Your Hetzner account is the way into your servers from outside them: whoever signs in can open a server’s console, rebuild or delete it, read its backups and run up the bill. With two-factor authentication on, Hetzner asks for a code from your authenticator after your password, so a leaked password alone does not open the account.
Turn on two-factor authentication at Hetzner
Hetzner asks you to save a recovery key before you add any method, and warns that a lost key can only be replaced by regular mail. Have somewhere safe to note it down before you begin.
- Sign in to Hetzner Accounts at accounts.hetzner.com on your computer.
- Under “Settings”, open “Two-factor authentication” and click “Enable 2-FA”.
- Enter your account password and confirm that a lost recovery key can only be replaced by regular mail.
- Hetzner shows your customer number and recovery key. Note the key down and keep it somewhere safe, then click “Set up authentication”.
- Under “Add new method”, choose “Mobile Device”.
- When Hetzner shows a QR code, leave that page open and add it to the extension as described below — then fill in the fields Hetzner asks for, including the code from the extension, and confirm.
Add Hetzner to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Hetzner page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Hetzner and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Hetzner confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Hetzner’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeKeep your Hetzner recovery key
Hetzner gives you one recovery key instead of a list of backup codes. If signing in with a code fails, click the red “Disable 2FA” option under “Verify” and enter the key: you get into your account, and two-factor authentication is switched off until you set it up again. Write the key down and keep it somewhere other than this computer — replacing it means a manual review and a new key by regular mail.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use Hetzner 2FA without a phone?
- Yes. The method is called “Mobile Device”, but Hetzner only checks the six-digit code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the Hetzner page and generates the codes in Chrome.
- Can I add more than one 2FA method to Hetzner?
- Yes. Hetzner lets you add several methods and keep them active at once — for example the extension and an authenticator on your phone, or a YubiKey — and you can sign in with any of them. A second method is a good way back if you lose the first.
- What if I lose access to my authenticator?
- Sign in with another active method if you added one, or click “Disable 2FA” under “Verify” and enter your recovery key, then set the authenticator up again. Without the key, request a new one with Hetzner’s recover-access form at accounts.hetzner.com/recover_access: you need your full customer number — it starts with “K” and is in the top right-hand corner of your last invoice — and an email address where Hetzner can reach you.
- Why does Hetzner say my code is wrong?
- Usually the QR code changed: if the setup page was reloaded or opened again, Hetzner made a new one, and the account you added first no longer matches. Add the QR code that is on the screen now and type its code in straight away. If you have two Hetzner entries in the extension, use the newest.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free