Two-Factor Authentication
Add a second step to sign-in so a stolen password is not enough to reach your servers, domains, and secrets on its own.
Two-factor authentication (2FA) asks for a six-digit code from an authenticator app after your password. Your Cosmoner account controls servers, DNS, and secrets, so a password that leaks — reused on another site, phished, or pulled from a breach dump — is otherwise all someone needs.
A passkey — Touch ID, Face ID, Windows Hello, or a security key — covers the same ground in a single prompt and cannot be phished, since there is no code to read out and no password to type. If your devices support one, start there. The two work side by side, and having both is the belt-and-braces option.
Turn it on
Go to Account → Security and choose Set up.
- Confirm your password. This stops someone at an unlocked laptop from adding a factor only they hold.
- Scan the QR code with any TOTP app — 1Password, Bitwarden, Google Authenticator, Authy. If you are enrolling a password manager on the same screen, use the enter this key manually option instead.
- Enter the six-digit code the app shows.
2FA switches on only after that code is accepted, so a mis-scanned QR cannot lock you out — an abandoned setup leaves your account exactly as it was.
Save your recovery codes
Setup ends with ten single-use recovery codes. They are shown once: we store them encrypted and have no way to read them back to you.
Save them somewhere other than the phone or laptop running your authenticator app. If you lose that device, these codes are the only way back into the account. Each one works a single time, and using one does not disable 2FA.
Lost them, or used most of them? Account → Security → New recovery codes issues a fresh set and immediately invalidates the old one.
Signing in
After your password you are asked for a code. If you cannot reach your authenticator app, choose Use a recovery code instead and enter one of the codes you saved.
Too many wrong codes in a row temporarily locks the second-factor step on the account. Wait a few minutes and try again — it clears on its own, and on the first code that is accepted.
Trusted devices
Ticking Trust this device for 30 days at the code prompt skips the code on that browser until the 30 days are up. It is per browser and per device, so your laptop being trusted says nothing about your phone.
Two things are worth knowing:
- Signing out does not untrust a device. The trust outlives the session by design.
- Revoking is the lever. Account → Security → Trusted devices → Revoke all makes every device — including the one you are on — ask for a code again. Do this whenever a device is lost, sold, or out of your hands.
Turning it off
Account → Security → Turn off, confirmed with your password. Your recovery codes are discarded and your password alone gets you in again. Turning 2FA back on later starts a fresh setup with a new QR code and new recovery codes.
Sign-in methods
Account → Security → Sign-in methods lists every way into your account: a password, a connected GitHub identity, or both. Connecting GitHub is what makes a mismatched email harmless — the identity is joined to the account you are already signed in to, so a work address here and a personal one on GitHub still resolve to one account.
You cannot disconnect your only remaining method. If GitHub is all you have, set a password first via the password reset link.
GitHub sign-in and 2FA
The code prompt applies to email-and-password sign-in. Continue with GitHub is governed by the second factor on your GitHub account instead, so if both are enabled on your Cosmoner account, turn 2FA on at GitHub too — otherwise whoever controls the linked GitHub account walks around the code prompt. The security page shows a warning when this applies to you.