Two-factor authentication and passkeys
An authenticator code on top of your password, or passwordless sign-in with Touch ID, Face ID or Windows Hello.
Updated:
There are two ways to protect your account better: ask for a 6-digit code from an authenticator app on top of your password (two-factor authentication), or use a passkey instead of a password. Signing in with Google or a passkey is already two-factor, so the code is only needed for password sign-in.
Turn on two-factor authentication
- Open Settings → Account & security and expand Two-factor authentication.
- Click Turn on.
- Scan the QR code with your authenticator app (e.g. the iPhone Passwords app, Google Authenticator, Microsoft Authenticator, 1Password). On the same device you can use Open in authenticator app or the key after Manual key: instead.
- Enter the 6-digit code the app shows now.
- Click Confirm.
From then on, password sign-in also asks for the Authentication code. Each code works only once, and too many wrong codes lock sign-in for a while.
Turn it off
Enter a current code in the code field and click Turn off.
Add a passkey
- On Account & security, expand Sign-in methods.
- In the Passkeys – Touch ID / Face ID row, click the add button (on a Mac e.g. + Add Touch ID).
- Confirm on your device with your fingerprint, face or Windows Hello.
The key stays on your device (or in iCloud Keychain); the server only stores its public part. Next time, use the passkey button on the sign-in page. Remove a passkey with Remove.
Was this article helpful?
Related articles
- Sign-in methods: Google, Microsoft, password, passkey, AppleThe ways you can sign in to Sayweek, how to set a password, and when you can turn password sign-in off.
- Devices and sessions, sign out everywhereSee which browsers and apps are signed in, sign out a lost phone, and what “Sign out everywhere” does.
- Activity log: who did whatOwners see approvals, deletions, settings changes, sign-ins and other security events in the activity log.
- Export your data and delete your accountDownload all your data as a JSON file, see the data processors, and delete your workspace permanently.