How to Enable 2FA on X (Twitter)
Since March 2023, X only offers SMS-based 2FA to Premium subscribers — but authenticator-app 2FA is free for everyone, and it's the more secure option anyway. Setup takes about two minutes.
Quick path: Settings → Security and account access → Security → Two-factor authentication → Authentication app
Step-by-step: 2FA setup on X (Twitter)
- 1
Open Security settings
On x.com (or in the app), go to 'Settings and privacy' → 'Security and account access' → 'Security'.
- 2
Open Two-factor authentication
Click 'Two-factor authentication'. You'll see three methods: Text message (Premium only), Authentication app, and Security key.
- 3
Check 'Authentication app'
Tick 'Authentication app'. X asks for your password, then shows a QR code.
- 4
Scan the QR code with 2FAA
Open 2FAA's authenticator, scan the QR code (or use 'Can't scan the QR code?' to get the setup key). A 6-digit X code starts rotating in 2FAA.
- 5
Verify and save the backup code
Enter the current code from 2FAA to confirm. X then displays a single-use backup code — save it somewhere offline. You can regenerate it later under 'Backup codes'.
Generate X (Twitter) 2FA codes with 2FAA
You don't need a separate authenticator app. 2FAA is a free, browser-based TOTP generator — your secret never leaves your device, and it works offline as a PWA. The same secret can be used in parallel with Google Authenticator or Authy if you prefer redundancy.
Frequently asked questions
Is 2FA on X really free? I thought it required Premium.
Only SMS 2FA is restricted to Premium subscribers. The authenticator-app method (TOTP) and hardware security keys are free for every account — and both are more secure than SMS.
Can I use 2FAA instead of Google Authenticator for X?
Yes. X's 'Authentication app' option is standard TOTP — 2FAA, Google Authenticator, and Authy all generate identical codes from the same QR code.
How many backup codes does X give me?
One at a time. After setup, X shows a single backup code; you can generate a replacement anytime under Two-factor authentication → 'Backup codes'. Store it offline — it's your only recovery path besides the authenticator.
I lost my authenticator and backup code — can I recover my X account?
You'll need to go through X's support form with proof of account ownership (email/phone access helps). Recovery is slow and not guaranteed — keep the backup code stored safely from day one.