X two-factor authentication: how to turn it on
X put SMS 2FA behind Premium, so the free route is an authenticator app. Here is how to enable it, plus the backup code and temporary password people lose.
On this page · 11 sections
The short version
- ▸The path is Settings and privacy, Security and account access, Security, Two-factor authentication. Three methods are offered: authentication app, security key, and text message.
- ▸Text message 2FA is subscriber-only. X announced in February 2023 that enrolment in SMS 2FA was limited to paying subscribers and gave non-subscribers 30 days to move to another method, so the free and stronger route is an authenticator app.
- ▸Save the backup code offline when you enable 2FA. It is generated automatically when you turn 2FA on in the mobile app and can also be generated on x.com, and it is what gets you back in when the phone is gone.
- ▸Backup codes and temporary passwords are not the same thing. Backup codes sign you in to X clients; third-party applications need a temporary password, which expires after one hour.
- ▸2FA protects logins, not live sessions or connected apps. Pair it with logging out of other sessions, revoking unknown app access, and password reset protect.
Quick answer
Turn on X two-factor authentication under Settings and privacy, Security and account access, Security, Two-factor authentication. Three methods exist: an authentication app, a security key, and text message. Text message is the one non-subscribers cannot enrol in, so for most accounts the answer is an authenticator app, which is also the more secure choice because a SIM swap cannot defeat it. Save the backup code offline before you close the screen.
Last updated: September 2026
The three methods, and which one costs money
X offers the same three options it has for years, but the pricing around them changed and most guides still describe the old world.
| Method | Cost | Strength | Catch |
|---|---|---|---|
| Authentication app | Free | Strong. Codes are generated on your device, so there is nothing to intercept | Lose the phone without a backup code and recovery gets hard |
| Security key | Free to enable, you buy the hardware | Strongest available | Needs the physical key present at sign-in |
| Text message | Subscriber-only enrolment | Weakest of the three | Defeated by a SIM swap, and availability varies by country and carrier |
The text message restriction is the detail worth getting right. X announced in February 2023 that enrolment in SMS-based two-factor was being limited to paying subscribers, and accounts already using it that did not subscribe were given a window of 30 days to disable it and move to another method. Authentication apps and security keys stayed free for everyone.
It reads like a paywall on security, and it was reported that way at the time. The practical effect for you is closer to the opposite: it pushed the free tier off the method that SIM-swap attacks target and onto ones they cannot touch. If you are weighing the subscription for other reasons, we break the tiers down in X Premium benefits, tiers and price. Do not buy it for SMS 2FA. The free option is better.
How to turn on two-factor authentication on X
The route is identical on web and mobile, and it is not where people expect to find it. It sits under account security rather than under privacy.
- Open Settings and privacy. On mobile, tap your profile picture first. On the web, click More in the left sidebar, then Settings and Support.
- Select Security and account access.
- Select Security.
- Select Two-factor authentication.
- Tick the method you want. X will ask you to confirm your password before it lets you continue.
Authentication app, the free default
Choose Authentication app and X shows a QR code. Open your authenticator, add a new account, scan the code, and type the six-digit number back into X. A trusted third-party authenticator such as 1Password, Authy, Google Authenticator, Microsoft Authenticator or Duo Mobile will do the job, and codes rotate roughly every 30 seconds.
Two things to do immediately after, while the screen is still open:
- Save the backup code. X generates one automatically when you turn 2FA on through the iOS or Android app, and you can generate one on x.com as well. Write it down or put it in an encrypted password manager. Not in the notes app on the same phone that holds the authenticator.
- Add the authenticator to a second device or its cloud backup if your app supports it. The common failure is not a hacker. It is a broken phone.
Security key
If you own a hardware key, add it here. This is the configuration X treats as strongest, to the point that it says adding a security key means another backup method is no longer required, so the key can stand alone. Convenient if you sign in from one or two machines. Painful if you sign in from everywhere.
Text message
Available if you subscribe, and dependent on your country and carrier. If you already have it enabled from years ago, moving to an authenticator app is a straight upgrade rather than a sideways step.
Backup codes and temporary passwords are not the same thing
This is the part that sends people to a search engine at the worst possible moment, and almost no page covering X 2FA separates the two clearly.
A backup code signs you in to X. X's verification help documents that your backup codes work when logging in to x.com, mobile.x.com, X for iOS or Android, or another X client. It is the emergency route into your own account.
A temporary password signs you in to something else. If you are trying to access a third-party application connected to your X account, X's own guidance is that you need a temporary password rather than a backup code, and that temporary passwords expire after one hour.
So when a scheduler, an analytics dashboard or any outside tool rejects your login after you enable 2FA, you have not broken anything. You reached for the wrong credential. Generate a temporary password, use it inside the hour, and expect to repeat that if the tool asks again later.
Worth knowing if you are wiring anything up programmatically: the sanctioned route for automation is the official API with its own credentials, not a password of any kind. What that now costs is covered in how to get an X API key.
If you lose the phone
Work in this order, because each step depends on the one before it.
