Two-Step Verification
By the end of this page your account takes a 6-digit code as well as a password — somebody holding only the password cannot get in, and you still have a way back in if you lose your phone.
Before you start
1. Turn on the authenticator app
- 1
Open Sign-in security
Where: Settings → My account → Sign-in security → the Authenticator app card at the top.
- 2
Start the setup
What to do: click "Turn on". If you started this once and left halfway through, the button reads "Finish setup" instead — click that and carry on.
- 3
Scan the QR code
What to do: scan the QR code on screen with your authenticator app. If you are reading this page on the phone itself and cannot scan it, click "Copy" next to the key and paste it into the app's manual-entry option.
- 4
Enter the 6 digits
What to do: type the number your app is showing into "Verification code" and click "Turn on". How you know it worked: the status on the card changes from "Off" to "On".
- 5
Save the 10 recovery codes
What to do: this step hands you 10 recovery codes, once. Copy them into your password manager, or print them and put them in a drawer. Click "I've saved them" once they are somewhere safe.
The recovery codes appear only once
2. Signing in gains a step
Once it is on, signing in to the web admin and to the phone apps takes two steps: username and password first, then the 6-digit code from your authenticator app. The number changes every 30 seconds, so just type whichever one is showing.
- On the web — once the password goes through, a code box appears, with "Use a recovery code" on the line below it.
- In the Android / iOS apps — the same extra screen, and you can switch to a recovery code there too. The app stays signed in afterwards as it always did, so this is not a daily chore.
- Five wrong codes in a row locks you out for 5 minutes — that is there to stop somebody who has your password from grinding through codes. Wait five minutes and try again; nobody has to unlock anything for you.
A phone clock that has drifted looks exactly like a wrong code
Coming in through single sign-on does not ask for a code again
3. Lost phone, wiped authenticator
- 1
Use a recovery code first
What to do: at the code step on the sign-in page, click "Use a recovery code" and enter one of the codes you saved. Note: each code works once and is then spent. The card shows how many are left; when that number gets low, click "Generate new recovery codes" for a fresh set.
- 2
Set up a new phone once you are back in
What to do: Settings → My account → Sign-in security → "Turn off" (it asks for your current password), then walk through section 1 again and scan the QR code with the new phone.
- 3
Out of recovery codes too? Ask an admin
What to do: ask an admin to open Settings → Users, click your name → "Security & test" → "Reset two-step verification". After that: your password is unchanged, your next sign-in needs the password alone, and you set a new phone up once you are in.
If you are the only admin, guard those recovery codes
4. Turning it off
Settings → My account → Sign-in security → "Turn off", and enter your current password once. From then on the password alone signs you in, and every recovery code stops working at the same moment. Changing phones or changing authenticator apps goes the same way: turn it off, then turn it on again.
5. Where it does not work yet
Two-step verification covers the web admin and the phone apps. The following still accept nothing but a username and password, and sign-in fails against an account that has it turned on:
- The big-screen interface connected to your TV — give it an account of its own with two-step verification left off, and read-only camera access.
- Older versions of the mobile app — they report a failed sign-in without saying why. Update the app and it works.
- Older versions of the Home Assistant integration — the current version sends you to SkyView to authorize instead, which is fine with two-step verification on. If you are still on an older one, update it first; see Home Assistant.
6. Common questions
- It says the code is wrong and I am sure I typed it right — nine times out of ten the phone's clock has drifted; see above. The other possibility is two entries with the same name in the app (easy to end up with after changing the server address) — delete the stale one.
- Do I have to use a phone — no. The desktop versions of password managers such as 1Password and Bitwarden work as authenticators, so you can do the scanning step on the computer itself.
- Will the phone app ask for a code every time now — no. The app stays signed in as before; you only see the code step when you sign in again.
- Can an admin see my codes or my recovery codes — no. Recovery codes are shown once, at the moment they are generated, and what the server keeps cannot be turned back into them. The only thing an admin can do is clear your two-step verification, and clearing it does not get them into your account — they would still need your password.
- I turned it on; does everyone at home have to — no, each person decides for themselves and it affects nobody else.
Related guides
- Passkeys — sign in with a fingerprint or your face, less work than a code
- Single Sign-On — sign in to SkyView with a Synology or work account
- Users & Permissions — how an admin resets it for a family member
Was this page helpful?