We're on Product Hunt today! Leave a comment

Vercel authenticator app

Vercel two-factor authentication works with any authenticator app that makes time-based codes (TOTP) — including one in your browser. Open Account Settings → Authentication, switch on two-factor authentication, choose the authenticator app, and scan the QR code from the screen with the Authenticator extension.

A Vercel account deploys to production, holds your projects’ environment variables — API keys, database URLs — and points your domains at whatever it serves. Whoever signs in with your password can change all of that. With 2FA on, Vercel also asks for the six-digit code from your authenticator, and teams can make it a condition of membership: a team that enforces 2FA blocks members without it.

Turn on two-factor authentication on Vercel

Vercel offers two methods: an authenticator app and a passkey, such as a security key or your computer’s fingerprint sign-in. The steps below set up the authenticator app; a passkey can be added alongside it.

  1. Sign in to Vercel on your computer.
  2. Open your account settings and select “Authentication” — or go straight to vercel.com/account/settings/authentication.
  3. In the “Two-Factor Authentication” section, toggle the switch to enable 2FA.
  4. Choose the authenticator app as your method.
  5. When Vercel shows a QR code, leave that page open and add it to the extension as described below — or copy the key Vercel shows for manual entry — then enter the six-digit code from the extension to confirm.
Vercel’s own instructions

Add Vercel to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the Vercel page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to Vercel and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. Vercel confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on Vercel’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Save your Vercel recovery codes

Once 2FA is set up, Vercel prompts you to save your recovery codes. Keep them somewhere other than this computer — they are what gets you into the account if you lose your authenticator. Each code works once, and you can generate a new set at any time in the same Authentication settings.

The code is not accepted?

Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.

Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Can I use Vercel 2FA without a phone?
Yes. Vercel names Google Authenticator as an example, but any app that makes standard time-based codes works — including the Authenticator extension, which reads the QR code straight off the settings page and generates the codes in Chrome. A passkey on your computer is the other method Vercel offers.
What if I lose access to my authenticator?
At the two-factor prompt, use one of your recovery codes, or a passkey if you added one. Then set the authenticator up again and save the new codes. Without either, you have to ask Vercel to recover the account, which means proving it is yours.
My Vercel team enforces 2FA. What changes for me?
Until 2FA is on for your account, you cannot open the team’s resources, your builds for the team fail, and CI tokens tied to your account stop working. Vercel prompts you to set it up when you visit the team dashboard; once it is on, everything works again. Service accounts and bots need 2FA too.
Why does Vercel say my code is wrong?
Usually the QR code changed: if the setup was closed or started again, Vercel made a new one, and the account you added first no longer matches. Remove it from the extension, add the QR code on the screen now and type its code in straight away. If you have two entries for Vercel, use the newest.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free