Enable two-factor authentication
StackBlaze uses TOTP. Setup is at /setup-2fa or Account → Two-factor authentication. Scan the QR code, enter the 6-digit code, then Enable 2FA & continue.
There are no recovery codes. If you lose the authenticator, an admin can Reset 2FA on the user, or you contact support. 2FA is not forced by the admin/member/guest role.
Step by step
Open two-factor setup
From account settings, start Two-factor authentication, or go to /setup-2fa after sign-in if you are prompted.
Scan and verify
Add the otpauth URL in your authenticator app. Enter the current 6-digit code and click Enable 2FA & continue.
Optional: require 2FA on email-code sign-in
Account settings has Require 2FA on email-code sign-in. That is an account preference, not a role policy.
Disable or reset
Disable from account settings with a current TOTP code. Reset 2FA is an admin action on the user, not a downloadable backup-code list.
Next steps