Step title="Confirm your password">
    In **Turn on two-factor sign-in**, enter your **Password** and select **Continue**.
  </Step>
  <Step title="Add Hiresweep to your authenticator app">
    In **Set up your authenticator app**, scan the QR code with your app. If you can't scan it, select **Copy setup key** and paste the key into the app.

    Enter the 6-digit code the app shows and select **Verify code**.

  </Step>
  <Step title="Save your backup codes">
    In **Save your backup codes**, you get 10 codes. Select **Download codes** or **Copy codes** and keep them somewhere safe, such as a password manager. Each code signs you in once if you lose your phone.

    Select **Finish setup**. The row now shows **On**.

  </Step>
</Steps>

<Warning>
  Without your phone or your backup codes, you can't finish signing in with your password. Save the codes before you
  select **Finish setup**.
</Warning>

## Sign in with two-factor authentication

After you enter your email or username and password, Hiresweep shows **Two-factor authentication**. Enter the current code from your authenticator app and select **Verify**.

If you don't have your phone, select **Lost access to your authenticator?**, enter one of your backup codes in **Backup code** and select **Verify**. Type the code as it was given, including the hyphen (for example `abcde-12345`). Each backup code works once.

Signing in with a [passkey](https://docs.hiresweep.com/guides/setting-up-passkeys) doesn't ask for a code.

## Turn it off

<Steps>
  <Step title="Select Turn off">
    In **Settings** → **Sign-in & security**, select **Turn off** in the **Two-factor authentication** row.
  </Step>
  <Step title="Confirm with your password">
    Enter your **Password** and select **Turn off two-factor**. From then on, your password alone signs you in.
  </Step>
</Steps>

## Troubleshooting

<AccordionGroup>
  <Accordion title="That code didn't work">
    Codes change every 30 seconds. Enter the newest one. If codes keep failing, check that your phone's clock is set
    automatically. After 5 wrong attempts, wait 10 minutes before trying again.
  </Accordion>
  <Accordion title="I don't see the Two-factor authentication row">
    Your account has no password. Set one with **Set password** in the **Password** row, then come back.
  </Accordion>
</AccordionGroup>
