A Netlify login deploys your sites, holds their environment variables — API keys, tokens, database URLs — and often runs the DNS for your domains. Whoever signs in with your password can change what your visitors see. With 2FA on, Netlify asks for the code from your authenticator before you can open any team or organization tied to your user, and team owners on Pro plans and up can require it of every member.
Turn on two-factor authentication on Netlify
2FA belongs to your Netlify user, not to a team, so you set it up once in your personal user settings and it covers every team and organization you belong to.
- Sign in to Netlify at app.netlify.com on your computer.
- Open your “User settings”, then “Security” → “Two-factor authentication” — or go straight to app.netlify.com/user/security.
- Select “Enable two-factor authentication”.
- When Netlify shows a QR code, leave that page open and add it to the extension as described below — or copy the code under “Manual entry” — then enter the six-digit code from the extension and select “Next: Recovery codes”.
Add Netlify to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Netlify page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Netlify and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Netlify confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Netlify’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your Netlify recovery codes — they are shown once
Right after the code is accepted, Netlify shows your recovery codes. Copy or print them now: Netlify presents them only once, so this is your one chance. Keep them somewhere other than this computer, then select “Finished! I saved my recovery codes.” Each code works once, in place of the code from your authenticator.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use Netlify 2FA without a phone?
- Yes. Netlify’s steps assume an app on your phone, but all it checks is the six-digit code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the Netlify settings page and generates the codes in Chrome.
- Which authenticator app works with Netlify?
- Netlify names 1Password, Authy, Duo and Google Authenticator as examples, and any app that makes standard time-based codes works the same — including the Authenticator extension. Your company may ask you to use a particular one.
- My Netlify team requires 2FA. What does that mean for me?
- An owner on a Pro plan or higher has set the team or organization to “Encouraged” — you see a banner — or “Enforced”, which keeps you out of its sites until 2FA is on for your Netlify user. Developers, owners, reviewers, publishers and billing admins all need it; Git Contributors, who have no Netlify login, do not.
- What if I lose access to my authenticator?
- Sign in with one of your recovery codes, then set the authenticator up again. Netlify’s docs describe no way back without them, so if the codes are gone too, contact Netlify support. Keeping the extension’s automatic backups on means a reinstall does not cost you the account.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free