Two-factor authentication (2FA) requires a second step after your password. Your site admin chooses which methods are allowed: an authenticator app (time-based codes) and/or email codes.
Admin setup: Enable 2FA in Security Ninja.
First-time setup
When 2FA is enabled (and your role requires it, or you opt in), you are prompted on login.
- Enter your username and password as usual.
- Authenticator app: Scan the QR code (or enter the secret manually) in an app such as Google Authenticator or Authy, then enter the 6-digit code to confirm.
- Email codes: If the admin enabled email as a method, choose Email code, send a verification code to your inbox, and enter it on the login screen.
When both methods are enabled, you choose a preferred method at login. That preference is remembered.
- After a successful code, you are logged in.
If the admin set a grace period (default 14 days), you may see a link to skip setup for that period. A grace of 0 means required-role users cannot skip.
Logging in after setup
- Enter username and password.
- Enter the code from your authenticator app, or the email code if that is your method.
- When the code is valid, you see a confirmation and are signed in.
Resetting 2FA
Admins can reset 2FA for users from the tools/settings described in How to reset 2FA. If you are locked out, use the secret access URL or ask an admin to reset your 2FA.



