Skip to content

Two-factor authentication (2FA)

Two-factor authentication asks for a second proof after the password, usually a code from an app on your phone. WordPress does not include it, so a plugin adds it. A recovery code is a spare that works once, for the day the phone is not there.

By
WP Ministry
Published

In short

  • With a second step, a password alone no longer gets anyone in, however it was obtained.
  • WordPress has no setting for it. A plugin adds it, and each account has to be set up.
  • Save recovery codes when you set it up, somewhere other than the phone. They are the way back in when the phone is lost.

Two-factor authentication is a login that asks for two different kinds of proof. The first is the password. The second is most often a code from an app on your phone. Someone who has guessed or stolen the password still cannot log in without the phone.

WordPress's documentation calls it two-step authentication and lists three kinds of proof: something you know, such as a password, something you have, such as a phone, and something you are, such as a fingerprint. Two-factor means two of the three.

WordPress itself does not include it. The same documentation says it has to be added with a plugin or a single sign-on service.

Where you meet it

On a new WordPress site, nowhere. The profile screen has no section for a second step.

Once a plugin adds it, you meet it in two places. One is your profile, where you set it up. With the Two Factor plugin, which the plugin directory lists as by WordPress.org, the section is headed "Two-Factor Options". The other is the login screen, which shows a second screen after the password and asks for a code.

The second step comes in a few kinds:

  • An authenticator app. The app and the site share a secret, set up once by scanning a QR code. Each then works out the same code from that secret and the time. The standard recommends a new code every 30 seconds.
  • A code sent by email.
  • A passkey or a security key, which that plugin's listing says needs a further plugin.
  • A recovery code. This is a spare code made ahead of time, for when the usual second step is not there: a lost, broken or replaced phone. Two Factor makes ten at a time, each works once, and its screen warns that you will not be able to view them again once you leave the page. Its listing calls them backup codes.

What goes wrong

  • The phone is gone and there are no recovery codes. The password is right and you still cannot get in. Locked out of WordPress admin has the ways back for a lost second step.
  • The code is refused. A code from an app depends on the time. Two Factor's own setup screen says "Your device and server times must match." How to set up two-factor authentication covers this and the setup itself.
  • Only some administrators use it. Two Factor's listing says each user must set it up individually and that it has no built-in enforcement settings. One administrator without it is one account a guessed password still opens.
  • It does not cover programs. A script or an app has no screen to type a code into. It reaches the site with an application password, which is asked for no code.
  • It is taken for the whole answer. A second step defeats a guessed password, which is what a brute force attack is after. How to protect WordPress from brute force attacks puts it in order with the other measures.

How to look at yours

Go to Users, then Profile, and look for a section about two-factor or two-step login. If there is none, the site has no second step. With the Two Factor plugin and WP-CLI, this shows one account's state, with the username in place of admin:

bash
wp two-factor status admin

using_2fa reads true or false, and backup_codes_remaining counts the recovery codes left.

Common questions

What is a recovery code?

A spare code you generate when you set two-factor up. Each one works once, in place of the code from your phone. Keep them somewhere other than the phone, because the day you need one is the day the phone is not there.

Is two-step the same as two-factor?

In WordPress's documentation, yes. It uses "two-step authentication" and says that is also known as two-factor authentication.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.