# How do I turn on two-factor authentication (2FA)? Turn on optional two-factor sign-in in Settings > Security > 2FA. Update PrivacyNotes on your other devices first. Scan the QR code with an authenticator app, or enter the setup key manually. Save the 2FA backup key outside PrivacyNotes, confirm the saved copy, then enter a current code to finish. After setup, a new server session needs your phrase or a connected provider, followed by an authenticator code. Self-custody users still need their phrase to decrypt notes. Manage provider accounts in Settings > Account > Accounts; connecting one does not change key custody. If you lose the authenticator, add the saved 2FA backup key to another authenticator app. Losing both means we cannot restore server access. Notes already unlocked on a device remain readable and exportable. Two-factor sign-in does not add encryption or protect an already unlocked device. ## Read the source - THREAT_MODEL.md: Two-factor sign-in -> https://privacynotes.app/docs/threat-model.md (source: https://github.com/LifetimeLabsDev/PrivacyNotes.app/blob/main/THREAT_MODEL.md#two-factor-sign-in) --- Source: https://privacynotes.app/help/enable-2fa