Account & sign-in · Two-factor authentication

Turn off two-factor authentication

Disable the six-digit code at sign-in from Settings › Security and Privacy — you need one last code from your authenticator. And if the phone is gone.

WiA·2 min·Updated 11 Sept 2026·Verified against app release 2026.09
Screenshots for
Same steps on every device — only the pictures change. Show all

Two-factor authentication (TOTP) asks for a six-digit code from your authenticator app after your password. You can switch it off at any time from Settings — but only from a session that has already passed the two-factor check, and only by entering one more valid code. That last code is what stops someone who merely knows your password from removing the second factor.

Keep it on if you can

Two-factor protects sign-in. Turning it off means your password alone is enough to get into your account. If you are switching authenticator apps or phones, disable it here and set it up again straight away on the new device.

Turn it off

  1. Open Settings. Click your name at the bottom-left, then Settings.
    1Settings2Your name opens this menuWeb & desktop
    Your name at the bottom-left opens the account menu.1
    1Tap your name, then SettingsiPhone
    Your name at the bottom-left opens the account menu.1
    1Tap your name, then SettingsAndroid
  2. Go to Security and Privacy. Under Two-Factor Authentication you see Two-factor authentication is enabled with a green dot. Click Disable TOTP.
    1Security and Privacy2Two-factor authentication is enabled3Disable TOTPWeb & desktop
    Security and Privacy with two-factor enabled: the green dot and the Disable TOTP button.12
    1Two-factor authentication is enabled2Disable TOTPiPhone
    Security and Privacy with two-factor enabled: the green dot and the Disable TOTP button.12
    1Two-factor authentication is enabled2Disable TOTPAndroid
  3. Enter a current code. The prompt reads Enter a code from your authenticator app to disable two-factor authentication. Type the six digits shown in your app. The form submits by itself when the sixth digit is in; you can also click the red Disable TOTP button. Cancel backs out without changing anything.
    1Type the six digits from your app2Disable TOTP3Cancel keeps 2FA onWeb & desktop
    One last code from the authenticator app confirms the change.123
    1Six digits2Cancel3Disable TOTPiPhone
    One last code from the authenticator app confirms the change.123
    1Six digits2Cancel3Disable TOTPAndroid
  4. Done. A toast says TOTP disabled successfully and the section shows Enable TOTP again. From the next sign-in on, only your username and password are asked for.
    1Enable TOTP — 2FA is now offWeb & desktop
    Back to the starting state: Enable TOTP is offered again.1
    1Enable TOTP — 2FA is now offiPhone
    Back to the starting state: Enable TOTP is offered again.1
    1Enable TOTP — 2FA is now offAndroid

On the phone, open the menu ☰ first, tap your name at the bottom of the drawer, then SettingsSecurity and Privacy. The steps are otherwise identical.

What to expect

  • The secret stored for your account is erased, not just switched off. If you enable two-factor again later you scan a new QR code — the old entry in your authenticator app stops working and can be deleted.
  • Other devices you are signed in on stay signed in. Disabling two-factor does not end any session.
  • Five wrong codes in a row lock code entry for that account for 15 minutes (Too many incorrect codes. Try again later.). Wait, then try once more with a fresh code — and check that your phone's clock is set automatically.

What our server sees

Cannot see

  • Your mail, chats or attachments — two-factor has nothing to do with encryption
  • Your passphrase or private key

Can see

  • That two-factor was enabled and is now disabled on your account
  • Whether each code attempt succeeded or failed

Common questions

I lost the phone with the authenticator app. How do I turn two-factor off?

Private.Ki has no backup codes, so there is no code you can type instead. You have two ways back in:

  1. A device that is still signed in. If any browser or phone is still signed in to your account, open SettingsSecurity and Privacy there and click Disable TOTP. You still need one valid code for that step, so this only helps if the authenticator app was backed up or is installed on a second device.
  2. Support. If you are signed out everywhere, contact support. We can verify that the account is yours through your recovery address, if you set one. We cannot remove two-factor on your word alone — that would defeat the point of having it.

Why does it ask for a code again? I already signed in with one.

Removing the second factor is the one action a second factor must never allow without proof that you still hold it. The code you enter here is that proof. It also has to come from a session that itself passed the two-factor check; a session that skipped it (for example one minted before you enabled two-factor) is refused with TOTP verification required.

I clicked Disable TOTP by mistake. Is anything changed?

No. Nothing changes until a valid code has been accepted. Click Cancel and the section returns to Two-factor authentication is enabled.

Does turning two-factor off affect my messages?

No. Your messages are protected by encryption, not by two-factor. Turning it off only changes what is asked at sign-in. See How encryption works.

Article account/turn-off-two-factor-authenticationReplaces: How to disable 2‑factor authentication (2FA) at Private.KiScreenshots regenerated automatically for release 2026.09