Two-step sign-in

Add a code from your phone to every sign-in, so someone who gets into your email still can't get into your sites.

Updated Oct 6, 2026

WP Foreman can reach every site you connect, so it’s worth protecting. With two-step sign-in on, after Google or an emailed sign-in link WP Foreman also asks for a 6-digit code from an authenticator app on your phone.

Turn it on

  1. Go to Settings › Two-step sign-in and click Set up two-step sign-in.
  2. Open an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, Authy and others all work) and scan the QR code. Can’t scan? Type the key shown next to it.
  3. Enter the 6-digit code the app shows and click Turn on.
  4. Save the 10 recovery codes somewhere safe, like your password manager. They’re shown once.

We email you whenever two-step sign-in is turned on or off.

Signing in

Sign in as usual, then enter the code from your app. Tick Don’t ask again on this browser for 30 days on computers you trust. Signing in somewhere new always asks.

Lost your phone?

  • On the code page, click Lost your phone? Use a recovery code. Each recovery code works once.
  • Then set it up again on your new phone: make new recovery codes or turn it off and on from Settings › Two-step sign-in.
  • Lost your recovery codes too? Use our contact page. We’ll check it’s really you before resetting it.

Good to know

  • Admins must have two-step sign-in on to use the admin area, and can’t turn it off.
  • Turning it off or making new recovery codes asks for a current code first.
  • API tokens aren’t affected. Keep them secret and revoke any you don’t use.
Was this helpful?