A Substack account can be a publication with a mailing list and paid subscribers — whoever signs in as you can post to everyone on it. Substack lets you sign in with a link sent to your email, so a hijacked inbox could be enough on its own. With two-factor authentication on, Substack also asks for a code from your authenticator app every time you sign in.
Turn on two-factor authentication on Substack
Substack will not let you turn two-factor authentication on until recovery questions are set up — if the toggle is locked, that is why. The answers are your way back if you lose your authenticator, so choose ones you will remember exactly.
- Sign in at substack.com on your computer and open your account “Settings” page.
- In the “Security” section, click the toggle next to “Recovery questions” and set up your questions.
- Click the toggle next to “Turn on two-factor authentication”.
- Substack shows a QR code and a setup key. Leave the QR code on the screen and add it to the extension as described below — or copy the setup key for manual entry.
- Enter the six-digit code from the extension and click “Enable two-factor authentication”.
Add Substack to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Substack page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Substack and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Substack confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Substack’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeYour way back into Substack: recovery questions
Substack’s help describes no backup codes — the recovery questions you set up first are the way back. If you lose your authenticator, sign in with your email or password, click “Still not able to log in? Recover your account.” on the two-factor page, answer the questions and click “Reset”. Two-factor authentication is then off and you can set it up again. The challenge can expire, so answer it without leaving the page — and keep the extension’s automatic backups on as well.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Do I need a phone for Substack two-factor authentication?
- No. Substack points to apps from the App Store or Google Play, such as Google Authenticator or 1Password, but it only checks the six-digit code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the Substack settings page and generates the codes in Chrome.
- Why is the two-factor authentication toggle locked?
- Because recovery questions are not set up yet. Turn on “Recovery questions” in the same Security section and answer them — the two-factor toggle unlocks afterwards.
- What if I lose access to my authenticator?
- Sign in with your email or password, choose “Still not able to log in? Recover your account.” and answer your recovery questions to reset two-factor authentication. If you have lost access to your email address as well, follow Substack’s separate account recovery steps.
- Why does Substack say my code is wrong?
- Usually the computer clock is off by a minute or more — the code changes every 30 seconds. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension, reset two-factor authentication and set it up again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free