2FA methods supported by GitHub
Adding two-factor authentication is one of the most effective ways to protect your GitHub account. With TOTP support, you can generate GitHub verification codes directly in the Authenticator App.
SMS
GitHub can send a one-time verification code to your phone via text message.
Authenticator app (TOTP)
GitHub lets you use time-based one-time passwords, so you can generate verification codes in an authenticator app on your device — no network or SMS needed.
Proprietary app
GitHub offers its own companion app for approving sign-ins.
Security key (U2F)
GitHub works with hardware security keys using the U2F/FIDO standard.
Hardware tokens must have a backup method, either SMS or software token.
GitHub 2FA — Frequently asked questions
Does GitHub support an authenticator app?
Yes. GitHub supports time-based one-time passwords (TOTP), so you can add it to the Authenticator App and generate verification codes right on your device.
Which two-factor authentication methods does GitHub support?
GitHub currently supports: SMS, Authenticator app (TOTP), Proprietary app, Security key (U2F).
Is it free to generate GitHub codes with the Authenticator App?
Yes. The Authenticator App is free to download, and generating GitHub verification codes does not require an account or sign-up.
This page is for educational purposes only. We are not affiliated with or endorsed by GitHub. All trademarks and product names are the property of their respective owners and are used solely for identification.