Hijacked X accounts are used to post crypto scams and phishing links to everyone who follows you, and a handle you built for years can be renamed in minutes. Since 2023 X offers text message 2FA only to Premium subscribers, so for most people an authentication app or a security key is the only way to protect the account.
Turn on two-factor authentication on X
- Sign in at x.com on your computer and click “More” in the left menu.
- Choose “Settings and privacy”, then “Security and account access” → “Security”.
- Click “Two-factor authentication” and check “Authentication app”.
- Click “Get started” and confirm your password. X shows a QR code — leave it on the screen and add it to the extension as described below.
- Enter the code from the extension to confirm. X confirms that two-factor authentication is on.
Add X (Twitter) to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the X (Twitter) page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to X (Twitter) and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- X (Twitter) confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on X (Twitter)’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freeSave your X backup code
Right after setup X offers “Get backup code”. Copy it and keep it away from this computer — it is the way in if you lose the authentication app. You can get a new one later under Security → Two-factor authentication → “Backup codes”; X keeps up to five active codes, and they have to be used in the order they were generated.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Is two-factor authentication on X free?
- With an authentication app or a security key, yes. Only text message codes require X Premium. The Authenticator extension is free as well, so the whole setup costs nothing.
- Can I use X 2FA without a phone?
- Yes. X accepts codes from any standard authentication app, and the Authenticator extension generates them in Chrome on your computer. It reads the QR code straight off the X settings page.
- What if I lose access to my authentication app?
- At the code prompt, click the link to use a backup code. Without one, X support may not be able to restore access — which is why saving the backup code, and keeping the extension’s automatic backups on, matters.
- Why does X say my code is wrong?
- Check the computer clock first: a clock that is off by more than about 30 seconds produces codes X refuses. Turn on automatic date and time and try the next code. If it still fails, remove the account from the extension and set 2FA up again.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free