Set up two-factor authentication (TOTP)
Add a second step to sign-in — a six-digit code from an authenticator app on your phone. Someone who knows your password still can't get in without it.
Two-factor authentication (2FA) adds a second check when you sign in: after your username and password, Private.Ki asks for the current six-digit code from an authenticator app. Private.Ki uses the standard TOTP method, so any authenticator app works.
Install an authenticator app if you don't have one — Google Authenticator, Authy, Aegis, 1Password and Bitwarden all work.
Turn it on
Open Settings. Click your name at the bottom-left, then Settings.
1Settings2Your name opens this menuWeb & desktop
11Tap your name, then SettingsiPhone
11Tap your name, then SettingsAndroid Go to Security and Privacy and click Enable TOTP under Two-Factor Authentication.
Scan the QR code with your authenticator app. Can't scan? Type the code shown under Or enter this code manually into the app instead.
1Scan this2…or type this into the app3Enter the 6 digits the app showsWeb & desktop
12341QR code2Manual entry code3Six-digit code4Verify & EnableiPhone
12341QR code2Manual entry code3Six-digit code4Verify & EnableAndroid Codes expire every 30 secondsIf a code is rejected, wait for the app to show the next one and try again. Make sure your phone's clock is set automatically — TOTP depends on it.
Enter the six-digit code from the app and click Verify & Enable. You'll see Two-factor authentication is enabled, and the button changes to Disable TOTP.
12FA is onWeb & desktop
121Two-factor authentication is enabled2Disable TOTPiPhone
121Two-factor authentication is enabled2Disable TOTPAndroid
On the phone, open the menu ☰ first and tap your name at the bottom of the drawer to reach Settings. Because the authenticator app is usually on the same phone, tap the manual code to copy it instead of scanning.
What changes at sign-in
After your username and password, Private.Ki asks for the current code from your authenticator app. A device you add by QR code takes over the signed-in session, so you are not asked twice on that device.
What our server sees
Cannot see
- Your mail, chats or attachments — 2FA has nothing to do with encryption
- Your passphrase or private key
- Which authenticator app you use
Can see
- That two-factor is enabled on your account
- The TOTP secret — it has to, to check your codes
- Whether a code attempt succeeded or failed
Two-factor protects sign-in. Your messages are protected by encryption: even someone who gets past sign-in still needs your passphrase or your unlocked device to read anything. See How encryption works.
Common questions
I lost my phone or the authenticator app
If you are still signed in on another device, go to Security and Privacy, click Disable TOTP and set it up again on the new phone. If you are signed out everywhere, contact support — we can verify you through your recovery address if you set one. There are no backup codes, and we cannot remove 2FA on your word alone.
Can I use a hardware key or passkey instead?
Not at the moment. Hardware security keys are not supported for sign-in, and passkeys are not offered yet.

