Two-step authentication (also known as two-factor authentication or 2FA) adds an extra layer of protection to your Mozilla account, especially if your password is compromised.
Once enabled, signing in requires both your password and a unique authentication code generated by an authenticator app. This prevents unauthorized access to your account even if someone knows your password.
Table of Contents
How do I enable two-step authentication?
Step one - Choose an authenticator app
Before you get started, install the authenticator application of your choice. Here are some options (this is not an exclusive list of supported applications):
- Ente Auth: GitHub (Windows, Linux, Android & macOS), App Store (iOS), Google Play & F-Droid (Android). The basic web version is only for those who downloaded the above apps. Includes backups.
- Zoho OneAuth: Android, iOS & macOS, Windows. Includes backups.
- Twilio Authy Authenticator: Android, iOS & macOS. Includes backups.
- Google Authenticator: Android, iOS & macOS.
- Duo Mobile: Android, iOS & macOS.
- FreeOTP: Android, iOS & macOS.
- KeepassXC: Linux, macOS, Windows.
Step two - Connect your authenticator app
Now that one of the applications is installed, you can set up two-step authentication for your Mozilla account:
- Sign in to your Mozilla account, then open your Mozilla account settings. Alternatively, click your Mozilla account in the Firefox toolbar and select Manage account.
- You can also click the menu
button in Firefox, select your Mozilla account, and then click Manage account.
- You can also click the menu
- On the Mozilla accounts page, under Security, click the button next to Two-step authentication.
- Open the authenticator app of your choice and scan the QR code that appears on your computer.
- You can also click Can’t scan code? to display a code you can enter manually into your authenticator app.
- Tip: If you are entering the code manually on Authy, search Mozilla to get the latest logo.
- Enter the code generated by the authenticator app into the field below the QR code, and click
Step three – Set up a recovery method
At this step, you’ll be asked to set up a recovery method for your Mozilla account. This is required to complete two-step authentication (2FA) setup.
Most users will see a list of backup authentication codes at this step but, depending on your eligibility, you may see a prompt allowing you to choose between:
- Backup authentication codes – a list of one-time use codes to save in a secure location.
- Recovery phone – a phone number that can receive a one-time password (OTP) via SMS if you lose access to your authenticator app.
Backup authentication codes
- A list of one-time use backup authentication codes will be displayed. These codes can be used in the event you lose access to the authenticator app you just set up.
- Download, copy or print your backup authentication codes, and save them in a safe place. Click .
- Paste one of the codes to confirm that you have saved them (if you haven't, click the arrow on the left to go back to the list of codes).
- Click .
The setup of two-step authentication on your Mozilla account is now complete!
Recovery phone
This feature is experimental and is being introduced to the Firefox user base through a progressive rollout. It may not yet be available to all users.
Follow the steps below to set up your recovery phone number:
- Enter your phone number.
- Click the
- Enter the six-digit code, and click
- Recovery phone will now be available as a recovery method in the event that you can’t use your authenticator app to sign in. Rate limits may apply.
How to remove your recovery phone number
You can remove your recovery phone number from your Mozilla account settings. Follow the steps below to learn how.
- Sign in to your Mozilla account, then open your Mozilla account settings.
- In the Security section, go to Recovery Phone.
- Click the
button.
- You will be asked to confirm that you want delete your recovery phone number. Please note that a recovery method is required for 2FA - if you want to remove your phone number, you may need to create a set of backup authentication codes before being allowed to proceed. Alternatively, you may choose to change your phone number or to disable two-step authentication entirely.