Codeberg 2FA: How to Set Up an Authenticator App
Your Codeberg account holds your repositories, issues and pull requests, and a leaked password alone shouldn't be enough to reach them. Codeberg calls the feature two-factor authentication and uses TOTP: when you log in, it asks for a six-digit code generated on your phone, so Authenticator App - Novaz can supply your codes.
A Codeberg account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, Codeberg also offers security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, Codeberg also supports hardware security keys.
2FA methods Codeberg supports
- Authenticator app (TOTP)
- Security key (U2F / WebAuthn)
Before you start
- Your Codeberg username or email address and password
- Authenticator App - Novaz installed on your iPhone or iPad: Codeberg requires an authenticator app on your phone
- Codeberg open on a computer, so you can scan the QR code with your phone
- A safe place for your scratch token, which Codeberg shows only once, right after setup
- If you push to Codeberg over HTTPS, a personal access token afterwards: it replaces your password for Git once 2FA is on
Part 1: Turn on 2FA in Codeberg
- 1
Open your user settings
Sign in at codeberg.org and open your user settings.
- 2
Go to the Security tab
Click the "Security" tab. The "Two-Factor Authentication" section is at the top.
- 3
Click the enroll button
Click "Enroll". Codeberg shows a QR code to scan with your authentication application, and a secret you can enter instead.
Part 2: Add Codeberg to Authenticator App - Novaz
- 4
Add Codeberg in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, choose to enter a setup key and type the secret Codeberg shows. Name the account "Codeberg" and tap "Save".
- 5
Note the six-digit code
Authenticator App - Novaz now shows a six-digit code for Codeberg. It changes every 30 seconds, so have it ready for the next step.
Part 3: Confirm and finish
- 6
Enter the passcode and click Verify
Back on Codeberg, enter the six-digit code from the app in the "Passcode" field of the settings form, then click "Verify".
- 7
Store your scratch token
Right after setup, Codeberg shows your scratch token. Copy it and store it in a safe place: it's shown only once, and it's how you recover your account if your phone breaks, gets lost or gets stolen.
- 8
Log in with your code from now on
Two-factor authentication is now configured. Each time you log in to Codeberg, you'll be asked for an authentication code from Authenticator App - Novaz on top of your password.
- 9
Save a way to recover your account
If Codeberg offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Codeberg recovers accounts before you need it.
If something goes wrong
- Codeberg rejects the code: Codeberg uses 30-second time frames and also accepts the code from the previous period, so you always have at least 30 seconds. If codes still fail, make sure your iPhone sets its date and time automatically (Settings > General > Date & Time).
- Git over HTTPS won't accept your password: create a personal access token. In your settings, open the "Applications" tab, add a "Token Name" under "Manage Access Tokens" and click "Generate Token". Enter the token when Git asks for your password; it won't be shown again, and you can revoke it with "Delete".
- You use SSH for Git: no extra configuration is needed after turning on 2FA; your SSH key keeps working.
Checked against Codeberg's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
How to recover your Codeberg account
Codeberg's recovery route is the scratch token it shows once, right after you set up two-factor authentication. If your phone ever breaks, gets lost or gets stolen, you can recover your account using that token, so keep it somewhere safe and separate from your phone. Codeberg's documentation doesn't describe another way back in if you lose both your phone and the scratch token, so treat the token as essential.
Frequently asked questions
- Which authenticator app should I use with Codeberg?
- Codeberg needs an authenticator app on your phone and suggests Aegis Authenticator, Authenticator and Ente Auth if you aren't sure which one to use. Authenticator App - Novaz works too.
- How long is each Codeberg code valid?
- Codeberg follows the RFC 6238 TOTP standard with 30-second time frames and accepts both the current and the previous code, so you always have at least 30 seconds to enter one.
- Can I add a security key as well?
- Yes, but only once TOTP is configured: go to the "Security" tab, give your key a nickname under the Security Keys section and click "Add Security Key". When you sign in, you can then choose between TOTP and WebAuthn. Codeberg recommends adding at least 2 security keys if you can.
Generate your Codeberg codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Developer guides
Novaz is not affiliated with, endorsed by, or sponsored by Codeberg. Codeberg and its logo are trademarks of their respective owner and are used here for identification only.



