# 2FA (Two-Factor Authentication) (/en/docs/pix-processamento/two-factor)

<QuickLinks>
  <QuickLink href="/docs/pix-processamento/authentication" title="Authentication" />

  <QuickLink href="/docs/pix-processamento/best-practices/security" title="Security" />
</QuickLinks>

**Two-Factor Authentication (2FA)** is required to create API tokens
and process Pix payments through the dashboard. This layer protects your
account and your money. Use any TOTP authenticator app (Time-based
One-Time Password), such as Google Authenticator, Microsoft Authenticator,
1Password, Authy or any other compatible app.

## Enable 2FA [#enable-2fa]

In the dashboard, open **Profile**, go to **Manage tokens** and start the
2FA setup. Scan the QR code with your authenticator app or add the account
manually with the secret code, enter the 6-digit code and confirm. After
that you can create API tokens.

<Callout>
  Step-by-step with screenshots in the [Help Center](https://suporte.payzu.com.br/portal/pt-br/kb/articles/como-habilitar-a-autenticacao-em-dois-fatores-2fa-da-sua-conta) (in Portuguese).
</Callout>

### Manual entry (if you can't scan the QR) [#manual-entry-if-you-cant-scan-the-qr]

1. Install a TOTP app and tap &#x2A;*+** to add an account.
2. Choose **Enter a setup key**.
3. Paste the **secret code** shown in the 2FA modal exactly as it is.
4. Give the account a name (for example, **PayZu**).
5. Use the generated **6-digit code** to confirm and activate.

<Callout type="warn">
  Keep your 2FA setup and recovery information in a safe place.
  You will need it if you change or lose your phone.
</Callout>

## Tips [#tips]

* If the code shows as **invalid**, check that your **phone's time** is
  set to automatic synchronization and try again.
* If you change devices, you will need to **reconfigure** 2FA.