Adding a second layer of security to your account.
Two-factor authentication (2FA) means signing in needs both your password and a code from your phone. Someone with your password alone can't get in.
Why it matters here
Your account holds real cards and real money. 2FA is the difference between a leaked password being an inconvenience and it being a loss.
Setting it up
Enable 2FA in your account settings. You'll scan a QR code with an authenticator app — Google Authenticator, Authy, 1Password and others all work — then confirm with a code to prove it's working.
Save your recovery codes
You're given recovery codes at setup. Save them somewhere safe, right then.
Each code works once. They're the way back into your account if you lose your phone, and they're shown at setup — not retrievable later.
A password manager, or printed and kept somewhere secure, both work. Don't keep them only on the same phone that runs the authenticator app.
Signing in with 2FA
Email and password as usual, then the current code from your app.
Codes not working
Almost always a clock problem. Authenticator codes are time-based, so a phone whose clock has drifted generates codes that get rejected. Turn on automatic date and time on your phone.
Lost your phone
Use one of your recovery codes to sign in, then re-enrol 2FA on your new device.
No recovery codes either?
Contact us on live chat and we'll help you recover the account. Expect to prove your identity — that check is exactly what stops somebody else doing this to you.