> For the complete documentation index, see [llms.txt](https://zerotick-trade.gitbook.io/documentation.v1.2/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zerotick-trade.gitbook.io/documentation.v1.2/user-guides/two-factor-authentication.md).

# Two-factor authentication

Two-factor authentication (2FA) adds a second check to your account: once you set it up, ZeroTick asks for a 6-digit code from your authenticator app before sensitive actions like withdrawals. You turn it on, turn it off, and manage it from **Account & Security**.

{% hint style="info" %}
You need to be signed in, and you need an authenticator app on your phone (such as Google Authenticator, Authy, or 1Password) to generate the codes. Set 2FA up before your first withdrawal; it protects exactly that flow.
{% endhint %}

#### Turn on two-factor authentication

{% stepper %}
{% step %}
**Open the Two-factor authentication card**

Open the profile menu (your avatar, top right of the navbar) and choose **Account & Security**. Find the **Two-factor authentication** card. Its status pill reads **Off** and its description reads "Require an authenticator code for sensitive actions". Press **Enable 2FA**.

![The Two-factor authentication card in Account & Security, showing the Off status and the Enable 2FA button](https://raw.githubusercontent.com/ZeroTick-Trade/Public-Assets/2e6995eabfe14239fd7ead6ac3785fe21c7dc747/docs/guides/account-and-security/two-factor-authentication/01-card-off.png)
{% endstep %}

{% step %}
**Scan the QR code**

The setup panel opens: "Scan this QR code with your authenticator app, then enter the 6-digit code." In your authenticator app, add a new account and scan the code on screen. If you cannot scan, copy the key shown under **Or enter this key manually** and type it into the app instead.
{% endstep %}

{% step %}
**Enter the 6-digit code**

Your authenticator app now shows a 6-digit code that changes every 30 seconds. Type the current code into the **6-digit code** field and press **Activate**. If the code does not match, "That code isn't valid. Try again." appears and the field clears; enter the next code your app shows.
{% endstep %}

{% step %}
**Save your backup codes**

The panel confirms **Two-factor authentication is on** and shows your one-time backup codes with the note "Save these backup codes somewhere safe. Each can be used once if you lose your authenticator." Press **Copy** to copy them, or **Download** to save them as `zerotick-2fa-backup-codes.txt`. Store them, then press **I've saved my backup codes** to finish.

{% hint style="danger" %}
Your backup codes appear only once, on this screen. Save them somewhere safe, private, and ideally offline, and never share them. They are your recovery codes for 2FA: if you lose both your authenticator app and these codes, you can be locked out of the actions 2FA protects and will need to contact support. Anyone who has them can pass your security checks.
{% endhint %}
{% endstep %}
{% endstepper %}

{% hint style="success" %}
When you finish, the card's pill reads **On** and a confirmation appears: "You'll be asked for a code on sensitive actions." From now on ZeroTick asks for a code where it matters, starting with withdrawals.
{% endhint %}

#### Turn off two-factor authentication

{% stepper %}
{% step %}
**Press Disable 2FA**

On the **Two-factor authentication** card, now showing **On**, press **Disable 2FA**.
{% endstep %}

{% step %}
**Enter a current code and confirm**

The **Disable two-factor authentication** dialog asks you to "Enter a current authenticator code to turn off 2FA." Type the current 6-digit code from your authenticator app and press **Confirm**. The card returns to **Off**, and a confirmation reads "Codes are no longer required." A wrong code shows "That code isn't valid. Try again." and lets you retry.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Turning 2FA off removes the code prompt from every action below, including external withdrawals. Leave it on unless you have a specific reason to disable it.
{% endhint %}

#### When ZeroTick asks for a 2FA code

Once 2FA is on, ZeroTick asks for a fresh code before the actions below. Most prompts are the same **Confirm with 2FA** dialog: "Enter a code from your authenticator app to continue." Sends to your own wallet (**My Wallet**) never ask for a code.

| Action                             | When a code is required                                                                                                                 |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Sending to an external address     | Every external send, whatever the amount, while **Require 2FA on every withdrawal** is on (the default).                                |
| A trade above your set amount      | When a trade's value is above **Require 2FA for trades above (USD)**. No code if you have not set that limit, or the trade is under it. |
| Changing your security settings    | When you save changes on the **Security limits & 2FA triggers** card.                                                                   |
| Closing your account               | On the final **Confirm** of **Close Account**.                                                                                          |
| Removing a saved withdrawal wallet | When you remove an address from your saved withdrawal list.                                                                             |

You decide which trades trigger a code, and can turn the withdrawal prompt on or off, on the **Security limits & 2FA triggers** card. See [Security settings](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/security-settings) for each control, and [Withdraw](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw) for the full send flow.

<details>

<summary>"That code isn't valid. Try again."</summary>

The code you entered does not match. Authenticator codes change every 30 seconds, so a code can expire while you type; wait for your app to show the next one and enter that. If every code is rejected, check that your phone's clock is set to update automatically, because a phone clock that drifts makes each code look wrong.

</details>

<details>

<summary>"Couldn't start 2FA setup. Please try again."</summary>

The setup panel could not load a new code. Press **Close**, then open the card and press **Enable 2FA** again. If it keeps failing, check your connection and retry.

</details>

<details>

<summary>I lost my authenticator app</summary>

If you lose your authenticator app, enter one of your one-time backup codes wherever ZeroTick asks for a code, including to turn 2FA off. Each backup code works once. If you have lost your backup codes too, contact ZeroTick support at <support@zerotick.trade>. Your wallet keys are non-custodial and remain yours regardless; see [Recovery kit](https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/recovery-kit) for backing those up.

</details>

#### Related guides

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Security settings</strong></td><td>Spending caps, 2FA triggers, and the withdrawal lock.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/security-settings">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/security-settings</a></td></tr><tr><td><strong>Withdraw</strong></td><td>Send funds to an external address, with the 2FA step.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/withdraw</a></td></tr><tr><td><strong>Recovery kit</strong></td><td>Back up your wallet keys so your funds are always recoverable.</td><td><a href="https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/recovery-kit">https://zerotick-trade.gitbook.io/documentation.v1.1/user-guides/recovery-kit</a></td></tr></tbody></table>
