> ## Documentation Index
> Fetch the complete documentation index at: https://docs.legalancer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-Factor Authentication

> Protect your account with an authenticator app, and know what to do if you lose it.

Once enabled, you're asked for a six-digit code on every sign-in, from every device — there is no trusted-device or remember-this-browser option. An authenticator app is the only supported second factor; there are no text-message codes, emailed codes, or security keys.

***

## Turning it on

Go to Security in your profile and use Enable 2FA.

<Steps>
  <Step title="Add the account to your authenticator">
    Scan the QR code with your authenticator app, or copy the Secret Key and paste it in.
  </Step>

  <Step title="Save the secret key">
    Store the secret key in your password manager. It's the only copy you'll be shown, and it's what lets you set up a replacement phone later.
  </Step>

  <Step title="Confirm the code">
    Enter the current six-digit code from your app and save.
  </Step>
</Steps>

<Warning>
  There are no backup or recovery codes. The saved secret key, or an authenticator that syncs across devices, is your entire safety net.
</Warning>

***

## Signing in

Enter the six digits from your app after your password. Codes are accepted a window either side of the current one, so slight clock drift is fine — but the verification step expires after five minutes, so if you're turned away with a correct code, start the sign-in again.

***

## If you lose your authenticator

There is no self-service recovery. Ask the agency handling your matter to send you a two-factor reset link — it arrives by email, is good for twenty-four hours, and walks you through setup again on the new device. Resetting your password does not switch two-factor off.

***

## Moving to a new phone or app

You can't add a second authenticator while one is active. Disable 2FA — which asks for a current code, so do it while the old app still works — then enable it again with the new one.
