A Gemini account holds your crypto and the bank account linked to it, and two-factor authentication is what stands between a stolen password and all of it. Gemini makes 2FA mandatory — it cannot be turned off — and since December 2025 it no longer accepts text message or Authy codes, so every account needs a passkey, a security key or an authenticator app.
Turn on the authenticator app at Gemini
Gemini ranks passkeys above authenticator apps and may ask you to create a passkey first; the authenticator app stays a supported method in Security Settings. If you used Authy through Gemini before, that set-up was retired — Authy can be added again like any other authenticator app.
- Sign in at gemini.com on your computer.
- Open the security page at exchange.gemini.com/settings/security — in the mobile app it is the profile icon → “Security Settings”.
- Find the authenticator app option and start the setup.
- When Gemini shows a QR code, leave that page open and add it to the extension as described below — or use the setup key Gemini offers in its place.
- Enter the six-digit code from the extension to confirm the link.
Add Gemini to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Gemini page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Gemini and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Gemini confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Gemini’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeKeep a way back into Gemini
Gemini’s help describes no backup codes for the authenticator. Our advice: while the setup key is on the screen, write it down and keep it offline, away from this computer and as private as a password — with it you can add the account to any authenticator again. Adding a passkey as well gives you a second way in. If everything is lost, Gemini’s account recovery asks you to verify the email and phone number on the account and possibly upload an ID or record a selfie, and a successful recovery puts a 72-hour hold on crypto withdrawals.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use a Gemini authenticator without a phone?
- Yes. Gemini names Google Authenticator, Duo Mobile and Microsoft Authenticator, but all it checks is the six-digit code, and any standard authenticator (TOTP) produces it. The Authenticator extension reads the QR code straight off the Gemini security page and generates the codes in Chrome.
- How do I move Gemini 2FA to a new phone?
- If your authenticator app was backed up, Gemini simply appears in it on the new device. If not, Gemini prefers that you change the 2FA setting from the old device while you still have it; otherwise you go through Gemini Support. With the extension, export a backup or restore one of its automatic backups on the new computer and the codes carry on working.
- What if I lose access to my authenticator?
- Sign in with your email and password and, on the 2FA screen, select “Recover Your Account”. Gemini asks you to verify your email and phone number and may ask for a government ID or a live selfie, then you set up a new passkey or authenticator app. You get three attempts, then a 24-hour wait. If the option does not appear, the account is not eligible for self-service and you need to contact Gemini Support.
- Is 2FA required for withdrawals on Gemini?
- 2FA is required on every Gemini account and cannot be disabled, and Gemini’s help describes your 2FA method as covering withdrawals as well as sign-ins. After an account recovery, Gemini holds crypto withdrawals for 72 hours. For extra protection Gemini also suggests Withdrawal Protection in your address book.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free