GitHub 2FA: How to Set Up an Authenticator App
Two-factor authentication keeps your GitHub account and repositories safe even if your password leaks. GitHub lets you set it up with an authenticator app, which is exactly what Authenticator App - Novaz provides.
A GitHub account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, GitHub also offers SMS text codes, a proprietary app and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience — and it's safer than SMS codes, which can be intercepted through SIM-swap attacks. For the strongest protection, GitHub also supports hardware security keys.
2FA methods GitHub supports
- SMS text message
- Authenticator app (TOTP)
- Proprietary app
- Security key (U2F / WebAuthn)
Before you start
- Your GitHub username and password
- Authenticator App - Novaz installed on your iPhone or iPad
- GitHub open in a browser on your computer, so your phone can scan the QR code
- Somewhere secure to keep the recovery codes GitHub gives you
Part 1: Turn on 2FA in GitHub
- 1
Open your GitHub settings
After signing in, click your profile picture in the top-right corner and pick "Settings" from the menu.

- 2
Turn on two-factor authentication
Open "Password and authentication", scroll to the "Two-factor authentication" area, and click "Enable two-factor authentication".

- 3
Choose the app option
Pick "Set up using an app", then click "Continue".

- 4
Keep the QR code page open
GitHub now displays a QR code that holds your secret key. Leave the page open while you grab your iPhone or iPad. The QR code pictured here is only a sample, so scan the one GitHub shows you.

Part 2: Add GitHub to Authenticator App - Novaz
- 5
Scan the QR code with Authenticator App - Novaz
In Authenticator App - Novaz, press the plus button, then point your camera at the QR code on the GitHub page.

- 6
Review and save the GitHub entry
The app adds the GitHub logo and fills in your account name along with the secret key by itself. Tap the icon if you'd like a different one, then tap "Save".

Part 3: Confirm and finish
- 7
Enter the code on GitHub
Go back to GitHub, type the 6-digit code from Authenticator App - Novaz into the verification field, and click "Continue".

- 8
Save your recovery codes
GitHub then lists recovery codes that get you back into your account if you ever lose your phone. Download them, keep them in Authenticator App - Novaz, or store them in another safe spot. Then select "I have saved my recovery codes", which switches two-factor authentication on.

- 9
Test your new sign-in
Your GitHub account is now protected, and each sign-in will ask for a code from Authenticator App - Novaz. GitHub suggests signing out and back in once to try it; if anything goes wrong, a recovery code lets you in so you can sort it out.

If something goes wrong
- GitHub says the code is invalid: confirm your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter a fresh code.
- The code expired mid-typing: let the next one appear and enter it quickly.
- The QR code won't scan: zoom in on the GitHub page so the code is bigger, and keep your phone steady and free of glare.
- You lost access to your phone: sign in with one of your saved recovery codes, then set up Authenticator App - Novaz again.
Menu names on GitHub can change — the official GitHub 2FA documentation ↗ always has the exact, current path.
How to recover your GitHub account
If you lose access to your authenticator and GitHub gave you backup or recovery codes when you turned on 2FA, sign in with one of them; keep them somewhere safe, away from your phone. Not every service issues codes. If GitHub doesn't, or you didn't save them, use GitHub's account-recovery or support process (or ask your admin, for a work account) to get back in.
Frequently asked questions
- Does GitHub work with authenticator apps like Authenticator App - Novaz?
- Yes. GitHub supports TOTP authenticator apps, so you can generate its two-factor codes in Authenticator App - Novaz.
- Is GitHub two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on GitHub is free — you only need the free Authenticator App - Novaz.
- What if I lose access to my GitHub 2FA codes?
- If GitHub gave you backup or recovery codes during setup, sign in with one of them. If it didn't, or you didn't save them, use GitHub's account recovery or contact its support (or your admin, for a work account), then add the account to Authenticator App - Novaz again.
- Should I use an authenticator app or a security key on GitHub?
- GitHub supports both. An authenticator app like Authenticator App - Novaz is free and works on any phone; a hardware security key adds phishing resistance. You can enable both.
Generate your GitHub codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Developer guides
Novaz is not affiliated with, endorsed by, or sponsored by GitHub. GitHub and its logo are trademarks of their respective owner and are used here for identification only.



