Your Supabase account opens every project you belong to: the database with your users’ data, the API keys, storage and billing. A stolen password is enough to read or delete all of it. With MFA on, Supabase also asks for the six-digit code from your authenticator, and organizations on paid plans can require it of every member.
Turn on multi-factor authentication in Supabase
This protects your own Supabase account. Turning on MFA for the users of an app you build on Supabase is a different setting, in the project’s Auth settings. When you enable MFA, Supabase signs out all your other sessions, and you sign in again with the code.
- Sign in to the Supabase Dashboard on your computer.
- Open your account menu and choose “Account”, then select “Security” in the sidebar — or go straight to supabase.com/dashboard/account/security.
- Under “Multi-factor authentication”, click “Add app”.
- Type a name you will recognize into “Authenticator app name” and click “Generate QR”.
- When Supabase shows a QR code, leave that page open and add it to the extension as described below — the key is under “Unable to scan?” — then type the code from the extension into “Authentication code” and click “Confirm”.
Add Supabase to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Supabase page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Supabase and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Supabase confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Supabase’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSupabase has no recovery codes — add a second app
Supabase’s docs say it does not hand out recovery codes, and that it cannot restore access to an account whose every two-factor factor is lost. Its advice is a backup factor: click “Add another app”, which Supabase offers while only one is registered, and scan that second QR code with an authenticator on a different device, such as your phone. Supabase also suggests keeping the secret key somewhere secure, apart from your main authenticator. Keep the extension’s automatic backups on as well.
The code is not accepted?
Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.
Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Which authenticator app works with Supabase?
- Any app that makes standard time-based codes. Supabase names 1Password, Authy, Google Authenticator and Apple’s Keychain; the Authenticator extension works the same way and reads the QR code straight off the dashboard, so no phone is needed.
- What if I lose access to my authenticator?
- Sign in with your second authenticator app, if you registered one, and replace the lost one. Without it there is no way back: Supabase says that for security reasons it will not restore access to an account whose two-factor credentials are all lost. That is why the second app matters.
- Why can’t I open my organization’s projects?
- The organization requires MFA. Its owner turned on “Require MFA to access organization”, and members without MFA lose access to its projects at once. You are still a member: turn on MFA as described above and your permissions come back.
- Does this turn on MFA for my app’s users?
- No. These steps protect your own Supabase account, the one you sign in to the dashboard with. MFA for the people who sign in to an app built on Supabase is part of Supabase Auth and is set up separately, in your project.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free