How to enable 2FA for your GitHub account
Updated August 4, 2026
Two-factor authentication (2FA) protects your GitHub account even if your password leaks. Follow the steps below to generate GitHub verification codes with the Authenticator App on your iPhone, iPad or Mac.
Open your Settings
While signed in to github.com, click your profile photo in the upper-right corner of any page and choose Settings from the drop-down menu.

Enable two-factor authentication
In the left sidebar under Access, open Password and authentication. Scroll to the Two-factor authentication section and click Enable two-factor authentication.

Choose to set up using an app
Select Set up using an app as your authentication method, then click Continue to move on to the QR code.

View the QR code on GitHub
GitHub now shows a QR code that encodes your secret key on the Set up authenticator app screen. Leave this page open on your computer while you reach for your iPhone. If you can't scan it, click setup key to reveal the code for manual entry.

Scan the QR code with your Authenticator App
Open the Authenticator App on your iPhone and tap the + button. Hold your phone up to the screen to scan the QR code shown by GitHub.

Save the GitHub entry in your app
After the scan, the Authenticator App automatically picks the GitHub logo and fills in the account name and secret key. Tap Save to add the entry to your app.

Enter the 6-digit verification code
Your Authenticator App now generates a six-digit code that refreshes every few seconds. Type the current code into the field on GitHub and click Continue.

Save your recovery codes
GitHub displays a list of recovery codes that let you back into your account if you lose your phone. Click Download to store them somewhere safe, then click I have saved my recovery codes.

You're done
Two-factor authentication is now active on your GitHub account, so you'll enter a code from your Authenticator App when signing in. GitHub recommends testing it by signing out and back in.

Backup & recovery
GitHub displays a list of recovery codes that let you back into your account if you lose your phone. Click Download to store them somewhere safe, then click I have saved my recovery codes.
That's it — your GitHub account is now protected with two-factor authentication. Keep your recovery information safe and follow the service's official documentation if its interface changes.

