We're on Product Hunt today! Leave a comment

Docker Hub authenticator app

Docker’s two-factor authentication works with any authenticator app that supports TOTP — including one in your browser. In your Docker account open Account settings → 2FA, save the recovery code, and scan the QR code from the screen with the Authenticator extension.

Your Docker account publishes the images other people pull. Whoever signs in with your password can push a poisoned image under your name, delete repositories or create access tokens for later. With 2FA on, Docker also asks for the six-digit code from your authenticator when you sign in to Docker Hub or Docker Home.

Turn on two-factor authentication for your Docker account

You need your Docker password and a verified email address on the account. Docker keeps one authenticator per account, and once 2FA is on, the Docker CLI no longer accepts your password for docker login -u, scripts and CI — create a personal access token for those.

  1. Sign in to your Docker account at app.docker.com on your computer.
  2. Select your avatar in the top-right corner, then select “Account settings”.
  3. Select “2FA”, enter your account password, then select “Confirm”.
  4. Docker shows your recovery code first. Select “Copy”, or open the menu next to it and select “Download” or “Print”, and keep it somewhere other than this computer.
  5. When Docker shows a QR code on the “QR Code” tab, leave that page open and add it to the extension as described below — the key is on the “Text Code” tab — then enter the code from the extension in “Authentication code” and select “Enable 2FA”.
Docker Hub’s own instructions

Add Docker Hub to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Docker Hub page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Docker Hub and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Docker Hub confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Docker Hub’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Keep your Docker recovery code

Docker gives you one recovery code, shown during setup before the QR code. It signs you in if you lose your authenticator — but only once: using it turns 2FA off and deletes the code, and you turn 2FA on again afterwards. If you lose the code while you can still sign in, open Account settings → “2FA”, confirm your password and select “Generate new code”; the new code replaces the old one.

The code is not accepted?

Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.

Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Can I use Docker Hub 2FA without a phone?
Yes. Docker says any authenticator app that supports TOTP works, and it checks only the six-digit code. The Authenticator extension reads the QR code straight off the Docker page and generates the codes in Chrome — no phone needed.
How do I use docker login with 2FA on?
Run docker login without a username to sign in through the browser, where you enter your password and the code from the extension. For docker login -u, scripts and CI, Docker no longer accepts your password: create a personal access token and enter it at the password prompt.
What if I lose access to my authenticator?
Sign in with your username and password, select “I’ve lost my authentication device” on the Two-Factor Authentication page, and enter your recovery code. That signs you in and turns 2FA off — turn it on again straight away. Without the recovery code, use Docker’s Contact Support form for 2FA lockouts.
How do I move Docker 2FA to another authenticator?
Docker keeps one authenticator per account, so you cannot add a second one. To move to a new app or device, turn 2FA off in Account settings → “2FA” and turn it on again, scanning the new QR code with the app you want to use.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free