> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gpuoutlet.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

> Set up an authenticator app, learn which actions ask for a code, and replace a lost authenticator.

Your second factor is a 6-digit code from an authenticator app on your phone, such as 1Password, Google Authenticator or Authy. GPU Outlet asks for it before two actions, and nothing else. It is not asked at sign-in or on every screen.

## When you are asked for a code

When an action needs your second factor, a dialog titled **Confirm it is you** opens. It says why the code is needed. Enter the six digits your app shows and the action continues.

A confirmation stays valid for 15 minutes. Other protected actions in that window do not ask again.

If your account has no second factor yet, the action cannot go ahead until you set one up.

<Tip>
  Codes change every 30 seconds. If a code is refused, wait for the next one and enter that.
</Tip>

## Actions that ask for it

Two actions, and no others:

* **Signing an agreement.** It binds your company to the document. See [Agreements](/account/agreements).
* **Changing your company's legal name or country.** Agreements are already signed under them. This applies once your company is verified, and also once it has signed anything. See [Company](/account/company#after-verification).

Your **Security** page lists the same two under "This is what asks for it".

Who can take each action is in [Team and roles](/account/team-and-roles#what-each-role-can-do). The role still decides who may act. The second factor only decides which two acts are challenged.

Nothing else asks for a code. In particular, these do not:

* Signing in
* Creating a company, or accepting an invitation
* Inviting a member, changing a member's role or position, or removing a member
* Submitting the company for verification
* Accepting an opportunity and revealing the buyer
* Declining an opportunity
* Downloading a signed agreement
* Publishing, editing or removing a listing
* Creating, editing or closing a request
* Confirming you are ready, and sending, paying or confirming invoices
* Filing an existing relationship claim

## Turn it on

You can turn it on during your first sign-in, on the **Additional Security** step. You can also do it any time in settings.

<Steps>
  <Step title="Open Security settings">
    Go to **Settings** → **Security** (`/app/settings/security`) and press **Set up two-factor authentication**.
  </Step>

  <Step title="Show the QR code">
    Press **Show me the QR code**.
  </Step>

  <Step title="Add it to your app">
    Scan the QR code with your authenticator app. If you are setting up on the same device, type the key shown under the code instead.
  </Step>

  <Step title="Confirm">
    Enter the six digits your app shows and press **Confirm**.
  </Step>
</Steps>

The **Security** page then reads "Two-factor authentication is on" with the date you added it. You also get a notification, "Two-factor authentication was turned on".

Setting up a new factor asks only for your authenticator app. You do not need an emailed code.

<Note>
  We record only that a factor is on and when it was added. We do not keep a record of which app holds it.
</Note>

## It cannot be switched off

There is no way to turn two-factor authentication off once it is on. If you lose access to your authenticator, you replace it.

## Replace a lost authenticator

Use this if you changed phones or can no longer open your authenticator app.

<Steps>
  <Step title="Start the replacement">
    On the **Security** page, under **If you have lost your authenticator**, press **Replace my authenticator**. If a code prompt is already open and your code fails, you can also choose **I no longer have my authenticator**.
  </Step>

  <Step title="Get an emailed code">
    Press **Email me a code**. We email a code to your account's address. It is valid for 10 minutes.
  </Step>

  <Step title="Enter the emailed code">
    Type the code from the email and press **Continue**. This is not a code from your authenticator app.
  </Step>

  <Step title="Set up the new authenticator">
    Scan the new QR code, enter the six digits from your app and press **Confirm**.
  </Step>
</Steps>

You get a notification, "Two-factor authentication is being replaced". If you did not start a replacement, contact [support](/reference/support) immediately.

<Warning>
  Your old factor is revoked as soon as the replacement starts. Until you confirm the new one, your account has no second factor, and every protected action is refused. Finish the setup in one go.
</Warning>

If you stop halfway, the **Security** page shows "Two-factor authentication is not set up on this account." Set up a new factor from there.

## If the GPU Outlet team resets it for you

If you cannot complete the replacement yourself, contact [support](/reference/support). The GPU Outlet team can reset your second factor.

When that happens:

* You get a notification, "Two-factor authentication was reset".
* You also get an email about it.
* Your account has no second factor until you set up a new one in **Security** settings.

If you did not ask for a reset, contact support straight away.

## Related

<CardGroup cols={2}>
  <Card title="Agreements" icon="file-signature" href="/account/agreements">
    Sign an agreement, the first of the two actions.
  </Card>

  <Card title="Company" icon="building" href="/account/company">
    Change a legal name or country, the second of the two.
  </Card>

  <Card title="Sign in" icon="right-to-bracket" href="/account/sign-in">
    How signing in works without a password.
  </Card>

  <Card title="Team and roles" icon="users" href="/account/team-and-roles">
    See which roles can take each action.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.