> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up 2FA

> Let Pomerado finish a website's two-step sign-in with an authenticator key, recovery codes or a Pomerado phone number.

This page shows how to let Pomerado finish a website's two-step sign-in on its own. Without these, a job that reaches a code step pauses and asks you for the code.

## Save an authenticator key

If the website uses an authenticator app, save its setup key (the text behind its QR code) as the login's **Authenticator app key**. Pomerado then computes the current code at each sign-in.

To see the code yourself, open the login's **Current authenticator code** link. It works only on the Dashboard, with the same checks as [revealing a login](/guides/logins/save-and-manage#reveal-a-login).

## Save recovery codes

Add the website's recovery codes (up to 20) from the login's **Recovery codes** link, or send `PUT /v1/logins/{id}/recovery-codes`. Then set **Preferred two-step method** to **Recovery code**, so sign-ins use them.

Pomerado uses one code per sign-in, marks it used and tells you how many are left, with a warning at 2 or fewer. It never shows a saved code again.

## Get a Pomerado phone number

On a Business account, anyone with Edit on a login can give it a Pomerado phone number. Pomerado reads the website's text-message codes there and fills them in without asking you.

<Steps>
  <Step title="Get a number">
    Open the login's **Text-message codes** link and select **Get a Pomerado number**.
  </Step>

  <Step title="Add it on the website">
    In your account on the website, set that number as the phone that gets sign-in codes.
  </Step>

  <Step title="Check that texts arrive">
    Select **Check that texts arrive**. For 10 minutes, the page shows the code in any text the number gets. Send it a test text, or have the website send its code.
  </Step>
</Steps>

The API has the same operations under `/v1/logins/{id}/sms-number`.

To remove a number, first remove it from your account on the website, then select **Remove this number**. It can go to someone else after 45 days.

## Answer a code yourself

When a login holds none of these, the job asks for the code as a question on its answer page; see [answer questions](/guides/jobs/answer-questions).

<Accordion title="Details">
  * **Preferred two-step method** picks the method when a website offers several: text message, call, email, authenticator, push or recovery code. It starts as "Ask each time".
  * A run can also choose recovery codes for one sign-in. Pomerado never falls back to them on its own.
  * With every recovery code used, Pomerado asks you for one.
  * The Pomerado number works only where Pomerado fills in the sign-in form itself.
  * A login without a password can't hold an authenticator key.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.