# Two-factor authentication (2FA)

> Two-factor authentication (2FA) asks for a second proof on top of the password when you sign in. That proof can be a code sent to your phone, a number in an authenticator app or a physical security key. Even if the password is stolen, nobody gets in without the second step.

- URL: https://radkod.com/en/glossary/two-factor-authentication
- Publisher: RadKod
- Published: 2026-07-30

## What is two-factor authentication?

Two-factor authentication means a sign-in asks for a second proof besides the password. It is often shortened to 2FA. The idea is simple: something you know (the password) plus something you have (a phone or a key).

Here is an everyday case. The password of an employee who uses your website admin panel leaked in a breach on another site. Someone tries it on your panel. With 2FA off, they get in and can delete products or download customer data. With 2FA on, the panel asks for the code on the employee's phone, and the attempt stops there.

## How does it work?

There are three common methods. The first is a one-time code by SMS. It is easy, but it is the weakest option against attacks such as SIM swapping. The second is an authenticator app, such as Google Authenticator or Microsoft Authenticator, showing a code that changes every 30 seconds. It is safer than SMS. The third is a physical security key or a passkey, which hold up best against phishing sites.

## Why does it matter?

Many account takeovers start with a stolen or guessed password. Your domain, hosting, code repository, email and site admin accounts should all have 2FA on. We review these accounts with you as part of [maintenance and support](/en/services/maintenance-and-support).

## Frequently asked questions

### Is SMS two-factor authentication good enough?

It is far better than nothing, but it can be bypassed with tricks such as SIM swapping. Use an authenticator app or a security key where you can.

### What if I lose my phone?

Keep the backup codes you get when you turn on 2FA somewhere safe. They let you sign in and register a new phone. Without them, account recovery can take a long time.

### Which accounts should have 2FA?

Start with your domain, hosting, email, code repository and bank accounts. Then your site admin panel and social media. If one of these falls, the others are at risk too.
