Turn on two-factor authentication

Set up TOTP in about a minute, save your ten recovery codes — and understand why saving them matters more here than elsewhere.

Last updated 2026-08-30

Two-factor authentication is available to every account on every plan, free included.

Turning it on

Settings → Security → the Two-factor authentication card → Enable 2FA.

  1. Scan with your authenticator app. A QR code appears; if your app can't scan, the base32 key is printed underneath to enter by hand. The account shows up as kitty.build.
  2. Enter the 6-digit code your app shows.
  3. Press Verify & enable. A wrong code says so and lets you retry.

Any TOTP app works — 1Password, Bitwarden, Authy, Google Authenticator. Codes are accepted with about 30 seconds of clock tolerance either side.

Save your recovery codes — properly

You are shown ten recovery codes in a dialog headed "Save your recovery codes". Each works once. Use Copy all and put them somewhere that is not the phone holding your authenticator.

Read this part carefully, because it is the difference between an inconvenience and losing your account:

  • They are shown once and never again.
  • There is no way to regenerate them without turning 2FA off and on again (which needs your password and a working second factor).
  • If you lose both your authenticator and your codes, there is no self-serve recovery path. A password reset does not clear 2FA.

So: copy them now, into your password manager, before you close that dialog.

Signing in afterwards

After your password you land on a page headed Two-factor authentication. Enter the code, or click Use a recovery code and enter one of your ten.

Eight failed attempts locks the attempt for 15 minutes.

Turning it off

Same card, Disable 2FA, confirmed with your password. This wipes the secret and all remaining recovery codes. Re-enabling issues a fresh set of ten — which is, today, the only way to rotate them.

API keys and 2FA

Worth knowing if you use MCP or the API: a bearer API key satisfies no 2FA challenge, and cannot be used to mint more keys. Keys act as you for data access, not for privilege escalation.

Frequently asked

Can I get new recovery codes without disabling 2FA?
Not today. Disabling and re-enabling 2FA issues a fresh set of ten; there is no separate regenerate button.
I lost my phone and my recovery codes.
There is no self-serve path back, and a password reset does not clear 2FA. Email info@foundergem.com — recovery is a manual, identity-checked operation and we cannot promise a turnaround.
Is 2FA only on the bigger plans?
No. It is available on every account on every plan, including free.

Related articles

Still stuck?

Email info@foundergem.com with your account email and what you were trying to do. A human replies, usually within one business day.

Browse all articles