Security & Privacy · THE NO-PANIC PLAN
Set up and verify GitHub account two-factor authentication
This guide covers two-factor authentication (2FA) for a GitHub.com personal account. GitHub recommends an authenticator app such as TOTP as the primary method and a security key as a backup; passkeys and GitHub Mobile can also be available. Secure recovery before closing your existing session. Organization or enterprise-managed accounts may be controlled by an administrator, and disabling 2FA can remove access to organization resources.
MISSION Help a GitHub.com personal-account owner enable two-factor authentication, store recovery codes, add a backup method and verify they can sign in safely.
Save recovery codes before finishing setupTHE REAL-WORLD BIT
What happens outside this browser tab?
Confirm the account is personally managed and check any organization requirement; enable a supported primary 2FA method through GitHub Settings; securely save recovery codes; add a second method or recovery option; then complete a successful 2FA sign-in during GitHub's check-up period while retaining your existing session until the new access path works.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Confirm the account type and organization requirements
Use this process for a GitHub.com personal account that you control. If this is an enterprise-managed user account, ask the administrator to configure authentication through the identity provider; GitHub says non-setup users cannot configure 2FA themselves. If you belong to an organization that requires 2FA, keep that requirement in place: disabling 2FA can remove access to its resources. Choose a method you can keep available and make sure you can access the device that will hold your authenticator before changing account settings.
- 02
Enable a primary two-factor method in GitHub Settings
While signed in, open your profile menu, choose Settings, then Access > Password and authentication. Under Two-factor authentication, choose Enable. GitHub recommends starting with a time-based one-time password (TOTP) authenticator app rather than SMS. Scan the GitHub QR code with your chosen app, or use GitHub's setup key only if you need manual entry; treat that setup secret like a password and do not share or save it in a public place. Enter the current code from the app in GitHub to verify setup. Follow the current page labels if GitHub updates its settings interface.
- 03
Save the recovery codes somewhere secure
Before completing enrollment, download the recovery codes when GitHub offers them and store them in a secure place you can reach if your phone is lost, such as a trusted password manager. Do not send or paste them into Nirmion, a ticket or a shared document. GitHub recovery codes are one-time use; generating a new set invalidates the old set. Confirm you have saved the codes before selecting GitHub's acknowledgement to finish enabling 2FA.
- 04
Add another authentication or recovery method
Return to Password and authentication and add at least one additional method you control, such as a registered security key, passkey or GitHub Mobile. GitHub recommends configuring two or more authentication methods to reduce lockout risk. If you add a security key, test that you can use it and keep the TOTP/recovery route available. Do not assume an old recovery-code file remains valid after regenerating codes or disabling and re-enabling 2FA.
- 05
Verify sign-in and keep a working session until backups pass
Use an existing signed-in session to complete a fresh GitHub sign-in check with your password and the new 2FA method; also confirm that your backup method is available. GitHub places newly configured 2FA in a 28-day check-up period and requires a successful 2FA action during that period to leave it. Keep your current session open until the new method and recovery codes are confirmed, then note privately where the recovery material is stored. If a TOTP code fails, first check the correct account entry and the device's automatic date/time, then use a previously configured alternate method. GitHub warns that Support cannot restore access if all 2FA and recovery options are lost, so do not disable 2FA simply to troubleshoot a code.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-05