> ## Documentation Index
> Fetch the complete documentation index at: https://bigbrainape.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable Two-Factor Authentication for Big Brain Ape

> Secure your Big Brain Ape account with TOTP-based two-factor authentication using Google Authenticator, Authy, or any compatible authenticator app.

A password alone is no longer enough to protect a trading account. Two-factor authentication (2FA) requires you to provide a second proof of identity — a time-based one-time passcode (TOTP) generated on your device — every time you log in. Even if someone obtains your password, they cannot access your account without also having your authenticator app. Enabling 2FA is the single most impactful step you can take to secure your Big Brain Ape account.

## Supported authenticator apps

Big Brain Ape works with any TOTP-compatible authenticator app. The following are recommended:

* **Google Authenticator** — lightweight, available on iOS and Android
* **Authy** — supports encrypted cloud backup of tokens across multiple devices
* **1Password** — integrates TOTP directly into your password manager
* **Microsoft Authenticator** — solid choice for users already in the Microsoft ecosystem

Install your preferred app on your phone before you begin the setup process.

## Enabling 2FA

<Steps>
  <Step title="Open Security settings">
    Log in to Big Brain Ape, click your avatar in the top-right corner, and navigate to **Settings → Security**.
  </Step>

  <Step title="Start the 2FA setup">
    Click **Enable Two-Factor Authentication**. Big Brain Ape will generate a unique QR code tied to your account.
  </Step>

  <Step title="Scan the QR code">
    Open your authenticator app, tap the option to add a new account, and scan the QR code displayed on screen. If your app doesn't support QR scanning, tap **Show manual key** and enter the code by hand.
  </Step>

  <Step title="Enter the confirmation code">
    Your authenticator app will display a 6-digit code that refreshes every 30 seconds. Enter the current code in the confirmation field on Big Brain Ape and click **Verify**.
  </Step>

  <Step title="Save your backup codes">
    Big Brain Ape will show you eight single-use backup codes. Copy them and store them somewhere secure and offline — for example, in a printed document kept in a safe place or in an encrypted password manager vault. Click **Done** only after you have saved all eight codes.
  </Step>
</Steps>

Once 2FA is enabled, every subsequent login will require both your password and a fresh code from your authenticator app.

## Backup codes

When you enable 2FA, Big Brain Ape gives you **eight single-use backup codes**. Each code can only be used once and acts as a stand-in for your authenticator app when you don't have access to your device. After a backup code is used, it is invalidated immediately.

If you use all eight codes or simply want a fresh set, go to **Settings → Security → Regenerate Backup Codes**. Regenerating a new set invalidates all previous codes, so update your records immediately.

<Warning>
  Store your backup codes offline and in a location separate from your phone. If you lose access to your authenticator device **and** you don't have your backup codes, you will be locked out of your account permanently. Big Brain Ape support cannot bypass 2FA on your behalf.
</Warning>

## Signing in with 2FA

Once 2FA is active, the login flow has two steps:

1. Enter your email address and password as usual and click **Sign In**.
2. Open your authenticator app, read the current 6-digit code for Big Brain Ape, enter it in the verification field, and click **Confirm**.

The code refreshes every 30 seconds. If you enter a code and receive an error, wait for the next code to appear and try again — clock drift between your device and the server is the most common cause.

If you don't have your authenticator device available, click **Use a backup code** on the verification screen and enter one of your saved single-use codes instead.

## Disabling 2FA

<Warning>
  Disabling 2FA significantly reduces your account security. Only turn it off if you are switching authenticator apps, and re-enable it immediately on your new device.
</Warning>

To disable 2FA:

1. Go to **Settings → Security**.
2. Click **Disable Two-Factor Authentication**.
3. Enter your current TOTP code (or a backup code) to confirm the change.

2FA will be removed from your account immediately. You can re-enable it at any time by following the setup steps above.

<Note>
  Two-factor authentication is **required** to create or delete API keys. You cannot manage API keys on your account until 2FA is enabled.
</Note>
