1 article with this tag
A guide to setting up two-factor authentication (2FA) on GitHub and avoiding lockout. Since March 2023, GitHub has been requiring 2FA, group by group, for users who contribute code on GitHub.com; once selected, you get a 45-day enrollment period and a 7-day grace period, after which you cannot use GitHub.com until 2FA is on. GitHub Docs recommends a TOTP authenticator app as the primary method with a passkey or security key as backup (passkeys, security keys and GitHub Mobile can only be added after TOTP or SMS is set up). This site's take: the common 2FA failure on GitHub is not account takeover but locking yourself out, and GitHub Support cannot restore an account whose 2FA credentials and recovery methods are all lost. Save the 16 recovery codes in a password manager and register a second method on the same day. While you are there, move to expiring fine-grained tokens, prune authorized apps and SSH keys, and check push protection and Dependabot alerts.