---
title: "Two-Factor Authentication"
description: "Enroll an authenticator, store recovery codes, and complete login verification safely."
---

> Documentation Index
> Fetch the complete documentation index at: https://kb.kglo.beauty/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-Factor Authentication

## Initial enrollment

1. Open **2FA Setup**. Scan its QR code in an authenticator app, or copy the manual key and enter it there.
2. Enter a current TOTP code and confirm your password, then select **Enable 2FA**.
3. Store the ten recovery codes shown after enrollment. **Copy all** copies them to the clipboard; leaving the page hides the displayed codes.

## Recovery codes

Recovery codes appear once after they are created or regenerated. Each code works only once. Store them before leaving the page, and never send them through chat, unencrypted email, or a support ticket.

## While 2FA is enabled

From **2FA Setup**, enter your password to regenerate recovery codes. The new set replaces the old set. To turn 2FA off, enter your password and select **Disable 2FA**.

## Login verification

Use a TOTP for normal login. Use a recovery code only when the authenticator is unavailable. After using a recovery code, review the 2FA method and regenerate codes when needed.

## Lost access

Do not create a shared account or borrow another user's session. Follow the identity recovery procedure and escalate internally to an authorized administrator.

> QR codes, manual keys, and recovery codes are secrets. Use dummy values in knowledgebase screenshots.

Source: https://kb.kglo.beauty/en/security/two-factor-authentication/index.mdx
