---
id: en/general-settings/how-do-i-set-up-two-factor-authentication
title: "How Do I Set Up Two-Factor Authentication?"
category: general-settings
language: en
updated_at: 2025-12-14
url: https://help.bidx.io/en/general-settings/how-do-i-set-up-two-factor-authentication/
---
# How Do I Set Up Two-Factor Authentication?

## Overview

With two-factor authentication, you add an extra layer of protection to your account against unauthorized access. After activation, you’ll always be prompted to enter a 6-digit code in addition to your password when logging in. You can choose to receive this code via an authenticator app (like Google Authenticator) or by email – or activate both options at the same time.

## Accessing the Function

To find the setting, go to your **Account Settings** and open **Personal Settings**. Then scroll to the **Two-Factor Authentication** section.

## Step-by-Step Guide

### Step 1: Choose Your Method

In the **Two-Factor Authentication** section, go to **Select Authentication Method**. Here you can choose between **Authenticator App** and **Email**.

- With the **Authenticator App**, you set up 2FA through an app like Google Authenticator, which even works offline.
- With **Email**, you’ll receive a code sent to your registered email address during login.

### Step 2.1: Activate Authenticator App

Switch the toggle under the **Authenticator App** tab to **Enable App Authentication** (**ON**). A QR code will appear – scan this with your authenticator app. If scanning doesn’t work, you can enter the secret code shown next to the QR code manually into your app. Use **Copy to Clipboard** to quickly copy the code. After you’ve added it in your app, click **Save**. A dialog will then appear where you enter the 6-digit code generated by your app to confirm setup.

**Important:** Make sure you enter the code from your authenticator app correctly – otherwise, you’ll see a message saying, “The entered one-time password was incorrect.” If you already have another method enabled, you may need to remove it first.

### Step 2.2: Activate Email Authentication

Select the **Email** tab and switch **Enable Email Authentication** to **ON**. Your registered email address will appear. After clicking **Save**, a 6-digit code will automatically be sent to this address. Enter the code in the pop-up window to confirm setup.

If you don’t receive a code, be sure to check your spam folder. When logging in, if you need a new code, simply click “Didn’t receive a code? Send new code.” under the “2FA Authentication” section.

### Step 3: Verify Completion

Once set up, the dialog will close automatically. You’ll now see your active 2FA methods listed in the **Authorized Devices** area, such as **Authenticator App** or **Email: your@email.com**. You can disable any method at any time by clicking **Remove**.

You can use both methods in parallel. When logging in, you can choose which code to use for authentication.

### Step 4: Logging In With 2FA

Sign in as usual; if 2FA is enabled, the **2FA Authentication** page will appear. Enter your 6-digit code from your app or email into the six fields and click **Submit**. If you’re using email, you’ll also see the option “Didn’t receive a code? Send new code.” to request a new code.

If you enter the wrong or expired code, you’ll see a message saying “The entered one-time password was incorrect.”

## Settings & Options

- Under **Authorized Devices**, you’ll find a list of all currently active 2FA methods, which you can disable any time with **Remove**.
- In the **Select Authentication Method** section, you can freely switch between **Authenticator App** and **Email**, or use both at once.

## Limitations & Special Notes

- Email codes are only valid for a few minutes (about 5 minutes). After they expire, just request a new code.
- If you disable a method, it’s removed immediately – whether by the ON/OFF toggle or **Remove**.
- Incorrect entries are always returned with a clear error message.

## Tips & Best Practices

- For maximum security and reliability, we recommend using the **Authenticator App**. This works even if you don’t have email access or internet connection.
- It’s best to enable both methods (app and email). This gives you a fallback in case one device or service is unavailable.
- Never share the secret code that’s displayed during setup. Store it securely.
- Check your spam folder if you don’t get the email.
- Avoid enabling two-factor authentication on shared email accounts to prevent misuse.
