Two-factor authentication

Agent-Q supports TOTP (time-based one-time passwords) compatible with any authenticator app — Authy, 1Password, Google Authenticator, Bitwarden, Ente Auth. Enabling 2FA requires a second code from your app on every sign-in.

Enabling 2FA

  1. Open /settings/account → Two-factor authentication.
  2. Click Enable two-factor and confirm your current password.
  3. A QR code appears. Scan it with your authenticator app. (If you can't scan, copy the otpauth:// URI shown below the QR and paste it into the app manually.)
  4. Save the 10 backup codes. Each works once. Put them somewhere you can find if you lose your phone.
  5. Enter the 6-digit code from your app to verify. Done — 2FA is on.

Signing in with 2FA

Enter email + password as usual, then you'll be redirected to a 6-digit code prompt. If you've lost your authenticator, click Use a backup code to enter one of the codes you saved.

Disabling 2FA

Same place you enabled it: /settings/account → Disable two-factor → confirm password. The TOTP secret and remaining backup codes are destroyed.

Why we recommend it for admins

Admin accounts can promote other admins, grant credits, edit campaigns, and view PII. A compromised admin password is a platform compromise. The minute of setup friction is worth it.

Privacy note

The QR code is rendered locally in your browser. The secret never traverses a third-party QR-rendering service.