GitLab 2FA: How to Set Up an Authenticator App
Enable two-factor authentication on GitLab to stop unauthorized logins. After setup, GitLab asks for a rotating code from Authenticator App - Novaz in addition to your password.
A GitLab account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, GitLab also offers email codes and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, GitLab also supports hardware security keys.
2FA methods GitLab supports
- Email code
- Authenticator app (TOTP)
- Security key (U2F / WebAuthn)
- 1
Download Authenticator App - Novaz
Install Authenticator App - Novaz from the App Store on your iPhone or iPad and open it — you'll use it to scan GitLab's QR code and generate your 6-digit sign-in codes.
- 2
Sign in to GitLab and open Preferences → Account → Two-Factor Authentication.
- 3
Turn on two-factor authentication and choose the authenticator-app option.
Look for "Authenticator app", "Authentication app", or "TOTP" rather than SMS.
- 4
Scan the QR code with Authenticator App - Novaz.
Open Authenticator App - Novaz, tap add, and point your camera at the QR code GitLab displays. Can't scan? Enter the setup key manually instead.
- 5
Enter the 6-digit code to confirm.
Type the code Authenticator App - Novaz generates to verify and link your GitLab account.
- 6
Save a way to recover your account.
If GitLab shows backup or recovery codes, store them somewhere safe, away from your phone. If it doesn't, check how GitLab recovers accounts (support, an admin, or another sign-in method) before you need it.
Menu names on GitLab can change — the official GitLab 2FA documentation ↗ always has the exact, current path.
How to recover your GitLab account
If you lose access to your authenticator and GitLab gave you backup or recovery codes when you turned on 2FA, sign in with one of them; keep them somewhere safe, away from your phone. Not every service issues codes. If GitLab doesn't, or you didn't save them, use GitLab's account-recovery or support process (or ask your admin, for a work account) to get back in.
Frequently asked questions
- Does GitLab work with authenticator apps like Authenticator App - Novaz?
- Yes. GitLab supports TOTP authenticator apps, so you can generate its two-factor codes in Authenticator App - Novaz.
- Is GitLab two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on GitLab is free — you only need the free Authenticator App - Novaz.
- What if I lose access to my GitLab 2FA codes?
- If GitLab gave you backup or recovery codes during setup, sign in with one of them. If it didn't, or you didn't save them, use GitLab's account recovery or contact its support (or your admin, for a work account), then add the account to Authenticator App - Novaz again.
- Should I use an authenticator app or a security key on GitLab?
- GitLab supports both. An authenticator app like Authenticator App - Novaz is free and works on any phone; a hardware security key adds phishing resistance. You can enable both.
Generate your GitLab codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Developer guides
Novaz is not affiliated with, endorsed by, or sponsored by GitLab. GitLab and its logo are trademarks of their respective owner and are used here for identification only.



