How to set up 2FA / Two Factor Authentication
Two-factor authentication adds a second verification step each time you sign in with your password. Once enabled, you'll be asked for a time-based code from your authenticator app or password manager after entering your credentials. This applies only to password-based accounts — accounts using Single Sign-On (SSO), Google sign-on, Apple sign-on, or Passkeys will not be prompted for a code.
If you enabled 2FA before recovery codes existed, your reset flow hasn't changed yet — you won't be asked for anything extra until you generate your codes from Account Settings. So it's normal for your reset experience to look different from a colleague's
.
Enabling 2FA
- Go to Account Settings
- Enable 2FA under the Password Actions section.

- A QR code will appear. Scan it with an authenticator app — or, if you're using a password manager, copy the displayed key directly into its TOTP/2FA section.

- Enter the code generated by your app and click "Verify code and continue".
- You'll be shown six recovery codes — save these somewhere safe now. They're shown this one time only, and Toggl can't display or recover them for you afterward.

- You'll see a confirmation message once 2FA is active on your account.
Recovery codes
Recovery codes are a backup way to sign in if you ever lose access to your authenticator app or device.
- You get six codes, each in the format
XXXX-XXXX. - A recovery code can be entered instead of your 6-digit app code at login — you'll still need your email and password as usual.
- Each code works once. After it's used, it won't work again.
- Codes are shown only once, at the moment they're generated. Toggl stores only a one-way hash, so support can't look them up or show them to you again — save them somewhere secure as soon as you see them.
- Turning 2FA off deletes your codes. Turning it back on issues a brand new set of six.
Already had 2FA enabled before recovery codes existed? You won't have a set yet. Go to Account Settings, find the link under the 2FA section, and generate your codes whenever it suits you — it's a link you choose to click, not an automatic prompt, since the codes only display once. If you've already generated a set, that link won't create a new one; your existing codes stay valid and won't be shown again.
Signing in with a recovery code
If you can't access your authenticator app:
- Enter your email and password as normal.
- When asked for your authenticator code, choose the option to use a recovery code instead.
- Enter one of your six codes.
That code is now spent and can't be reused. As with password attempts, repeated incorrect codes will temporarily lock the account.
Supported authenticator apps and password managers
Any TOTP-compatible app will work. Some popular options:
Tip: Some password managers label this feature as "TOTP" (time-based one-time passcode) — that's the standard Toggl Track uses, so you're in the right place.
Turning off 2FA
- Open the Profile page > Click on Account Settings.
- Scroll to the 2FA section under Password Actions.
- Click the 3-dot menu.
- Click "Disable 2FA sign-in".

- You'll be prompted for your current 2FA code to confirm the change.

Frequently asked questions
I've lost access to my 2FA device — what do I do?
Sign in using one of your six recovery codes instead of your authenticator code — see "Signing in with a recovery code" above. A password reset will not disable 2FA or help you bypass it, so don't rely on that route.
If you don't have your recovery codes either, there's no self-service way back in — contact Support.
I'm not being prompted for 2FA upon login.
This is expected if your account uses Single Sign-On (SSO), Google sign-on, Apple sign-on, or Passkeys — 2FA is only triggered when you sign in with an email address and password, even if it's enabled on your account.
I closed the window without saving my recovery codes — can I see them again?
No, codes are shown only once by design and can't be retrieved afterward. If you still have access to your authenticator app, turn 2FA off and back on to generate a fresh set of six.
It says I already have recovery codes — I don't remember getting them.
A set was likely issued earlier, possibly when 2FA was first enabled on the account. Your existing codes are still valid and won't be reissued or shown again — if you no longer have them saved, treat it the same as losing your codes.
My recovery code was rejected.
Each code only works once — you may be reusing a code that's already been spent, or there's a typo. Try one of the other five.
I'm locked out after too many attempts.
Repeated incorrect codes or passwords temporarily lock the account, the same as with password attempts. Wait for the lock to clear, then try again with a code you haven't used yet.
My password reset asked for a code, but my colleague's didn't.
This is expected. Anyone who enabled 2FA before recovery codes existed keeps the older reset flow — no extra step — until they generate their codes in Account Settings. Once they do, their reset flow will match everyone else's.
I reset my password and 2FA is still turned on — is that a bug?
No, that's intended. Password resets do not disable 2FA. Use a recovery code if you don't have access to your authenticator device.
Can I enforce 2FA for all users in my workspace / organization?
Yes — go to the admin console and enable the "Enforce 2FA" option.

Updated on: 07/29/2026
Thank you!
