> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# Two-factor authentication

> Add a second factor to your Unkey sign-in from Account settings.

Two-factor authentication (2FA) adds a second factor to your sign-in. It belongs to your user account but is scoped to your workspace, so enrolling one workspace will not enroll it for any others you may have.

Manage it on your **Account settings** page, which is in the user menu in the top navigation.

## Enroll

The **Security** section of Account settings holds the enrollment controls, alongside a **Profile** section for your name and email. The methods offered and the enrollment steps come from WorkOS, the identity provider behind Unkey sign-in, so they can change without an Unkey release.

<Frame>
  <img src="https://mintcdn.com/unkey/TjbnJStfcJRkiuek/images/dashboard/platform--workspace-two-factor-auth--account-settings.png?fit=max&auto=format&n=TjbnJStfcJRkiuek&q=85&s=4b25649bc5d05c729fd2c28ddaddfaef" alt="Account settings page with the Profile section and, under Security, the Multi-factor authentication row with a Set up authenticator app button" width="2560" height="1600" data-path="images/dashboard/platform--workspace-two-factor-auth--account-settings.png" />
</Frame>

You can enroll whether or not your organization requires MFA.

## If you lose your device

Remove the old factor and enroll the new one from Account settings while you still have access. If you've already lost the device and can't sign in, email [support@unkey.com](mailto:support@unkey.com) from the address on your account.
