A Hugging Face account holds your models, datasets and Spaces — private ones included — your access tokens, and the right to push to your organizations’ repositories. Whoever has your password can publish under your name or swap a model other people download. With two-factor authentication on, the Hub asks for the six-digit code from your authenticator every time you log in, and again every 30 days.
Turn on two-factor authentication on Hugging Face
Hugging Face names Authy, Google Authenticator, Microsoft Authenticator and FreeOTP, and any app that produces standard six-digit codes works. Organizations on the Team and Enterprise plans can require all their members to enable two-factor authentication.
- Log in at huggingface.co on your computer.
- Click your profile picture in the top right corner and choose “Settings”.
- Open the “Authentication” page of your settings.
- Select “Add Two-Factor Authentication”.
- The Hub shows a QR code. Leave it on the screen and add it to the extension as described below — then enter the six-digit code from the extension into “Code” and save.
Add Hugging Face to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Hugging Face page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Hugging Face and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Hugging Face confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Hugging Face’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeDownload your Hugging Face recovery codes
As soon as the code is accepted, the Hub shows a list of recovery codes. Download them — the file is huggingface-recovery-codes.txt — or print them, and keep them somewhere other than this computer. Each code signs you in once. If you lose them or want a new set, open the Authentication settings, select “Recovery Code” and click “Regenerate recovery codes” — the old codes stop working.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Which authenticator apps work with Hugging Face?
- Any app that produces standard time-based codes (TOTP). Hugging Face names Authy, Google Authenticator, Microsoft Authenticator and FreeOTP; the Authenticator extension works the same way and reads the code straight off the Hub’s settings page, so no phone is needed.
- Can my organization require two-factor authentication?
- Yes, on the Team and Enterprise plans: among the organization’s advanced security settings, admins can require every member to enable two-factor authentication on their own account.
- What if I lose access to my authenticator?
- At the code prompt, click “Lost access to your two-factor authentication app? Use a recovery code” and enter one of your recovery codes. Without them, contact Hugging Face support — you will be asked to prove the account is yours with another factor, such as an SSH key or a personal access token.
- Why does Hugging Face say my code is wrong?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, the account may have been added from an old code — remove it from the extension, remove two-factor authentication in the Authentication settings, and set it up again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free