Turn on two-factor authentication
Set up TOTP in about a minute, save your ten recovery codes — and understand why saving them matters more here than elsewhere.
Last updated 2026-08-30
Two-factor authentication is available to every account on every plan, free included.
Turning it on
Settings → Security → the Two-factor authentication card → Enable 2FA.
- Scan with your authenticator app. A QR code appears; if your app can't scan, the base32 key is printed underneath to enter by hand. The account shows up as
kitty.build. - Enter the 6-digit code your app shows.
- Press Verify & enable. A wrong code says so and lets you retry.
Any TOTP app works — 1Password, Bitwarden, Authy, Google Authenticator. Codes are accepted with about 30 seconds of clock tolerance either side.
Save your recovery codes — properly
You are shown ten recovery codes in a dialog headed "Save your recovery codes". Each works once. Use Copy all and put them somewhere that is not the phone holding your authenticator.
Read this part carefully, because it is the difference between an inconvenience and losing your account:
- They are shown once and never again.
- There is no way to regenerate them without turning 2FA off and on again (which needs your password and a working second factor).
- If you lose both your authenticator and your codes, there is no self-serve recovery path. A password reset does not clear 2FA.
So: copy them now, into your password manager, before you close that dialog.
Signing in afterwards
After your password you land on a page headed Two-factor authentication. Enter the code, or click Use a recovery code and enter one of your ten.
Eight failed attempts locks the attempt for 15 minutes.
Turning it off
Same card, Disable 2FA, confirmed with your password. This wipes the secret and all remaining recovery codes. Re-enabling issues a fresh set of ten — which is, today, the only way to rotate them.
API keys and 2FA
Worth knowing if you use MCP or the API: a bearer API key satisfies no 2FA challenge, and cannot be used to mint more keys. Keys act as you for data access, not for privilege escalation.
Frequently asked
- Can I get new recovery codes without disabling 2FA?
- Not today. Disabling and re-enabling 2FA issues a fresh set of ten; there is no separate regenerate button.
- I lost my phone and my recovery codes.
- There is no self-serve path back, and a password reset does not clear 2FA. Email info@foundergem.com — recovery is a manual, identity-checked operation and we cannot promise a turnaround.
- Is 2FA only on the bigger plans?
- No. It is available on every account on every plan, including free.
Related articles
- Reset your password or get back inReset links last an hour and work once. Here's the flow, the rate limits you might hit, and what a reset changes about your sessions.
- How your data is protectedEncryption at rest, how credentials are stored, what the AI can and can't read, and honest answers about export and deletion.
- Invite teammates and set their rolesThe four workspace roles and exactly what each can do, how to send an invite, and how to change or remove someone later.
Still stuck?
Email info@foundergem.com with your account email and what you were trying to do. A human replies, usually within one business day.
Browse all articles