> For the complete documentation index, see [llms.txt](https://documentation.opencollective.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.opencollective.com/advanced/security-for-accounts/two-factor-authentication.md).

# Two Factor Authentication

You can opt to add two-factor authentication as part of your login process at Open Collective, adding an extra layer of security to your account.

Users can choose to add two-factor authentication to their Open Collective accounts. This helps to keep your account safe.

### Why Two-Factor Authentication?

Two-factor authentication provides an additional level of security for your account. If your password or email address is compromised, your account will still be protected so long as your two-factor authentication is secure.

### Enabling Two-Factor Authentication

Navigate to your Dashboard > Settings > Security.

To enable 2FA, you will require a secondary authenticator service or product, such as an authenticator app, a YubiKey, or a fingerprint sensor.

**How to use an Authenticator App**

We recommend using Google Authenticator or 1Password.

Scan the QR code displayed on the screen with your authenticator app, and your app should offer you a time-limited six-digit code.

Type this code into the box provided to complete the process. You will now be asked for a six-figure code from the app each time you log in to your Open Collective account.

{% hint style="warning" %}
Once you’re set up, do not delete the entry for Open Collective from your authenticator app.
{% endhint %}

### Recovery Codes

When you set up the 2FA process on Open Collective, you will be given some recovery codes. These codes are an emergency option to help you access your account if you are unable to use your authenticator app.

{% hint style="warning" %}
Store these codes in a safe place, such as a password manager app.
{% endhint %}

If you get locked out of your account due to 2FA, [please contact our support team](http://opencollective.com/help). In some cases, we may need to ask you for substantial proof that the account is indeed yours.

### Enforce 2FA for all admins

You can require all your admins to enable 2FA on their profiles to perform tasks.

Opt in to enforce 2FA for all your admins. Any attempt to trigger admin operations or visit the admin pages will be blocked until admins enable 2FA on their profiles. Projects and events inherit the 2FA settings.

To enable 2FA for all admins, navigate to your Collective, Organization, or Fiscal Host Dashboard > Settings > Security and turn on two-factor authentication. Make sure to press save.

When visiting admin pages, your admins will be prompted to activate their 2FA.

### Actions that prompt for a 2FA code

If 2FA is enabled on your account, some sensitive actions ask for a code. Changing your organization's [platform subscription](/organizations/platform-subscription.md) always prompts for a code. Connecting a bank account or Wise, and paying expenses when your fiscal host requires 2FA for payouts, also prompt for a code.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://documentation.opencollective.com/advanced/security-for-accounts/two-factor-authentication.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
