July 30, 2026
New https://fivenines.io/changelog/16-2fa-is-here🔐 2FA is here
Two-factor authentication is now available on every plan, with any TOTP app
Turning it on
- User Settings: Two-factor authentication tab Scan the QR code with your authenticator app, or type the key in by hand, then enter the six-digit code to confirm.
- You will then get 10 recovery codes. They are shown once and cannot be retrieved afterwards, so save them before you leave the page, they are how you get back in if you lose your phone. You can mint a fresh set at any time from the same page.
- At sign-in, tick Remember this device for 30 days to skip the code on a browser you trust. Every remembered device is listed in your settings and can be revoked on its own, which takes effect immediately.
Requiring it across your organization
Admins have a new page: Organization Settings, Sign-in policy. Switch on
Require two-factor authentication and everyone in the organization has to
enroll.
Two things to know before you enable it:
- You have to enroll first. The switch stays unavailable until your own account has a second factor, otherwise you would be locked out of the very page that turns it back off.
- Members are stopped, not locked out. Anyone without a second factor lands on the setup page on their next request and can finish enrolling there and then. Nothing is deleted and no new invitation is needed.
Switching the policy back off leaves everyone enrolled; it just stops enforcing.
Specific cases
People who sign in through SAML single sign-on are exempt, your identity
provider owns MFA for them. GitHub sign-in is not: we have no way to verify
GitHub's own 2FA, so those accounts get the prompt like everyone else. Turning
2FA off, or regenerating recovery codes, always asks for your password or a
current code first.