Authenticator app sign-in
A six-digit code from an app, with or without a password — and the ten backup codes that keep a lost phone from becoming a lost account.
- Intermediate
- 6 min read
- Applies to 2.0
Two ways to use it
The same six-digit code, in two different positions:
- As a second factor, after a password — either from Security → Two-factor, where 2FA Method offers two cards, Email and Authenticator app, or from the Password with two-factor add-on on the Authentication screen. Both ask the member for the same code.
- On its own, replacing the password entirely — present in the Pro code, but not offered in 2.0: the Authentication screen builds no card for it, so there is nothing to select.
Enrolment and backup codes are shared by both, and are what the rest of this article covers.

The 2FA Method list, under Security → Two-factor.
Enrolment comes first
A member cannot sign in with an app they have not enrolled. Enrolment pairs their account with the app once — scan a QR code, confirm one code — and from then on the app produces a fresh code every thirty seconds, offline.
There are two places to do it, and they write the same pairing:
- On the site, wherever you drop the Two-Factor Authentication component in the form builder — the Account or Settings flow is the natural home. This is the one to use on a membership site, where members never see wp-admin.
- On the WordPress profile screen, under TOTP Authenticator App, for administrators and editors who work there anyway. That section appears once the app is asked for somewhere, which is what the setting above does.
Either way it is the same three steps: scan, confirm one code, save the backup codes.
Switching the method to the app does not lock anyone out. A member who has not enrolled keeps receiving a code by email, and moves to the app the moment they finish the wizard — so you can turn it on first and let people enrol at their own pace. App-only sign-in, on the release that offers it, will not be so forgiving: there would be no password and no mailbox left to fall back on.
- You have enrolled a test account and signed in with it, password then code
- Members have been told to enrol, with a deadline
- Your emergency access link is saved outside the site
Backup codes
Enrolment issues ten single-use codes. They exist for the day the phone is lost, replaced, or wiped — without them, that day ends in a support request and a manual reset.
Three things worth telling your members:
- They are shown once, at enrolment. Stored hashed, they cannot be displayed again.
- Each works once.
- Regenerating issues a fresh set and invalidates the old one.
- One is typed into the same box as the app's code, at the sign-in prompt — there is no separate screen to find while locked out.
When someone is locked out
An administrator can reset a member's authenticator from their user profile, which clears the pairing and lets them enrol again. For an administrator locked out of their own account, that is what the emergency access link is for.
Related articles
Something missing or out of date? Tell support.