Two-factor authentication

Protecting your account with an authenticator app.

With two-factor authentication on, signing in needs your password and a six-digit code from an authenticator app on your phone. Someone who learns your password still cannot get in.

What you need

Any TOTP authenticator app: Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, Aegis, Raivo and others all work. Annotune uses the standard six-digit, thirty-second scheme, so there is nothing app-specific about it.

Turning it on

  1. Open Settings and find Two-factor authentication.
  2. Press Set up two-factor authentication. A QR code and a setup key appear.
  3. Scan the QR code with your app, or type the setup key in by hand if you cannot scan.
  4. Enter the six-digit code your app now shows, and press Turn on.
It is not on until that code is accepted. This is deliberate: turning the feature on without proving the app can generate codes would lock you out of your own account at the next sign-in.

Signing in afterwards

Enter your email address and password as usual, then the code. A code is accepted once and cannot be reused, and there is a small allowance for clock drift so a code typed as it rolls over still works.

If you lose your phone

Open Settings, enter your account password in the Two-factor authentication section, and press Turn off. Your password is the check rather than a code, requiring the thing you have lost in order to stop needing it would leave you with no way back into your account.

Turning it off clears the secret entirely. Turning it on again gives you a new QR code, so an old screenshot of the previous one is worthless.

Google accounts

Accounts that sign in with Google do not see this section. They have no Annotune password, so there would be no way to turn the second factor off again; Google's own second factor protects them instead.