We're on Product Hunt today! Leave a comment

Add to Chrome

Atlassian authenticator app

Atlassian two-step verification works with any authenticator app, including one in your browser — and one setting covers Jira, Confluence and Trello. Open your Atlassian account’s Security page → Manage two-step verification, choose “Enable authenticator app”, and scan the QR code from the screen with the Authenticator extension.

One Atlassian account signs you in to Jira, Confluence and Trello, so a stolen password opens your team’s tickets, pages and boards all at once. With two-step verification on, the password alone is no longer enough: Atlassian also asks for the six-digit code from your authenticator. Many organizations require it — Atlassian then emails you to say so, and you have to turn it on to keep signing in.

Turn on two-step verification for your Atlassian account

Two-step verification belongs to your Atlassian account, not to Jira or Trello separately, so you set it up once. Turning it on keeps you signed in on this computer but may sign you out on your other devices. If your company signs you in through its own login (single sign-on), the second step is set up with that identity provider instead, and this setting does not apply.

  1. Sign in to your Atlassian account on your computer and open its security page at id.atlassian.com/manage-profile/security.
  2. Select “Manage two-step verification”.
  3. Enter your password in the “Atlassian account password” field and select “Set up”.
  4. Select “Enable authenticator app”.
  5. Atlassian shows a QR code. Leave it on the screen and add it to the extension as described below — then enter the code from the extension and follow the prompts to the end.
Atlassian’s own instructions

Add Atlassian to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Atlassian page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Atlassian and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Atlassian confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Atlassian’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Save your Atlassian emergency recovery key

During setup Atlassian gives you one emergency recovery key — copy, print or write it down and keep it somewhere other than this computer. At the code prompt, “Use recovery key” signs you in with it. Each key works once: after using it, Atlassian shows you a new one to save. If you lose the key while you are still signed in, “Create new emergency recovery key” in the two-step verification settings replaces it.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Can I use Atlassian two-step verification without a phone?
Yes. Atlassian supports most authenticator apps — it names Google Authenticator, Authy and Duo — and all it checks is the six-digit code. The Authenticator extension reads the QR code straight off the Atlassian page and generates the codes in Chrome.
Does this one setting cover Jira, Confluence and Trello?
Yes, for the cloud versions you sign in to with your Atlassian account — Trello’s own help points to the same setting. Two exceptions: Jira or Confluence running on your company’s own servers sign you in their own way, and Bitbucket Cloud’s help describes a two-step setting of its own.
What if I lose access to my authenticator?
Sign in with your emergency recovery key, then set the authenticator up again. Without the key, ask your organization’s admin if it manages your account; otherwise, at the code prompt choose “Use recovery key?” → “Can’t find your recovery key?” → “Send recovery email”. Atlassian emails a one-time link 24 hours later, and it expires soon after — check your inbox on time.
Why does Atlassian say my code is wrong?
Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If you have several Atlassian accounts, check you copied the code from the right one. If it still fails, remove the account from the extension, turn two-step verification off and on again, and add the new QR code.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free