> ## Documentation Index
> Fetch the complete documentation index at: https://developer.omni.z-api.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

> Add an extra layer of protection to the Omni Z-API dashboard login

export const projectName = 'Omni Z-API';

Two-factor authentication (2FA) asks, besides email and password, for a code generated by an authenticator app (Google Authenticator, Microsoft Authenticator, Authy, etc.) to sign in to the {projectName} dashboard.

## Turn on

1. In the dashboard, open **My account**.
2. In **Security and compliance**, on the **Two-factor authentication** card, click **Enable 2FA**.
3. Scan the QR code with the authenticator app (or type the code shown below it).
4. Enter the 6-digit code shown in the app to confirm.

<Frame>
  <img src="https://mintcdn.com/omni-z-api/q9hmNrF61s-W1Xyg/images/security-two-factor.png?fit=max&auto=format&n=q9hmNrF61s-W1Xyg&q=85&s=e053946bd0a43739478f7df92d3b88de" alt="Two-factor authentication card in My account" width="1668" height="364" data-path="images/security-two-factor.png" />
</Frame>

From then on, every dashboard login asks for the app code after the password.

## Turn off

In **My account → Security and compliance**, click **Disable 2FA** and confirm.

## 2FA and the API

2FA protects **the dashboard login**. It does not change API authentication: calls keep using the Secret Key, with no verification code. To protect the API, use [IP restriction](/en/security/ip-restriction) and keep the Secret Key only in your backend.

<Warning>
  Keep access to the authenticator app. Without it, you cannot complete the dashboard login.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.