July 30, 2026

New

🔐 2FA is here

Two-factor authentication is now available on every plan, with any TOTP app

Turning it on

  • User Settings: Two-factor authentication tab Scan the QR code with your authenticator app, or type the key in by hand, then enter the six-digit code to confirm.
  • You will then get 10 recovery codes. They are shown once and cannot be retrieved afterwards, so save them before you leave the page, they are how you get back in if you lose your phone. You can mint a fresh set at any time from the same page.
  • At sign-in, tick Remember this device for 30 days to skip the code on a browser you trust. Every remembered device is listed in your settings and can be revoked on its own, which takes effect immediately.

Requiring it across your organization

Admins have a new page: Organization Settings, Sign-in policy. Switch on
Require two-factor authentication and everyone in the organization has to
enroll.

Two things to know before you enable it:

  • You have to enroll first. The switch stays unavailable until your own account has a second factor, otherwise you would be locked out of the very page that turns it back off.
  • Members are stopped, not locked out. Anyone without a second factor lands on the setup page on their next request and can finish enrolling there and then. Nothing is deleted and no new invitation is needed.

Switching the policy back off leaves everyone enrolled; it just stops enforcing.

Specific cases

People who sign in through SAML single sign-on are exempt, your identity
provider owns MFA for them. GitHub sign-in is not: we have no way to verify
GitHub's own 2FA, so those accounts get the prompt like everyone else. Turning
2FA off, or regenerating recovery codes, always asks for your password or a
current code first.

← All updates

Want something that isn't here yet? Vote on the roadmap.