Skip to main content

How to enable two-factor authentication

Two-factor authentication (2FA) adds and additional layer of protection on your account. After entering your password, you will also be required to enter a rotating 6 digit code that lives inside your authenticator app on your phone.

Before You Begin

You will need:

  • A smartphone with an authenticator app installed, such as Google Authenticator, Microsoft Authenticator, Authy, or 1Password.

  • Your current password,

  • A safe place to store backup or recovery codes.

Important: Save your backup/recovery codes before finishing the setup. If you lose your phone and do not have these, you will need to create a ticket to reset your 2FA.

Enabling 2FA in WHMCS

  1. Log into the client area here.

  2. Click your name in the top-right corner and choose Security Settings or using the link here.

  3. Under Security Settings click Click here to Enable.

  4. When Enable Two-Factor Authentication menu opens click Get Started.

  5. Open your authenticator app and scan the QR code shown on screen. If you can't scan it, enter the code manually shown above the QR code.

  6. Enter the 6-digit code your authenticator app displays and click Submit.

  7. WHMCS will display a backup code. Copy and store it somewhere securely then click Close.

Disabling 2FA in WHMCS

  1. Log into the client area here.

  2. Click your name in the top-right corner and choose Security Settings or using the link here.

  3. Under Security Settings click Click here to Disable.

  4. Enter your account password to confirm.

We strongly recommend having 2FA enabled as an extra layer of security

Enabling 2FA in Pterodactyl

  1. Log into the Pterodactyl Panel here.

  2. Click Account in the left sidebar navigation or using the link here.

  3. In the Two-Step Verification section click Enable.

  4. Open your authenticator app and scan the QR code shown on screen. If you can't scan it, enter the code manually shown below the QR code.

  5. Enter the 6-digit code your authenticator app displays along with your account password and click Enable.

  6. The panel will display a list of recovery tokens. Copy and store it somewhere securely. Each token can be used once in case you lose access to your authenticator app.

Disabling 2FA in Pterodactyl

  1. Log into the Pterodactyl Panel here.

  2. Click Account in the left sidebar navigation or using the link here.

  3. In the Two-Step Verification section click Disable.

  4. Enter your account password to confirm.

Troubleshooting

I got a new phone.

Transfer your authenticator app accounts before wiping the old phone, or disable 2FA on your accounts and set them up again on your new device. If you can no longer access the old device, use your backup or recovery token.

I lose my phone and my backup codes.

You will need to submit a ticket so a staff member can manually disable your 2FA. Additional verification may be needed.

Did this answer your question?