How to enable 2FA on Substack
Protect your Substack account with two-factor authentication (2FA). Once enabled, signing in also requires a one-time code from your authenticator app — not just your password.
Step-by-step setup
- 1
Sign in to Substack and open your Substack account security settings.
- 2
Turn on two-factor authentication and choose the authenticator-app option.
Look for "Authenticator app", "Authentication app", or "TOTP" rather than SMS.
- 3
Scan the QR code with MS Authenticator App.
Open MS Authenticator App, tap add, and point your camera at the QR code Substack displays. Can't scan? Enter the setup key manually instead.
- 4
Enter the 6-digit code to confirm.
Type the code MS Authenticator App generates to verify and link your Substack account.
- 5
Save your backup codes.
Store the recovery codes Substack gives you somewhere safe — you'll need them if you lose your phone.
Menu names on Substack can change — the official Substack 2FA documentation ↗ always has the exact, current path.
Frequently asked questions
- Does Substack work with authenticator apps like MS Authenticator App?
- Yes. Substack supports TOTP authenticator apps, so you can generate its two-factor codes in MS Authenticator App.
- Is Substack two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on Substack is free — you only need the free MS Authenticator App.
- What if I lose access to my Substack 2FA codes?
- Use the backup or recovery codes you saved during setup. If you didn't save them, contact Substack support to regain access, then re-add the account to MS Authenticator App.
Generate your Substack codes in MS Authenticator App
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Social guides
Novaz is not affiliated with, endorsed by, or sponsored by Substack. Substack and its logo are trademarks of their respective owner and are used here for identification only.