Help topics

Two-factor authentication (2FA)

Add a second step to sign-in with a passkey or an authenticator app — how to turn it on, what to expect at login, and how to turn it off.

EveryoneUpdated August 14, 2026

Two-factor authentication (2FA) adds a second step when you sign in: after your password (or social login), you confirm it's really you. Even if someone learns your password, they can't get in without your device. Manage it under Profile → Security.

The security settings screen, where passkeys and an authenticator app are added to an account.
Security settings. Both a passkey and an authenticator app are added from here.

Two ways to confirm

  • A passkey — unlock with Face ID, Touch ID, a fingerprint, or Windows Hello. Nothing to type, and nothing to copy from another device. A passkey is tied to the device you created it on, so add one on each device you use.
  • An authenticator app — a 6-digit code that changes every 30 seconds, from e.g. Google Authenticator, Microsoft Authenticator, Authy, or a password manager like 1Password or Bitwarden. Waypoint Realms uses standard TOTP, so any of them work.

You can use both, and we recommend it: passkeys are the quick everyday route, and an authenticator app is what gets you back in if you lose a device.

Add a passkey

  1. Go to Profile → Security and, under Passkeys, choose Add a passkey.
  2. Your device asks you to confirm with Face ID, a fingerprint, or your device PIN. That's the whole setup.
  3. The passkey appears in the list, named after the device and browser you added it from, so you can tell them apart later.

One passkey per device

A passkey can't leave the device that created it. Signing in on a new laptop or phone means either adding a passkey there too, or using your authenticator code that first time.

Turn on an authenticator app

  1. Go to Profile → Security and, under Authenticator app, choose Set up authenticator app.
  2. Your authenticator app: add a new account by scanning the QR codeshown, or by typing the setup key underneath it if you can't scan.
  3. The app now shows a 6-digit code that changes every 30 seconds. Type the current code into Verify & enable.
  4. That's it — 2FA is on. From now on you'll confirm a second step each time you sign in.

Enter the current code

TOTP codes expire every 30 seconds. If verification fails, wait for the app to show a fresh code and try again — and make sure your phone's clock is set automatically.

Signing in with 2FA on

Sign in with your email and password (or a social login) as usual. If you have a passkey on that device, Waypoint Realms offers it first — one tap and you're in. Otherwise it asks for your 6-digit code. Either way you can pick the other method with the link underneath. You can't reach the rest of the app until you complete this step — it applies on every device and browser, every time you sign in.

Turn off 2FA

On Profile → Security, remove each passkey with Remove, and the authenticator app with Turn off. You'll need to be signed in (which means you've already passed 2FA), so keep it on unless you have a reason to remove it.

Keep a way back in

Waypoint Realms doesn't issue backup/recovery codes yet, and a passkey only works on the device that made it — so passkeys alone can lock you out if that device is lost or wiped. Keep an authenticator app set up as well, ideally one that syncs across devices (Authy, 1Password, etc.), and add it before switching phones. If you do get locked out, contact support from the Help center.

Good to know

  • 2FA protects sign-in. It doesn't change how your profile privacy or messaging work — see Privacy controls for those.
  • Only you can enable or remove 2FA on your account, and only from a signed-in session.
  • You can attach one authenticator app and as many passkeys as you have devices. Backup codes are a planned addition.
  • Passkeys need a reasonably current browser and a secure connection. If your browser can't use them, the Passkeys section says so and you can use codes instead.

Still stuck? Browse all help or contact us. To report someone or something, use the report action on the relevant profile, post, or session — it sends us the context automatically.