How to Enable GitHub 2FA

Two-factor authentication (2FA) adds an extra layer of security to your GitHub account. With 2FA enabled, signing in requires more than your username and password. Depending on the authentication method you choose, GitHub may also require a code from an authenticator app, a security key, or another supported verification method.

Enabling 2FA is especially useful if your GitHub account contains private repositories, source code, or access to development projects. Even if someone obtains your password, the additional authentication step can help prevent unauthorized access.

Method 1: Enable 2FA From GitHub Settings

The simplest way to enable two-factor authentication is through your GitHub account settings.

  1. Open GitHub in your web browser.
  2. Sign in to your account.
  3. Click your profile picture in the upper-right corner.
  4. Select Settings.
  5. Open the Password and authentication section.
  6. Find the Two-factor authentication option.
  7. Select Enable two-factor authentication.
  8. Follow the instructions displayed by GitHub.
  9. Choose your preferred authentication method.
  10. Complete the verification process.

GitHub may ask you to confirm your password or otherwise verify your account before allowing security settings to be changed.

Once the setup is complete, your account will require the additional authentication step when GitHub requests it.

Method 2: Set Up an Authenticator App

An authenticator app is one of the most convenient ways to generate temporary verification codes.

You can use a compatible authenticator application on your phone or another supported device.

To set it up:

  1. Start the GitHub 2FA setup process.
  2. Select the option for an Authenticator app.
  3. GitHub will display a QR code.
  4. Open your authenticator application.
  5. Add a new account.
  6. Scan the QR code displayed by GitHub.
  7. The application will generate a temporary verification code.
  8. Enter the current code on GitHub.
  9. Confirm the setup.

Afterward, the authenticator app can generate verification codes whenever GitHub requests them.

Keep your authentication device secure. Anyone who can access your authenticator application may potentially be able to generate codes for your account.

Method 3: Save Your Recovery Codes

Recovery codes are important because they can help you regain access if you lose access to your normal 2FA method.

During the 2FA setup process, GitHub provides recovery codes.

Save them somewhere secure.

You can:

  • Download the codes.
  • Print them.
  • Store them in a secure password manager.
  • Keep an offline backup in a safe location.

Do not post recovery codes online or send them to other people.

Each recovery code should be treated as sensitive account information. If someone obtains your unused recovery codes, they may be able to use them to bypass the normal second authentication step.

If you use a recovery code, treat it as consumed and keep track of your remaining codes.

Method 4: Add a Security Key

A hardware security key can provide another strong authentication method.

Security keys are physical devices that can be connected to or used with a compatible computer or mobile device.

To add one:

  1. Sign in to GitHub.
  2. Open Settings.
  3. Select Password and authentication.
  4. Locate the two-factor authentication settings.
  5. Choose the option to add a security key.
  6. Give the key a recognizable name.
  7. Connect or activate the security key when GitHub asks.
  8. Complete the registration process.

The exact prompts depend on the security key and browser you are using.

A security key can be particularly useful if you want a physical authentication method that does not depend entirely on manually entering temporary codes.

Keep the security key in a secure location and consider having an additional recovery method available.

Method 5: Add Additional Authentication Methods

Using more than one authentication method can make account recovery easier.

After enabling 2FA, review the available authentication options in your GitHub security settings.

Depending on your account and current GitHub features, you may be able to configure additional methods or recovery options.

For example, you might use:

  • An authenticator application.
  • A security key.
  • Recovery codes.
  • Another supported authentication method.

Having a backup method is useful if your primary phone is lost, damaged, or unavailable.

However, adding more authentication methods also means you should protect each one carefully.

Method 6: Verify Your 2FA Setup

After enabling 2FA, test the setup before relying on it.

Sign out of GitHub and sign back in.

  1. Open GitHub.
  2. Enter your username or email address.
  3. Enter your password.
  4. Continue to the authentication step.
  5. Enter the code from your authenticator app or use your configured authentication method.
  6. Complete the sign-in process.

If you are able to sign in successfully, your 2FA configuration is working.

Keep your recovery codes accessible in case you later lose access to your authentication device.

Method 7: Review GitHub Account Security

Enabling 2FA is only one part of securing your GitHub account.

After setting it up, review your other account-security settings.

Check:

  • Your password.
  • Authorized applications.
  • SSH keys.
  • Personal access tokens.
  • Connected devices or sessions.
  • Recovery options.
  • Recent account activity.

Remove credentials or access methods that you no longer use.

For example, if an old personal access token is no longer required, revoking it reduces the number of credentials that could potentially be abused.

You should also use a unique password for GitHub rather than reusing a password from another website.

Method 8: What to Do If You Lose Your 2FA Device

Losing your phone or authentication device does not necessarily mean you permanently lose access to your GitHub account.

First, try your configured backup method.

If you saved GitHub recovery codes, use an unused recovery code when GitHub requests two-factor authentication.

If you configured another supported authentication method, use that method instead.

After recovering your account:

  1. Sign in to GitHub.
  2. Open your security settings.
  3. Review your two-factor authentication methods.
  4. Remove methods you no longer control.
  5. Add a new trusted authentication method.
  6. Generate or update recovery information if GitHub provides the option.

This is why saving recovery codes during the original 2FA setup is so important.

Conclusion

Enabling GitHub 2FA is an effective way to add another layer of protection to your account. The setup can be completed from GitHub’s security settings, and an authenticator application provides a convenient way to generate verification codes.

For stronger account protection, consider adding a security key and keeping recovery codes in a secure location. It is also a good idea to review your SSH keys, personal access tokens, authorized applications, and other account-security settings regularly.

Most importantly, do not rely on your password alone. Use a unique password, protect your authentication devices, and keep your recovery information somewhere safe.

FAQs

1. Is GitHub 2FA free?

GitHub’s two-factor authentication is an account-security feature and does not require you to purchase a separate 2FA service. An authenticator application can also be used to generate verification codes.

2. What happens if I lose my phone with my authenticator app?

Use another configured authentication method or an unused GitHub recovery code if available. After regaining access, update your 2FA configuration and remove authentication methods you no longer control.

3. Can I use a security key for GitHub 2FA?

Yes. GitHub supports compatible security keys as an authentication method. You can register a security key through your account’s security settings.

4. Where should I store GitHub recovery codes?

Store them somewhere secure and accessible to you when needed, such as a trusted password manager or a protected offline location. Never share recovery codes publicly.

Quick Summary

  • Enable GitHub 2FA from Settings > Password and authentication.
  • An authenticator app provides a convenient way to generate verification codes.
  • Save your GitHub recovery codes in a secure location.
  • Consider adding a security key and regularly reviewing your GitHub account security settings.

Related Articles

Popular Categories