A GitLab account pushes code, approves merge requests, runs CI pipelines and holds the variables and tokens they deploy with — whoever signs in as you can ship code under your name. With 2FA on, a password alone no longer gets in. Groups and instances can also require it, so you may be asked to turn it on before you can work in a project.
Register an authenticator on GitLab
Once 2FA is on, your password stops working for Git over HTTPS and the GitLab API — create a personal access token and use it in their place. On a self-managed GitLab run by your company, the screens are the same; open them on that instance instead of GitLab.com.
- Sign in to GitLab on your computer.
- Select your avatar in the upper right corner, then “Edit profile”.
- In the left sidebar, select “Access” → “Password and authentication”.
- In the “One-time password authenticator” section, select “Register authenticator”.
- When GitLab shows a QR code, leave that page open and add it to the extension as described below — the details for manual entry are next to it — then enter your current password and the code from the extension, and select “Register with two-factor app”.
Add GitLab to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the GitLab page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to GitLab and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- GitLab confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on GitLab’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeDownload your GitLab recovery codes
After the code is accepted, GitLab shows your recovery codes. Copy or print them, or select “Download codes” to save gitlab-recovery-codes.txt, and keep them somewhere other than this computer. Each code works once. To get a new set, go to Password and authentication → “Regenerate recovery codes” and enter your password — the old codes stop working.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use a GitLab authenticator without a phone?
- Yes. GitLab lists phone apps such as Google Authenticator, Microsoft Authenticator and Authy, but it checks only the six-digit code, and any app that makes standard time-based codes produces it. The Authenticator extension reads the QR code straight off the GitLab page and keeps the codes in Chrome.
- What if I lose access to my authenticator?
- At the two-factor prompt, select “Recover your account” and enter a recovery code. Lost those too? If you still have an SSH key on the account, run ssh git@gitlab.com 2fa_recovery_codes and confirm with yes to get a fresh set. GitLab Support resets 2FA only for paid GitLab.com accounts (Premium or Ultimate) — on a Free account, losing every method locks you out for good.
- Why does git push reject my password after turning on 2FA?
- With 2FA on, GitLab no longer accepts your password for Git over HTTPS or the API. Create a personal access token and enter it where Git asks for the password — or push over SSH, which uses your SSH key and is not affected.
- Why does GitLab say my code is wrong?
- Usually the QR code changed: if you left the page and started registering again, GitLab made a new one, and the account you added first no longer matches. Remove it from the extension, add the QR code on the screen now and type its code in straight away. If you have two entries for GitLab, use the newest.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free