# Two-Factor Authentication ☁

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/two-factor-authentication
Last updated: 2026-10-03

Turn on and manage two-factor authentication (2FA) for your NocoDB account.

Two-factor authentication (2FA) adds a second layer of security to your NocoDB account. After you enter your password, you also enter a time-based one-time code. An authenticator app on your phone gives you this code.

## Setting up 2FA

### Prerequisites

* Sign in to NocoDB with **email and password**. If you signed in with Google or another identity provider, sign out. Then sign in again with email and password.
* Install an authenticator app that supports TOTP. For example: Google Authenticator, Microsoft Authenticator, Authy, or 1Password.

### Steps

1. In the bottom-left corner, click your avatar. Then select **Account Settings**.

<img alt="Account panel" src={__img0} placeholder="blur" />

2. Go to the **Security** tab.

<img alt="Security tab" src={__img1} placeholder="blur" />

3. Click **Enable 2FA**.

<img alt="Enable 2FA button" src={__img2} placeholder="blur" />

4. Enter your current password. Click **Next**.

<img alt="Enter password" src={__img3} placeholder="blur" />

5. Open your authenticator app and scan the QR code on the screen. If you cannot scan the QR code, click the copy button next to the manual entry key. Add the key to your authenticator app manually. Click **Next**.

<img alt="Scan QR code" src={__img4} placeholder="blur" />

6. Enter the 6-digit verification code from your authenticator app. Click **Verify**.

<img alt="Enter verification code" src={__img5} placeholder="blur" />

7. NocoDB shows 10 one-time backup codes. **Copy or write these down immediately** and keep them in a safe place. You can use each code only once. To complete the setup, click **I've saved these codes**.

<img alt="Backup codes" src={__img6} placeholder="blur" />

2FA is now active on your account.

<img alt="2FA enabled" src={__img7} placeholder="blur" />

## Signing in with 2FA

When 2FA is enabled, each sign-in has a second verification step after your password.

1. Enter your email and password.
2. On the **Two-Factor Authentication** screen, enter the current 6-digit code from your authenticator app. Click **Verify**.

<img alt="Sign in with TOTP" src={__img8} placeholder="blur" />

3. If you cannot use your authenticator app, click **Use a backup code instead**. Enter one of your saved backup codes (in `xxxx-xxxx` format). Click **Verify**. To go back to the authenticator code view at any time, click **Use authenticator code instead**.

<img alt="Sign in with backup code" src={__img9} placeholder="blur" />

4. To stop the sign-in and go back to the login screen, click **Cancel**.

<Callout type="info">
  The verification step must be completed within 

  **5 minutes**

   of entering your password. If it expires, sign in again.
</Callout>

<Callout type="warning">
  Each backup code can only be used 

  **once**

  . After signing in with a backup code, it is consumed and cannot be reused.
</Callout>

## Backup codes

Backup codes are emergency access codes. Use them when you cannot use your authenticator app, for example when you lose your phone or uninstall the app.

* You get **10 backup codes** when you enable 2FA.
* You can use each code only **once**. A successful sign-in uses up the code.
* Codes have the `xxxx-xxxx` format. When you enter a code, NocoDB ignores dashes, spaces, and letter case.

### Regenerating backup codes

Do these steps if you used most of your backup codes, or if you think that someone else knows them:

1. Go to **Account Settings** > **Security**.
2. Click **Regenerate Backup Codes**.
3. To verify your identity, enter a current 6-digit code from your authenticator app.

<img alt="Regenerate backup codes" src={__img10} placeholder="blur" />

4. Your old backup codes stop working **immediately**. NocoDB shows the new codes.
5. Copy and save the new codes. Then click **I've saved these codes**.

## Disabling 2FA

1. Go to **Account Settings** > **Security**.
2. Click **Disable 2FA**.
3. Read the warning. To confirm, click **Disable 2FA**.

<img alt="Disable 2FA" src={__img11} placeholder="blur" />

NocoDB permanently deletes your TOTP secret and all backup codes. If you enable 2FA again later, you do the full setup again. You get a new secret and new backup codes.

## Troubleshooting

### "Invalid verification code"

* Make sure that the clock on your device is correct. TOTP codes depend on the time. A clock difference of 30 seconds can cause codes to fail. Turn on automatic time sync on your device.
* Make sure that you enter the code for the correct account. The label in your authenticator app must show "NocoDB".
* Codes change every 30 seconds. If a code is about to expire, wait for the next code.

### Lost access to authenticator app and no backup codes

Contact your NocoDB workspace administrator or system admin. An admin can disable 2FA on your account from the backend. If you cannot use your authenticator app and all your backup codes, you cannot recover access yourself.

### "Too many failed attempts"

After 5 failed verification attempts in a row, NocoDB locks your account for **15 minutes**. Wait until the lockout period ends, then try again. Before you try again, make sure that the clock on your device is synced correctly.

### Migrating to a new phone

Before you change devices:

1. If your authenticator app has cloud backup or multi-device sync (for example, Authy, Microsoft Authenticator, 1Password), your codes move to the new device automatically.
2. If it does not, disable 2FA on NocoDB and change devices. Then enable 2FA again and scan the new QR code on your new phone.
3. As an alternative, keep your backup codes available. Sign in with a backup code. Then disable 2FA and enable it again to set up the new device.

## Good to know

* You can enable two-factor authentication only when you sign in with **email and password**. If you signed in with Google, SAML, OIDC, or another identity provider, that provider manages your authentication. 2FA is then not available in NocoDB.

## Availability

* Two-factor authentication is available on all **NocoDB Cloud** plans and on licensed self-hosted deployments (Business plan and above).

---

## Related pages

- [Google OAuth](https://nocodb.com/docs/product/account-settings/authentication/google-oauth.md): Configure Google OAuth 2.0 so users can sign in to NocoDB with their Google credentials.
- [SCIM](https://nocodb.com/docs/product/account-settings/authentication/scim.md): Configure SCIM v2.0 in NocoDB to provision users and groups automatically from your identity provider.
- [SSO FAQs](https://nocodb.com/docs/product/account-settings/authentication/FAQs.md): Answers to frequently asked questions about Single Sign-On (SSO) in NocoDB.
