Two-factor authentication (2FA) adds a second step when you sign in: after your password, you enter a 6-digit code from an authenticator app. It's one of the strongest ways to protect your account.
How it works
- Open Settings → Security and enable Two-Factor Authentication.
- Scan the QR code (or enter the key manually) with any authenticator app — Google Authenticator, Microsoft Authenticator, Authy, 1Password or Bitwarden.
- Confirm one code to verify it's working.
- Save your 10 recovery codes somewhere safe (download, copy or print).
From then on, sign-in asks for a code after your password. If you signed up with Google and enabled 2FA, you'll be asked for a code after the Google step too.
Limitations
- Moza supports app-based codes (TOTP) only — there's no SMS or email code option.
- Disabling 2FA or regenerating recovery codes requires your password and a current code.
- Each recovery code works once.
Common Questions
Which authenticator apps work?
Any standard TOTP app — Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, and others.
What if I lose my phone?
Use one of the 10 recovery codes you saved when enabling 2FA. Each works once; you can regenerate the set after signing in.