> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure two-factor authentication

> Add a second verification step to your Biqli account.

Two-factor authentication adds a rotating code after your normal sign-in. Enable it in account security, scan the setup QR code with an authenticator app, and enter a current code to finish enrollment.

Save the recovery codes in a secure password manager. Each recovery code is intended for account recovery when the authenticator is unavailable.

Disabling two-factor authentication lowers account protection and requires the security confirmation shown by Biqli.

## Enable two-factor authentication

1. Open account security and start two-factor setup.
2. Scan the QR code with an authenticator application or enter the setup key.
3. Enter the current one-time code to confirm enrollment.
4. Copy the recovery codes and store them outside the device running the
   authenticator.
5. Sign out and verify the next sign-in flow.

## Recovery codes

Use a recovery code when the authenticator device is unavailable. Treat every
code as a password and regenerate the set if it is exposed or running low. A
regeneration invalidates the previous set.

## Remove protection

Disable two-factor authentication only after completing the confirmation shown
by Biqli. If a device was lost, also review passkeys, password, and active
sessions because removing the second factor alone does not end existing access.

## Frequently asked questions

### Can I reuse a recovery code?

Treat recovery codes as one-time emergency credentials. Regenerate the set when
its security or remaining availability is uncertain.

### Why is an authenticator code rejected?

Confirm the correct account entry and make sure the device clock is set
accurately before restarting setup.
