docs/help/contents/two-factor-authentication.md
Two-factor authentication (2FA) asks for a 6-digit code in addition to your password every time you log in. You set it up from {{settings}}, choose one of three methods — an authenticator app, email or SMS — and save the recovery codes Notesnook shows you at the end.
::: info 2FA protects your account, not your notes Your notes are already end-to-end encrypted with a key derived from your password. 2FA stops someone from logging in as you. It is a separate protection from the encryption of your data.
:::
| Method | What it is | Plan |
|---|---|---|
{{mfaAuthAppTitle}} | Use an authenticator app to generate 2FA codes. Marked {{recommended}}. | All plans |
{{mfaEmailTitle}} | Notesnook sends a 2FA code to your account email when prompted. | All plans |
{{mfaSmsTitle}} | Notesnook sends an SMS with a 2FA code when prompted. | Pro and Believer |
An authenticator app is the recommended option because it generates codes on your device and keeps working without a network connection.
{{settings}} → {{authentication}}.{{twoFactorAuth}}, press {{change}} next to {{change2faMethod}}.{{verifyItsYou}} prompt with your account password.{{select2faMethod}} screen.{{sendCode}} for email and SMS — and type the code into {{enterSixDigitCode}}.{{saveRecoveryCodes}} screen, then finish.You should now see {{twoFactorAuthEnabled}}.
Notesnook shows a QR code with the instruction {{mfaScanQrCode}}. If your app cannot scan it, copy the text key shown underneath instead — spaces do not matter. Your app then displays a rotating 6-digit code to enter.
Notesnook pre-fills your account email and sends the code there when you press {{sendCode}}. You cannot enter a different address — email 2FA always uses your account email.
SMS 2FA is available on Pro and Believer. Enter your phone number with the country code (for example +1234567890), press {{sendCode}}, and enter the code from the SMS. On free and Essential plans, selecting {{mfaSmsTitle}} shows an upgrade prompt instead — see Plans & limits.
For email and SMS, the {{sendCode}} button becomes Resend code in … and counts down for 60 seconds after each send. On mobile, requesting a new code too early shows {{resendCodeWait}}. The countdown exists both during setup and at login.
A fallback is a second method you can use when your primary one is unavailable — for example email as a fallback when your authenticator app is on a phone you don't have. The method you already use as primary is not offered again in the list.
{{settings}} → {{authentication}}.{{addFallback2faMethod}} (it reads {{change2faFallbackMethod}} once one exists).{{verifyItsYou}} prompt.You should now see {{fallbackMethodEnabled}}.
Recovery codes are single-use codes that log you in when no 2FA method is reachable. Notesnook shows them once during setup, and you can pull them up again at any time.
{{settings}} → {{authentication}}.{{viewRecoveryCodes}} and confirm the {{verifyItsYou}} prompt.{{print}}, {{copy}} or Download to keep a copy. Download saves a notesnook-recovery-codes.txt file.{{regenerate}} to replace the current set with a new one.::: warning Regenerating invalidates the old codes Once you regenerate, the previous set stops working. Replace any copy you printed or stored.
:::
<!-- TODO: screenshot — the Save recovery codes screen with the Print / Copy / Download / Regenerate buttons -->After you enter your email and password, Notesnook asks for a 6-digit code:
Resend code in … is disabled for 60 seconds.{{mfaAuthAppSelector}}, {{mfaEmailSelector}} or {{mfaSmsSelector}} — opens {{select2faMethod}}, where you can switch to your fallback method or choose {{recoveryCode}}.Entering a recovery code instead of a 6-digit code logs you in the same way.
Work through these in order:
Don't have access to … link and pick your fallback.{{recoveryCode}} and enter one of the codes you saved.{{settings}} — an existing session does not need a fresh 2FA code.::: danger Notesnook cannot bypass 2FA for you If you have no fallback method, no recovery codes and no logged-in device, support cannot unlock the account — the same way we cannot recover your password or decrypt your notes. Save your recovery codes somewhere outside the phone that holds your authenticator app.
:::
The apps do not expose a switch to disable 2FA once it is enabled. What you can change is the primary method and the fallback method, from the same {{twoFactorAuth}} settings.