Account & sign-in · Two-factor authentication

Set up two-factor authentication (TOTP)

Add a second step to sign-in — a six-digit code from an authenticator app on your phone. Someone who knows your password still can't get in without it.

WiA·2 min·Updated 11 Sept 2026·Verified against app release 2026.09
Screenshots for
Same steps on every device — only the pictures change. Show all

Two-factor authentication (2FA) adds a second check when you sign in: after your username and password, Private.Ki asks for the current six-digit code from an authenticator app. Private.Ki uses the standard TOTP method, so any authenticator app works.

Before you start

Install an authenticator app if you don't have one — Google Authenticator, Authy, Aegis, 1Password and Bitwarden all work.

Turn it on

  1. Open Settings. Click your name at the bottom-left, then Settings.

    1Settings2Your name opens this menuWeb & desktop
    Your name at the bottom-left opens the account menu.1
    1Tap your name, then SettingsiPhone
    Your name at the bottom-left opens the account menu.1
    1Tap your name, then SettingsAndroid
  2. Go to Security and Privacy and click Enable TOTP under Two-Factor Authentication.

    1Security and Privacy2Enable TOTPWeb & desktop
    Security and Privacy → Enable TOTP.1
    1Enable TOTPiPhone
    Security and Privacy → Enable TOTP.1
    1Enable TOTPAndroid
  3. Scan the QR code with your authenticator app. Can't scan? Type the code shown under Or enter this code manually into the app instead.

    1Scan this2…or type this into the app3Enter the 6 digits the app showsWeb & desktop
    The setup screen: QR code, manual code and the six-digit verification field.1234
    1QR code2Manual entry code3Six-digit code4Verify & EnableiPhone
    The setup screen: QR code, manual code and the six-digit verification field.1234
    1QR code2Manual entry code3Six-digit code4Verify & EnableAndroid
    Codes expire every 30 seconds

    If a code is rejected, wait for the app to show the next one and try again. Make sure your phone's clock is set automatically — TOTP depends on it.

  4. Enter the six-digit code from the app and click Verify & Enable. You'll see Two-factor authentication is enabled, and the button changes to Disable TOTP.

    12FA is onWeb & desktop
    Done — two-factor authentication is enabled.12
    1Two-factor authentication is enabled2Disable TOTPiPhone
    Done — two-factor authentication is enabled.12
    1Two-factor authentication is enabled2Disable TOTPAndroid

On the phone, open the menu ☰ first and tap your name at the bottom of the drawer to reach Settings. Because the authenticator app is usually on the same phone, tap the manual code to copy it instead of scanning.

What changes at sign-in

After your username and password, Private.Ki asks for the current code from your authenticator app. A device you add by QR code takes over the signed-in session, so you are not asked twice on that device.

1Six digits2VerifyWeb & desktop
The two-factor prompt after sign-in.12
1Six digits2VerifyiPhone
The two-factor prompt after sign-in.12
1Six digits2VerifyAndroid

What our server sees

Cannot see

  • Your mail, chats or attachments — 2FA has nothing to do with encryption
  • Your passphrase or private key
  • Which authenticator app you use

Can see

  • That two-factor is enabled on your account
  • The TOTP secret — it has to, to check your codes
  • Whether a code attempt succeeded or failed
Why 2FA doesn't protect your messages — and doesn't need to

Two-factor protects sign-in. Your messages are protected by encryption: even someone who gets past sign-in still needs your passphrase or your unlocked device to read anything. See How encryption works.

Common questions

I lost my phone or the authenticator app

If you are still signed in on another device, go to Security and Privacy, click Disable TOTP and set it up again on the new phone. If you are signed out everywhere, contact support — we can verify you through your recovery address if you set one. There are no backup codes, and we cannot remove 2FA on your word alone.

Can I use a hardware key or passkey instead?

Not at the moment. Hardware security keys are not supported for sign-in, and passkeys are not offered yet.

Article account/two-factor-authenticationReplaces: How to set up 2‑factor authentication (2FA) at Private.Ki, Authenticator app on Private.KiScreenshots regenerated automatically for release 2026.09