Set Up an Authenticator App on Your Phone for 2FA Login
This guide is for customers who need to turn on two-factor authentication using an authenticator app on their phone. You will scan a QR code, save backup codes, and confirm the setup so your next login asks for a 6-digit code from your phone.
TL;DR — You will install an authenticator app on your phone, open your account's two-factor authentication settings, scan the QR code, and enter the 6-digit code the app shows. The most common issue is using the wrong code because the phone time is off or the code expired; wait for a fresh code and try again. Reading time: ~5 min
Goal
When you finish, your account will have two-factor authentication (2FA) enabled with an authenticator app on your phone, and your next sign-in will ask for your password plus a 6-digit code from that app.
Prerequisites
- Your account username and password for the website or app where you are enabling 2FA
- Access to your phone
- An authenticator app installed on your phone, such as one of these:
- Google Authenticator
- Microsoft Authenticator
- Duo Mobile
- 1Password or another password manager with one-time code support
- A stable internet connection on the device where you will log in
- A way to save backup codes safely, such as:
- your password manager's secure notes
- a printed copy stored somewhere private
- If your company requires it: access to your account settings page after sign-in
Steps
Step 1: Install an authenticator app on your phone
On your phone, open your app store and install one authenticator app.
Exact app store search terms:
Google Authenticator
Microsoft Authenticator
Duo Mobile
1Password
What you should see when this succeeds: the app is installed and opens on your phone.
Step 2: Sign in to your account and open the 2FA settings
In your account on the website, open the security settings. The exact menu names vary by provider, but use one of these common paths in your dashboard:
Profile picture → Account Settings → Security → Two-Factor Authentication
Settings → Security → 2FA
My Account → Login & Security → Authenticator App
Then select the option labeled one of these:
Enable two-factor authentication
Set up authenticator app
Add authentication app
Use an authenticator app
What you should see when this succeeds: a setup screen with a QR code and sometimes a manual setup key.
Step 3: Start adding an account in the authenticator app
Open the authenticator app on your phone and add a new account.
Common buttons or menu paths:
Google Authenticator → + → Scan a QR code
Microsoft Authenticator → + → Other account
Duo Mobile → Add → Use QR code
1Password → New Item → One-Time Password
If your phone asks for camera access, tap:
Allow
What you should see when this succeeds: the app is ready to scan a QR code.
Step 4: Scan the QR code from the website
Hold your phone over the QR code shown on the website.
If scanning does not work, use the manual key shown on the website instead. In your authenticator app, choose the manual-entry option if available, then enter:
Account name: your email address used for this login
Secret key: the exact key shown on the website
Type: Time-based or TOTP
("TOTP" means a time-based one-time password that changes every 30 seconds.)
What you should see when this succeeds: a new entry appears in the app with your account name and a 6-digit code that counts down and refreshes.
Step 5: Enter the 6-digit code to confirm setup
On the website, in the field for the verification code, type the current 6-digit code from your authenticator app.
Example format: 123456
Then click the button labeled one of these:
Verify
Confirm
Enable
Finish setup
If the code is about to expire, wait for the next code and enter the new one.
What you should see when this succeeds: the website shows that two-factor authentication is enabled.
Step 6: Save your backup or recovery codes
After 2FA is enabled, many sites show backup codes. These are one-time emergency codes you can use if you lose your phone.
Use the button shown on the page, usually one of these:
Download codes
Copy codes
Print codes
Show recovery codes
Save them in one safe place, such as:
Your password manager secure notes
A printed copy stored in a private location
Do not save them in an unprotected note on your phone.
What you should see when this succeeds: you have a saved copy of the backup codes and can find it again later.
Step 7: Test a fresh login before you close the page
Open a private browsing window and sign in again.
Common menu paths to sign out first:
Profile picture → Sign out
Account menu → Log out
Then sign in with your username and password. When prompted for the second factor, enter the current 6-digit code from the authenticator app.
What you should see when this succeeds: you can log in fully with your password and the code from your phone.
Verify it works
Use these end-to-end checks:
- Sign out of the account.
- Sign in again with your normal username and password.
- Confirm that the site asks for a second step, usually labeled one of these:
Enter authentication code
Enter 6-digit code
Two-factor authentication
Verification code
- Open your authenticator app and enter the current code.
- Confirm that you reach your account dashboard.
- Return to the account security page and confirm the status shows one of these:
Two-factor authentication: On
Authenticator app: Enabled
2FA status: Active
A successful result is: you cannot complete login with only your password, but you can complete login with your password plus the code from your authenticator app.
Common pitfalls
You scanned the QR code into the wrong app entry
Mistake: You added multiple accounts and selected the wrong 6-digit code.
Symptom: The site says the code is invalid even though the app is generating codes.
Fix: In the authenticator app, use the code for the entry that matches the website or your email address, then try again with a fresh code.
The code expired before you submitted it
Mistake: You typed a code near the end of its 30-second timer.
Symptom: The site rejects the code once, then accepts the next one.
Fix: Wait for the code to refresh, then immediately enter the new 6-digit code and click Verify.
Your phone time is wrong
Mistake: Your phone clock is manually set and not synced automatically.
Symptom: Every code is rejected, even fresh ones.
Fix: On your phone, turn on automatic date and time, then try again with the next code.
You closed the page before saving backup codes
Mistake: You finished setup but did not store the recovery codes.
Symptom: You can log in now, but you have no fallback if you lose your phone.
Fix: Go back to Account Settings → Security → Two-Factor Authentication and use Show recovery codes or Generate new backup codes if that option is available.
You set up 2FA on a shared or replaced phone
Mistake: The authenticator app was installed on a device you no longer control.
Symptom: You cannot get login codes after changing phones, or another person may still have access to your codes.
Fix: Sign in, go to Account Settings → Security → Two-Factor Authentication, remove the old authenticator app, then set it up again on your current phone and generate new backup codes.
You used SMS codes instead of the authenticator app
Mistake: You enabled text-message login codes when your company asked for an authenticator app.
Symptom: Login works with text messages, but your security page does not show Authenticator app: Enabled.
Fix: Return to Account Settings → Security → Two-Factor Authentication, choose Set up authenticator app, complete the QR-code setup, and then disable SMS if your policy requires app-based codes only.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI