A WordPress.com account controls every site you run from it — posts, pages, domains and plans — and a stolen password is enough to deface a site or lock you out of it. With two-step authentication on, WordPress.com also asks for the six-digit code from your authenticator each time you log in with your password.
Turn on two-step authentication at WordPress.com
This is the setting for your WordPress.com account — the one you log in to at wordpress.com. A self-hosted WordPress site, running on your own hosting, has its own admin login that this setting does not cover; there two-factor authentication comes from a plugin.
- Log in at wordpress.com on your computer, hover over your name in the top right corner and select “My WordPress.com account”.
- Select “Security” in the menu on the side.
- Click “Two-Step Authentication”.
- Choose “Set up using an app”.
- WordPress.com shows a QR code. Leave it on the screen and add it to the extension as described below — then type the six-digit code into the field and click “Enable”.
Add WordPress.com to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the WordPress.com page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to WordPress.com and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- WordPress.com confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on WordPress.com’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your WordPress.com backup codes
Right after you click “Enable”, WordPress.com shows a set of backup codes. Copy, print or download them with the icons under the list, then type one into the field and click “Verify”. WordPress.com advises against keeping them on your computer — store them in a wallet, a safe or a password manager. Each code works once. You can generate a new set from a computer under Security → Two-Step Authentication → Backup codes, after entering a saved code; the old set then stops working.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Can I use WordPress.com two-step authentication without a phone?
- Yes. WordPress.com suggests phone apps like Google Authenticator and Authy, but it only checks the six-digit code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the Security page and generates the codes in Chrome.
- Does this protect my self-hosted WordPress site?
- No. This setting protects your WordPress.com account. A WordPress site on your own hosting has its own admin login, and two-factor authentication there comes from a plugin. If the plugin offers an authenticator app and shows a QR code or a key, the extension adds it the same way.
- What if I lose access to my authenticator?
- On the login screen click “Use a backup code instead” and enter one of your backup codes. WordPress.com says backup codes are the only way back in without staff assistance; without them, contact WordPress.com support to recover the account. Keep the extension’s automatic backups on so a reinstall does not lock you out.
- Why does WordPress.com say my code is wrong?
- Usually the computer clock is off by a minute or more. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension, disable two-step authentication with a backup code, and set it up again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free