Two-factor authentication
Last updated:
Codebahn signs you in with a code sent to your email. Two-factor authentication adds a second step after that code: a passcode from an authenticator app, or a security key. Turn it on the day you sign up; it takes two minutes. Then: nothing else changes. SSH keys, access tokens, CI, the CLI and the MCP server keep working as before. When the CLI or the MCP server opens the browser to sign you in, the second step appears there.
Turn it on
Section titled “Turn it on”- Install an app that supports time-based one-time passcodes on your phone
- Open Settings > Security and choose Enroll into two-factor authentication
- Scan the image with the app, or enter the secret by hand
- Enter the passcode the app shows and choose Verify
Save your recovery key
Section titled “Save your recovery key”Codebahn shows a single-use recovery key once, right after you enroll. Store it in your password manager before you leave the page. It signs you in one time if you lose your authenticator; after you use it, generate a new one with Regenerate single-use recovery key.
Add a security key
Section titled “Add a security key”Optional, on top of the app. Under Settings > Security, register a hardware key or your device’s built-in authenticator. With a key registered, sign-in asks for the key, with a link back to your passcode if you also enrolled the app. Enroll the app first: the recovery key belongs to the app enrollment, and a key alone leaves you with no way back if you lose it.
If you lose access
Section titled “If you lose access”Use your recovery key first. It signs you in once; generate a new one right after.
Lost both? Codebahn resets two-factor authentication only with proof that you already hold another credential of the account, and only after a three-day delay. Any one of these counts:
- a challenge signed with an SSH key registered on the account
- a personal access token of the account, used to perform one action we ask for; never send us the token itself
- confirmation from an owner of your organization who has two-factor authentication enabled
Write to hello@codebahn.net from the account’s email address and we send the challenge. Once the proof checks out, we notify the account’s email address and every owner of the organizations it belongs to, wait three days so any of them can stop the reset, then remove the second factor. Your next sign-in asks you to enroll again.
The delay and the proof exist because sign-in has no password: a reset on an email request alone would make your account only as safe as your inbox, which is exactly what the second step protects against.
An account with no registered SSH key, no token and no organization owner cannot be recovered. Create a new account and ask an organization owner to invite it.
Two habits make all of this unnecessary: keep both an app and a security key enrolled, and if you own an organization, keep at least two owners.
Turn it off
Section titled “Turn it off”Under Settings > Security, choose Disable two-factor authentication. We recommend leaving it on.

