Skip to content

Account

Two-factor authentication (2FA)

Secure your xCloudPhone account with a 6-digit code from an Authenticator app. How to enable, disable and recover 2FA, plus what Google accounts should do.

3 min read

Two-factor authentication (2FA) adds a verification step after you enter your password: you must type a 6-digit code from an app on your phone. Even if someone learns your password, they can't get into your account without this code.

2FA is only for accounts with a password. If you sign in with Google, your account has no xCloudPhone password, so "Two-Factor Authentication" doesn't appear under Profile → Security. 2FA is a layer that sits behind a password, and with no password there's nothing for it to guard.

Secure your Google account instead: turn on 2-Step Verification in Google's own security settings. That layer is what protects your xCloudPhone access.

Why should I enable 2FA?

  • Protects your account if your password leaks.
  • Greater peace of mind when logging in from a new device or public network.
  • Safeguards your balance, orders, and personal data.

You should enable 2FA if your account holds a large balance or stores sensitive information.

Which Authenticator apps work?

  • Google Authenticator (Android/iOS)
  • Authy
  • Microsoft Authenticator
  • Any TOTP-compliant app

How to enable 2FA

Log in and go to Profile → Security.

Click Enable 2FA.

Open the Authenticator app on your phone and scan the QR code on screen.

The app generates a 6-digit code that changes every 30 seconds. Enter it into the confirmation field on xCloudPhone.

Click Confirm to finish.

No Enable 2FA button in the Security tab? Your account signs in with Google. That's expected behaviour, not a bug.

Logging in with 2FA enabled

Enter username and password as usual.

You're redirected to the 2FA entry page. Open the Authenticator app and read the current 6-digit code.

Enter the code. The form auto-submits as soon as you fill all 6 digits.

You have 5 minutes to enter the code after being redirected. If the countdown expires, you must log in again from the start.

Disable 2FA

Go to Profile → Security.

Click Disable 2FA.

Enter your current password to confirm. 2FA is turned off immediately.

Check where you're logged in

The same Profile → Security tab has a "Where You're Logged In" section listing every open session on your account. Give it a look whenever you suspect someone else got in, or after you've signed in on a borrowed machine.

If you spot a session that isn't yours, change your password immediately, then enable 2FA.

Lost phone or no access to Authenticator?

Contact support. Recovery requires identity verification.

Most Authenticator apps can back your codes up to a cloud account. Switch that on when you install the app so a new phone never locks you out.

Common issues

The code is rejected even though I just read it

TOTP codes are derived from the clock. If your phone's time drifts even half a minute from real time, the codes it generates won't match. Open your phone's date and time settings and switch it back to automatic network time.

I can't find Two-Factor Authentication

Your account signs in with Google, so it has no password and this section stays hidden. Turn on 2-Step Verification inside your Google account instead.

The 5 minutes ran out before I entered the code

Log in again from the start. Open your Authenticator app before you click Log in, so you're not hunting for it while the countdown runs.