We're on Product Hunt today! Leave a comment

Add to Chrome

Figma authenticator app

Figma two-factor authentication works with any authenticator app, including one in your browser. Open Settings → Security → Enable two-factor authentication, scan the code Figma shows straight from the screen with the Authenticator extension, and verify with the six-digit code.

A Figma account holds your design files, your team’s libraries and often product work nobody outside has seen yet — and whoever has your password can open, copy or delete it. With two-factor authentication on, Figma asks for a code from your authenticator every time you log in, so a leaked or reused password alone is not enough.

Turn on two-factor authentication in Figma

If you log in to Figma with Google or through your company’s SAML single sign-on, Figma has no two-factor setting for you — the second step is turned on with Google or your company’s login instead. On Figma Enterprise with Governance+, an organization can require two-factor authentication for all its members.

  1. In the Figma file browser on your computer, click your name in the top-left corner and select “Settings”.
  2. Open the “Security” tab and click “Enable two-factor authentication”.
  3. Enter your password and click “Continue”.
  4. Figma suggests authenticator apps to download. You already have one — click “Continue”.
  5. Figma shows a barcode — a QR code. Leave it on the screen and add it to the extension as described below — then enter the six-digit code from the extension and click “Verify”.
Figma’s own instructions

Add Figma to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Figma page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Figma and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Figma confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Figma’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Save your Figma recovery codes

After the code is verified, click “Continue to recovery codes”, and Figma shows a list of recovery codes on the screen. Save them somewhere other than this computer — Figma suggests a password manager or encrypted file storage. Its help does not say how many there are or how to get a new set, so save the whole list the moment it appears.

The code is not accepted?

Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.

If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Which authenticator apps work with Figma?
Figma’s help names Google Authenticator, Duo Mobile, Authy and Microsoft Authenticator, and any app that produces standard six-digit codes works — including the Authenticator extension, which reads the code straight off the Figma settings page. No phone is needed.
I log in to Figma with Google. Where is the two-factor setting?
There is none in Figma: with Google or SAML single sign-on, Figma leaves the second step to whoever signs you in. Turn on 2-Step Verification for your Google account — or ask your company’s IT about its login — and your Figma sign-in is protected by it.
What if I lose access to my authenticator?
Use one of the recovery codes you saved during setup. Figma’s help does not describe a way back without them, so keep the codes somewhere safe, keep the extension’s automatic backups on, and contact Figma Support if both are gone.
Why does Figma say my code is wrong?
Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, the account may have been added from an old code — remove it from the extension, turn two-factor authentication off and on again, and add the new one.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free