Skip to content
Security

Enabling two-factor authentication

Updated Sep 15, 2026

Two-factor authentication (2FA) adds a second check when you sign in: after your password, you enter a short-lived 6-digit code generated by an app on your phone. Even if someone learns your password, they cannot sign in without that code.

What you need

An authenticator app that supports standard time-based codes (TOTP). Widely used options include Google Authenticator, Microsoft Authenticator, and password managers with built-in authenticators such as 1Password or Bitwarden. YallowHost sends codes through the app only; they are not sent by text message or email.

Turn on 2FA

  1. Sign in and open Security from the account menu, then choose Two-factor authentication.
  2. In your authenticator app, add a new account and scan the QR code shown on the page. If you cannot scan it, choose Can't scan? Enter this key and type the key into the app manually.
  3. Enter the current 6-digit code from the app and choose Enable 2FA.

From now on, after entering your password, you will be asked for a code from the app. Codes change every 30 seconds, so enter the one currently displayed.

Store your setup key safely

There are no separate backup codes, so the setup key is your recovery method. Before you leave the setup page, save the key shown under "Can't scan? Enter this key" in a secure place, such as your password manager or a printed copy kept somewhere safe. With that key you can add the account to a new phone. If your password manager supports authenticator codes, keeping the entry there also means the codes move with you when you change devices.

If codes are rejected

  • Check your phone's clock. Codes are based on the current time, so set your phone to update the time automatically.
  • Make sure you are reading the code for the YallowHost entry, if you have several accounts in the app.
  • Wait for a fresh code if the current one is about to expire. After several failed attempts, sign-in is briefly paused for security.

Changing phones or turning 2FA off

Before switching phones, add your saved setup key to the authenticator app on the new phone and confirm it shows working codes. To turn 2FA off, open the same page, confirm with your password and choose Disable 2FA. We recommend re-enabling it straight away with your new device.

Lost your phone without the setup key?

Open a support request using the contact form on the Support Center page from the email address registered on your account. Our team will verify your identity before making any change to your sign-in security. This protects you, so expect questions that only the account owner can answer.

Still need a hand?

Our team is happy to help — open a ticket and we'll reply by email.

Get support
Need help?

How can we help?

Browse our guides or reach our support team. We typically reply by email during business hours.