Auth0 2FA: How to Set Up an Authenticator App
The Auth0 Dashboard is where you configure your Auth0 services, so your own admin login deserves more than a password. Auth0 calls the feature multi-factor authentication (MFA), and its one-time password (OTP) factor works with an authenticator app such as Authenticator App - Novaz. This guide covers your Dashboard login at manage.auth0.com, not MFA for the users of your applications.
A Auth0 account is part of your security setup, so it deserves strong 2FA of its own. Besides an authenticator app, Auth0 also offers a proprietary app, SMS text codes and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience — and it's safer than SMS codes, which can be intercepted through SIM-swap attacks. For the strongest protection, Auth0 also supports hardware security keys.
2FA methods Auth0 supports
- Proprietary app
- SMS text message
- Authenticator app (TOTP)
- Security key (U2F / WebAuthn)
Before you start
- Access to the Auth0 Dashboard, where you enroll MFA for yourself in "Your Profile"
- Authenticator App - Novaz installed on your iPhone or iPad
- The Dashboard open on a computer, so the setup screen is on a different device from your phone
- A safe place for your recovery code, such as a password manager or a printout
- Ideally a second factor as backup, such as a security key, or SMS if your tenant is attached to a subscription plan
Part 1: Turn on 2FA in Auth0
- 1
Open Your Profile
Sign in to the Auth0 Dashboard. Click your username in the top right corner, then click "Your Profile".
- 2
Click + ADD on the authenticator app row
Under "Multi-Factor Authentication" you'll see one row per factor. Find the one-time password row for authenticator apps (labelled "Google authenticator or similar" in Auth0's screenshot) and click "+ ADD" in that row.
- 3
Follow the on-screen instructions
Auth0 walks you through adding the account to an authenticator app. Keep this screen open.
Part 2: Add Auth0 to Authenticator App - Novaz
- 4
Add Auth0 in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code on the Dashboard. If Auth0 gives you a code to type instead, choose to enter a setup key and type it exactly. Use "Auth0" as the account name, then tap "Save".
- 5
Note the one-time code
Authenticator App - Novaz now shows a one-time code for Auth0 that changes every 30 seconds. Have it ready for the next step.
Part 3: Confirm and finish
- 6
Enter the code to complete enrollment
Back in the Dashboard, enter the code from Authenticator App - Novaz to finish enrolling the factor.
- 7
Copy your recovery code
Immediately after you enable MFA, Auth0 prompts you to copy a recovery code. Copy it and print it or store it in a password manager. It's your way in if you lose every enrolled factor.
- 8
Know what the next login looks like
After your credentials, Auth0 shows a second prompt: enter the code from Authenticator App - Novaz. Auth0 may then prompt you to enroll device biometrics such as Touch ID or Windows Hello, which can't be added from "Your Profile".
If something goes wrong
- Auth0 rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
- Your phone is lost but you have another factor: at the MFA prompt click "Try another method", pick a different method, then in "Your Profile" click "REMOVE" on the lost factor and "Yes" to confirm.
- You're moving to a new phone: in "Your Profile", enroll the new phone with "+ ADD" first, then "REMOVE" the old factor. Auth0 asks you to authenticate with your current factors before removing it.
- SMS isn't offered as a backup: SMS for Dashboard MFA is only available on tenants attached to a subscription plan.
Checked against Auth0's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
How to recover your Auth0 account
Auth0 gives you a recovery code right after you enable MFA. If you lose access to all your enrolled factors, choose another method at the MFA prompt and enter the recovery code to log in, then remove the lost factor in "Your Profile", where you can also generate a new recovery code. If you're locked out with no factor and no recovery code, there's no guarantee you'll get back in: another administrator must file an Auth0 support ticket on your behalf. In some cases Auth0 can verify the request and reset your MFA, but it may not be able to confirm that you own the account, so enroll more than one factor.
Frequently asked questions
- Does this turn on MFA for my application's users?
- No. This protects your own Auth0 Dashboard login. For your application's users, OTP has to be enabled as an MFA factor in your Auth0 tenant, and Auth0 support doesn't reset end-user accounts.
- Which MFA factors can Dashboard users enroll?
- WebAuthn with FIDO security keys, WebAuthn with device biometrics, push notifications via Auth0 Guardian, one-time passwords from an authenticator app such as Authenticator App - Novaz, and SMS on subscription plans. You also get a recovery code.
- Can other admins see whether I've turned on MFA?
- Yes. The MFA indicator in the Tenant Members list under "Settings" in the Auth0 Dashboard shows whether each user has enabled MFA.
Generate your Auth0 codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Security guides
Novaz is not affiliated with, endorsed by, or sponsored by Auth0. Auth0 and its logo are trademarks of their respective owner and are used here for identification only.



