A Kraken account holds your crypto and cash, and a stolen password is the usual way in. Kraken calls sign-in 2FA a basic security feature everyone should use: with it on, a password alone no longer signs anyone in. Funding 2FA goes further and asks for a code for every withdrawal, so even someone who got into the account cannot move your funds out without it.
Turn on authenticator 2FA in Kraken
Kraken sets up 2FA separately for each action — signing in, funding (deposits and withdrawals), trading, the Master Key and each API key — and funding and trading 2FA need sign-in 2FA on first. Kraken recommends a passkey for signing in and calls an authenticator app “moderately secure”; you can have both, with up to five passkeys and one authenticator app.
- Sign in to your Kraken account on your computer — at kraken.com or, for Kraken Pro, at pro.kraken.com.
- Open your “Security” settings. In Kraken Pro, click the profile icon in the upper-right corner, then “Settings” → “Security”.
- Pick the action to protect. For signing in, go to “Sign-in Two-Factor Authentication (2FA)”; funding, trading and the Master Key each have their own switch further down.
- Turn the switch on — or choose “Change method” if 2FA is already set up — and select “Authenticator app”. Kraken suggests a passkey first; skip it if codes are what you want.
- When Kraken shows a QR code, leave that page open and add it to the extension as described below — then enter the code from the extension and click “Confirm”.
Add Kraken to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Kraken page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Kraken and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Kraken confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Kraken’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeKeep the Kraken setup key — or set up a Master Key
Kraken hands out no list of backup codes. What restores authenticator 2FA is the setup key — sometimes called the “backup code” — shown as the QR code and as text under “View setup key”. Store it like a password, not digitally, and never share it, not even with Kraken Support. Kraken’s better answer is a Master Key on a different device: Security → “Advanced Settings” → “Enable” next to “Master Key”. It works as a second way to pass sign-in 2FA, but it has to be set up before the authenticator is lost. Funding and trading 2FA need no backup: once you are signed in, you can switch them off and set them up again.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use a Kraken authenticator without a phone?
- Yes. Kraken accepts any app that produces standard time-based codes and gives Google Authenticator only as an example. The Authenticator extension reads the QR code straight off the Kraken page and generates the codes in Chrome. Kraken does warn against apps that sync your codes to a Google, Apple or Microsoft account, since that account then becomes a way in.
- Is 2FA required for withdrawals on Kraken?
- Not by default — funding 2FA is a separate switch. Once it is on, Kraken asks for a code for every withdrawal and for transfers to your Futures wallet. Kraken adds that it is only effective with sign-in 2FA or the Global Settings Lock also on; otherwise whoever gets in can turn it off. API keys work the same way: 2FA is optional for each key, and the Kraken Pro mobile app cannot use API keys that have it.
- How do I move Kraken 2FA to a new phone or computer?
- While the old authenticator still works, check whether it can export accounts. If not, sign in, add a passkey or security key first, then click “Delete” under “Sign-in Two-Factor Authentication”, click “Enable” and scan the new QR code. If the old device is lost, sign in with your Master Key or the setup key you stored — then change your 2FA at once — or click “Recover account” at the 2FA prompt. Support then removes the 2FA by email and may ask for a photo of you holding your ID and a handwritten note.
- Why does Kraken say my code is wrong?
- Kraken gives each action its own entry, so check you are reading the right one — when it asks for your Master Key, Kraken says to enter the code labelled “Kraken.com Master Key”, not “Kraken.com Sign-in”. Otherwise the QR code may have changed because the setup page was reloaded or opened again: add the one on the screen now and use the newest entry. If 2FA was first set up in another app, the codes come from that app.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free