Authenticator App - Novaz

PyPI 2FA: How to Set Up an Authenticator App

pypi.org Supported

PyPI supports app-based two-factor authentication (2FA). Turning it on adds a second layer of protection, so a stolen password alone can't unlock your PyPI account.

A PyPI account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, PyPI also offers security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, PyPI also supports hardware security keys.

2FA methods PyPI supports

  • Authenticator app (TOTP)
  • Security key (U2F / WebAuthn)
  1. 1

    Download Authenticator App - Novaz

    Install Authenticator App - Novaz from the App Store on your iPhone or iPad and open it — you'll use it to scan PyPI's QR code and generate your 6-digit sign-in codes.

  2. 2

    Sign in to PyPI and open your PyPI account security settings.

  3. 3

    Turn on two-factor authentication and choose the authenticator-app option.

    Look for "Authenticator app", "Authentication app", or "TOTP" rather than SMS.

  4. 4

    Scan the QR code with Authenticator App - Novaz.

    Open Authenticator App - Novaz, tap add, and point your camera at the QR code PyPI displays. Can't scan? Enter the setup key manually instead.

  5. 5

    Enter the 6-digit code to confirm.

    Type the code Authenticator App - Novaz generates to verify and link your PyPI account.

  6. 6

    Save a way to recover your account.

    If PyPI shows backup or recovery codes, store them somewhere safe, away from your phone. If it doesn't, check how PyPI recovers accounts (support, an admin, or another sign-in method) before you need it.

Menu names on PyPI can change — the official PyPI 2FA documentation ↗ always has the exact, current path.

How to recover your PyPI account

If you lose access to your authenticator and PyPI gave you backup or recovery codes when you turned on 2FA, sign in with one of them; keep them somewhere safe, away from your phone. Not every service issues codes. If PyPI doesn't, or you didn't save them, use PyPI's account-recovery or support process (or ask your admin, for a work account) to get back in.

Frequently asked questions

Does PyPI work with authenticator apps like Authenticator App - Novaz?
Yes. PyPI supports TOTP authenticator apps, so you can generate its two-factor codes in Authenticator App - Novaz.
Is PyPI two-factor authentication free?
Yes. Enabling authenticator-app 2FA on PyPI is free — you only need the free Authenticator App - Novaz.
What if I lose access to my PyPI 2FA codes?
If PyPI gave you backup or recovery codes during setup, sign in with one of them. If it didn't, or you didn't save them, use PyPI's account recovery or contact its support (or your admin, for a work account), then add the account to Authenticator App - Novaz again.
Should I use an authenticator app or a security key on PyPI?
PyPI supports both. An authenticator app like Authenticator App - Novaz is free and works on any phone; a hardware security key adds phishing resistance. You can enable both.

Generate your PyPI codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Developer guides

Novaz is not affiliated with, endorsed by, or sponsored by PyPI. PyPI and its logo are trademarks of their respective owner and are used here for identification only.