Skip to content

Two-factor authentication

Last updated:

Codebahn signs you in with a code sent to your email. Two-factor authentication adds a second step after that code: a passcode from an authenticator app, or a security key. Turn it on the day you sign up; it takes two minutes. Then: nothing else changes. SSH keys, access tokens, CI, the CLI and the MCP server keep working as before. When the CLI or the MCP server opens the browser to sign you in, the second step appears there.

  1. Install an app that supports time-based one-time passcodes on your phone
  2. Open Settings > Security and choose Enroll into two-factor authentication
  3. Scan the image with the app, or enter the secret by hand
  4. Enter the passcode the app shows and choose Verify

Codebahn shows a single-use recovery key once, right after you enroll. Store it in your password manager before you leave the page. It signs you in one time if you lose your authenticator; after you use it, generate a new one with Regenerate single-use recovery key.

Optional, on top of the app. Under Settings > Security, register a hardware key or your device’s built-in authenticator. With a key registered, sign-in asks for the key, with a link back to your passcode if you also enrolled the app. Enroll the app first: the recovery key belongs to the app enrollment, and a key alone leaves you with no way back if you lose it.

Use your recovery key first. It signs you in once; generate a new one right after.

Lost both? Codebahn resets two-factor authentication only with proof that you already hold another credential of the account, and only after a three-day delay. Any one of these counts:

  • a challenge signed with an SSH key registered on the account
  • a personal access token of the account, used to perform one action we ask for; never send us the token itself
  • confirmation from an owner of your organization who has two-factor authentication enabled

Write to hello@codebahn.net from the account’s email address and we send the challenge. Once the proof checks out, we notify the account’s email address and every owner of the organizations it belongs to, wait three days so any of them can stop the reset, then remove the second factor. Your next sign-in asks you to enroll again.

The delay and the proof exist because sign-in has no password: a reset on an email request alone would make your account only as safe as your inbox, which is exactly what the second step protects against.

An account with no registered SSH key, no token and no organization owner cannot be recovered. Create a new account and ask an organization owner to invite it.

Two habits make all of this unnecessary: keep both an app and a security key enrolled, and if you own an organization, keep at least two owners.

Under Settings > Security, choose Disable two-factor authentication. We recommend leaving it on.