Authenticator App - Novaz

Postman 2FA: How to Set Up an Authenticator App

postman.com SupportedChecked against official help · September 25, 2026

Your Postman account signs you in to Postman on the web and in the desktop app. Postman calls the feature two-factor authentication (2FA): after your password, it asks for a six-digit code from an authenticator app, so Authenticator App - Novaz can supply your codes.

A Postman account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Postman secures sign-ins with an authenticator app — set it up once and you're protected on every login.

2FA methods Postman supports

  • Authenticator app (TOTP)

Before you start

  • A Postman account you sign in to with a username or email and a password: Postman's 2FA instructions are written for this kind of sign-in
  • Your Postman password, because Postman asks for it during setup
  • Authenticator App - Novaz installed on your iPhone or iPad
  • Time to sign in again on your other devices: enabling 2FA revokes all of your active Postman sessions
  • A secure place to store the recovery codes Postman gives you

Part 1: Turn on 2FA in Postman

  1. 1

    Open Account settings

    Sign in to Postman, click your avatar in the Postman header, hover over your account entry and click "Account settings". You can also go straight to go.postman.co/settings/me/account.

  2. 2

    Click Enable 2FA

    Click "Enable 2FA". Postman warns that enabling 2FA will revoke all of your active Postman sessions.

  3. 3

    Click Continue

    With Authenticator App - Novaz installed and your password at hand, click "Continue".

  4. 4

    Enter your password

    Enter your Postman password and click "Verify". Postman then asks you to link your authenticator app.

Part 2: Add Postman to Authenticator App - Novaz

  1. 5

    Link Authenticator App - Novaz

    Open Authenticator App - Novaz and tap the + button. Scan the QR code if Postman shows one, or choose to enter a setup key and type it exactly as Postman shows it. Check the account name, then tap "Save".

  2. 6

    Note the six-digit code

    Authenticator App - Novaz now shows a six-digit authentication code for Postman. The code changes after a short time, so have it ready for the next step.

Part 3: Confirm and finish

  1. 7

    Enter the code and click Next

    Back in Postman, enter the six-digit code from Authenticator App - Novaz and click "Next".

  2. 8

    Download your recovery codes

    Download your recovery codes and store them in a secure location. Each code can be used only once. Click "Done" to finish.

  3. 9

    Sign in with a code from now on

    Postman now asks for your password and the authentication code whenever you sign in. Enter the code from Authenticator App - Novaz and click "Verify". The Postman desktop app sends you to your browser for this sign-in.

If something goes wrong

  • Postman rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
  • You were signed out on your other devices right after setup: that's expected, because enabling 2FA revokes all of your active Postman sessions. Sign in again with your password and a code.
  • Sign-in from the desktop app timed out: you must finish signing in within five minutes of starting in the Postman desktop app. Go back to the app and restart the sign-in.
  • You've used up or misplaced your recovery codes but can still sign in: open your account settings and click "Regenerate recovery codes".

Checked against Postman's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:

How to recover your Postman account

Postman gives you recovery codes at the end of setup, and each one works only once. If you lose your device and can't open Authenticator App - Novaz, click "Use a recovery code" when Postman asks for your verification code at sign-in. While you're signed in, you can open your account settings and click "Regenerate recovery codes" for a new set. If you've lost your recovery codes as well, email Postman support at help@postman.com from a registered email address for help.

Frequently asked questions

Will Postman ask for a code every time I sign in?
Once 2FA is on, Postman says you must provide both your password and the authentication code to sign in. If you select "Stay signed in", you stay signed in until you're inactive for 30 days.
Does 2FA work with the Postman desktop app?
Yes. The desktop app opens your browser to sign in. After your credentials, Postman asks for the verification code from your authenticator app, then sends you back to the desktop app.
How do I turn off two-factor authentication?
Open "Account settings", click "Disable 2FA", enter your password and click "Disable 2FA" again. You can enable it again at any time from your account settings.

Generate your Postman codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Developer guides

Novaz is not affiliated with, endorsed by, or sponsored by Postman. Postman and its logo are trademarks of their respective owner and are used here for identification only.