A Cloudflare login controls your domains’ DNS and security settings: whoever has it can send your website and email somewhere else or take the site offline. Cloudflare recommends 2FA for every user, and an account’s Super Administrators can require it — invited members then have to turn it on before they can join.
Turn on two-factor authentication at Cloudflare
Cloudflare needs a verified email address before 2FA is turned on — its docs warn that without one you may lock yourself out. It also recommends at least two different methods, for example the authenticator app and a security key.
- Sign in to the Cloudflare dashboard at dash.cloudflare.com on your computer.
- Open the “My Profile” dropdown and select “My Profile”.
- Select “Authentication”.
- In the “Two-Factor Authentication” section, select “Set up” if it is shown, then “Add” under “Mobile App Authentication”.
- Cloudflare shows a QR code. Leave it on the screen and add it to the extension as described below — or select “Can’t scan QR code, Follow alternative steps” for the key — then enter the code from the extension and your Cloudflare password.
Add Cloudflare to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Cloudflare page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Cloudflare and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Cloudflare confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Cloudflare’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your Cloudflare backup codes
After the code is accepted, Cloudflare asks for your password again and shows backup codes: select “Download”, “Print” or “Copy”, keep them somewhere other than this computer, and select “Next” to finish. Each code works once. You can get a fresh set any time under Authentication → Two-Factor Authentication → “Manage” → “Regenerate” next to “Backup codes” — the old ones stop working.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Which authenticator app works with Cloudflare?
- Cloudflare names Google Authenticator and Microsoft Authenticator, and any app that makes standard time-based codes (TOTP) works the same — including the Authenticator extension, which reads the QR code straight off the dashboard. No phone needed.
- What if I lose access to my authenticator?
- On the “Two-Factor Authentication” sign-in page, enter a backup code instead. Without backup codes, select “Try recovery” under “Lost all 2FA devices and backup codes?”: Cloudflare emails you a code, checks that you are on a device you have signed in from before, and then sends instructions within 3–5 days — a wait it says cannot be sped up.
- Why does Cloudflare reject my code?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If you set the authenticator up again at some point, the old account in the extension stopped working — Cloudflare invalidates the previous codes — so remove it and add the new QR code.
- Cloudflare wants 2FA before I can join an account. Why?
- The account’s Super Administrator has turned on 2FA Enforcement, which requires every member to use two-factor authentication. Set up the authenticator app as described above, then accept the invitation. While enforcement is on, you may not be allowed to turn 2FA off.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free