Two-factor authentication

Require a 6-digit code from your authenticator app at every sign-in.

← Back to profile
@if (! $user->two_factor_secret) {{-- Not yet enabled --}} Enable 2FA You'll need an authenticator app like Google Authenticator, 1Password, or Authy.
@csrf Start setup
@elseif (! $user->two_factor_confirmed_at) {{-- Setup in progress — show QR + recovery codes + confirm form --}} Finish setup Scan the QR code with your authenticator, then enter a 6-digit code to finish.
{!! $qr !!}

Or enter this code manually in your authenticator:

{{ \App\Support\TwoFactor::secret($user) }}
@csrf 6-digit code @error('code')

{{ $message }}

@enderror Confirm {{-- Sibling form (HTML doesn't allow form nesting). --}}
@csrf @method('DELETE') Cancel setup
Recovery codes Save these somewhere safe. Each code can be used once if you lose access to your authenticator.
@foreach ($codes as $c) {{ $c }} @endforeach
@else {{-- Already enabled --}}
2FA is enabled Confirmed on {{ $user->two_factor_confirmed_at->format('M j, Y g:i a') }}.
Recovery codes {{ count(\App\Support\TwoFactor::recoveryCodes($user)) }} unused codes remaining.
@foreach (\App\Support\TwoFactor::recoveryCodes($user) as $c) {{ $c }} @endforeach
Disable 2FA This will remove the secret and recovery codes. Your next sign-in won't require a code.
@csrf @method('DELETE') Disable 2FA
@endif