Two-factor authentication (2FA) requires a second step after your password. Your site admin chooses which methods are allowed: an authenticator app (time-based codes) and/or email codes.
Admin setup: Enable 2FA in Security Ninja.
First-time setup
When 2FA is enabled (and your role requires it, or you opt in), you are prompted on login.
- Enter your username and password as usual.
- Authenticator app: Scan the QR code (or enter the secret manually) in an app such as Google Authenticator or Authy, then enter the 6-digit code to confirm.
- Email codes: If the admin enabled email as a method, choose Email code, send a verification code to your inbox, and enter it on the login screen.
When both methods are enabled, you choose a preferred method at login. That preference is remembered.
- After a successful code, you are logged in.
If the admin set a grace period (default 14 days), you may see a link to skip setup for that period. A grace of 0 means required-role users cannot skip.
Logging in after setup
- Enter username and password.
- Enter the code from your authenticator app, or the email code if that is your method.
- When the code is valid, you see a confirmation and are signed in.
Resetting 2FA
Admins can reset 2FA from How to reset 2FA. If you are locked out, use the secret access URL or ask an admin to reset or bypass 2FA for your account.