Try the backup code first. It exists for exactly this. Enter it in place of the 2FA code at sign-in.
If there is no backup code, secure the email account. Every recovery path X offers ends at the address on the account, so if that mailbox is not solidly yours, nothing downstream works. Change its password and enable 2FA there.
Then work the account access flow. X's troubleshooting for login verification covers the cases where the second factor is unavailable, and how far you get depends on whether you still control the email address and phone number on file.
Once you are back in, reset the second factor. Remove the old authenticator entry, add the new device, generate a fresh backup code. If the reason you lost access was not a broken phone, what to do when an X account is hacked walks the recovery sequence in order, and it is a different order than most people guess.
What 2FA does not protect
Turning this on is worth ten minutes of your evening. It is not a force field, and treating it as one is how secured accounts still get taken.
It does not end existing sessions. Someone already signed in stays signed in. On the same Security screen you will find the list of sessions and devices, and logging out of all other sessions is the step that actually ejects them. The layout of that screen is covered in the X login guide.
It does not revoke connected apps. An app you authorised in 2021 holds a token that does not care about your new authenticator. Audit Connected accounts periodically and revoke anything you do not recognise or no longer use.
It does not stop phishing on its own. A convincing fake login page will ask for the 2FA code too, and a code handed over is a code used. A security key is the method that resists this, because it will not authenticate against the wrong domain.
It does not cover the phone number and email. Those are the recovery rails. Turn on password reset protect, on the same Security screen, so a reset needs more than your handle, and put a PIN on your mobile carrier account.
If you are setting up an account from scratch, doing this on day one costs nothing and saves a bad week later. The full first-run checklist is in how to create an X account.
The short version
Go to Security and account access, Security, Two-factor authentication. Pick the authentication app unless you own a hardware key. Save the backup code somewhere that is not the phone you just scanned the QR code with. Remember that third-party tools want a temporary password, not that backup code. Then spend the extra two minutes logging out of other sessions, revoking stale connected apps, and switching on password reset protect, because the login is only one of the doors.
For anyone running an account seriously enough that losing it would hurt, that two-minute audit is the highest-return security work available on this platform. Tools that ask for your password instead of an official authorisation flow deserve suspicion; if you want automation, prefer something that runs in your own browser session on your own machine over a service that stores your credentials on a shared server. That is the model X-Autopilot uses, and it lowers the detection surface compared with cloud tools without eliminating account risk. Browser-based engagement is a gray area rather than a sanctioned API path, so read X's Automation rules before you lean on it.
Internal links
Frequently asked
Answers indexed by Google + AI assistants.
How do I turn on two-factor authentication on X?+
Go to Settings and privacy, then Security and account access, then Security, then Two-factor authentication. Pick a method, confirm your password, and follow the prompts. On mobile the authenticator route asks you to scan a QR code with an app such as 1Password, Authy, Google Authenticator, Microsoft Authenticator or Duo Mobile, then enter the six-digit code it generates.
Is SMS two-factor authentication free on X?+
No. X restricted enrolment in text message 2FA to paying subscribers, announced in February 2023, with non-subscribers given 30 days to switch to another method. Authentication apps and security keys remain free for everyone, and availability of the text message method can also vary by country and carrier.
What is the difference between a backup code and a temporary password on X?+
A backup code gets you into X itself when you cannot produce a 2FA code, and it works when signing in to x.com, mobile.x.com, the iOS or Android app, or another X client. A temporary password is different: it is what you use to sign in to a third-party application connected to your account, and it expires after one hour. Using the wrong one is the most common reason a 2FA login fails on an outside tool.
What happens if I lose the phone with my authenticator app?+
Your backup code is the way back in, which is why it is worth saving offline the moment you enable 2FA. Without a code and without the device, you are into X's account access troubleshooting flow, and recovery depends on still controlling the email address and phone number on the account. Secure the email first, since every reset path runs through it.
Do I need a second method if I use a security key?+
No. X states that once you add a security key, it no longer requires another backup method, so a key can be your sole two-factor method. That is the strongest configuration available, at the cost of needing the physical key present to sign in.
Does two-factor authentication stop someone who already has access to my account?+
Not on its own. Turning on 2FA secures future logins, but an attacker with a live session stays signed in, and a connected app that already holds a token keeps its access. Log out of all other sessions and revoke unknown connected apps at the same time, or you have locked the front door while a window is open.
- X Help - How to use two-factor authentication on X (three methods, subscriber-only text message enrolment, accessed 2026-09-12)
- X Help - Two-factor authentication verification help (backup codes vs one-hour temporary passwords for third-party apps, accessed 2026-09-12)
- X Blog - An update on two-factor authentication using SMS (February 2023 announcement restricting SMS 2FA to subscribers, 30-day switch window)
- X Help - What to do if your account has been compromised (session logout and connected app revocation, accessed 2026-09-12)
Product designer and indie hacker. Runs the agent on his own X account every day and writes up what the data shows, including when it's inconvenient.
Follow on X →