> ## Documentation Index
> Fetch the complete documentation index at: https://help.the-meridian.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# 2FA

Two-factor authentication (2FA) adds a second factor on top of your password. Meridian supports two, and either one satisfies the requirement:

* **Authenticator app (TOTP)**: a time-based code from an app like 1Password, Authy, or Google Authenticator.
* **Passkey (WebAuthn)**: a device passkey (Touch ID, Windows Hello, a hardware key). A passkey is itself phishing-resistant, so registering one counts as a second factor on its own. See [Passkey](/passkey).

## Set up an authenticator app

From your account security settings, choose to set up 2FA. Meridian shows a QR code and a secret; scan it with your authenticator app and enter the generated code to confirm. Once confirmed, the app prompts for a code after each password sign-in.

You can disable 2FA from the same screen, unless your organization requires it and you have no passkey registered, in which case Meridian keeps at least one factor in place.

## Wrong codes lock the account

A code is only asked for after your password was accepted, so wrong codes mean someone may have your password.

* Each sign-in allows **5** wrong codes, then you have to enter your password again.
* Every wrong code is recorded in your [login history](/login-history) as **Failed: wrong 2FA code**, and counts toward the failed-guess signal of [suspicious sign-ins](/suspicious-login).
* **10** wrong codes within **15 minutes**, across all sign-ins, lock the account. Meridian emails you straight away. The next sign-in needs your approval from that email, the same way a [suspicious sign-in](/suspicious-login) does, and the authenticator app is still asked for after it.

If you did not enter those codes, your password is known to someone else: [reset it](/password). The reset also clears the lock.

## Confirming it's you

Setting up 2FA and disabling it both ask you to confirm it's you first, unless you signed in within the last 10 minutes. Enter your current password, or a code from your authenticator app. If you signed up with [social login](/introduction-5), never set a password and have no authenticator app yet, Meridian asks you to sign in again instead. After five wrong attempts it stops accepting new ones for a few minutes.

## Organization enforcement

An organization owner can require 2FA for every member from **Organization settings → Security**. When enforcement is turned on:

* Members who already have an authenticator app or a passkey are unaffected.
* Members who satisfy neither can still sign in, but every other action is blocked by a mandatory setup screen until they add a factor, with no re-invitation needed.
* The requirement also triggers mid-session: if you switch into an enforcing organization, or the owner turns enforcement on while you're signed in, the setup screen appears immediately.
* It applies to everything about that organization, not only while it is your active one. If you belong to two organizations and only one enforces 2FA, opening the enforcing organization's pages from a link, an email or a bookmark shows the setup screen for it, even while the other organization is active. Its apps are left out of your apps list, [MCP](/mcp-server) calls about it are refused, and assistant conversations started in it stay closed until you add a factor.

The setup screen offers both options (set up an authenticator app or register a passkey) plus sign-out. Once you've added either, the rest of the platform unlocks.

Because a passkey satisfies the requirement, Meridian won't let you remove your last remaining factor while your organization enforces 2FA.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.