Guide

How to Set Up Two-Factor Authentication on Kraken

Kraken holds real money. A compromised Kraken account can result in immediate and irreversible financial loss. Two-factor authentication is non-negotiable for any crypto exchange account.

Kraken's 2FA Security Levels

Kraken offers two separate 2FA layers: one for sign-in and another for withdrawals. Use both for maximum protection.

Enable Sign-In 2FA

  1. Log in to Kraken and go to Security โ†’ Two-factor authentication
  2. Under Sign in two-factor, click Set up
  3. Choose Authenticator app (TOTP) โ€” this is the most secure option
  4. Scan the QR code with your authenticator app or paste the key into 2faco.com
  5. Enter the 6-digit code to verify
  6. Write down your backup codes

Set a Master Key (Optional but Recommended)

Kraken's Master Key is an additional password required to change security settings. This prevents an attacker from disabling 2FA even if they compromise your account password.

  1. Go to Security โ†’ Master key
  2. Set a unique, memorable password distinct from your login password

Enable Withdrawal 2FA

  1. Go to Security โ†’ Two-factor authentication โ†’ Withdrawal two-factor
  2. Set up a second TOTP entry using a different authenticator app entry or a different account in your authenticator
  3. This means even if your sign-in 2FA is compromised, funds cannot be withdrawn
Critical: Never disable withdrawal 2FA even temporarily. This is the last line of defence against fund theft.

Summary

  • โœ“ Enable TOTP 2FA for sign-in
  • โœ“ Set a Master Key to protect security settings
  • โœ“ Enable a separate 2FA for withdrawals
  • โœ“ Save backup codes offline

Why Kraken Requires Robust 2FA

Kraken is one of the largest cryptocurrency exchanges. Your Kraken account controls real funds and connects to bank accounts or other withdrawal methods. Unlike a hacked email account (which you can recover), cryptocurrency transactions are irreversible. A compromised Kraken account with a pending withdrawal cannot be undone after the fact. Kraken's multi-layer 2FA approach reflects this โ€” you can configure different 2FA requirements for different action types.

Kraken's Master Key

Kraken supports a "Master Key" โ€” a passphrase you set that is required to change security settings on your account. This is separate from your login password and provides an extra barrier against an attacker who has already obtained your password. Set a Master Key from Security โ†’ Master Key. Store it in a password manager along with your login password.

Global Settings Lock

Kraken offers a Global Settings Lock (GSL), which prevents changes to your security settings (including 2FA method, withdrawal addresses, and API keys) without a 24-hour waiting period. This means even if an attacker gains full account access, they cannot immediately change your withdrawal address and drain funds โ€” you get a window to detect and respond. Enable it under Security โ†’ Global Settings Lock.

Setting Up Different 2FA for Different Actions

Kraken uniquely allows you to configure separate 2FA methods for sign-in, trading/funding, and API key access. You could use an authenticator app for login, a hardware key for withdrawals, and a different TOTP for API access. This separation means compromising one factor does not automatically compromise all actions. Configure this under Security โ†’ Two-factor authentication.

Kraken API Keys and 2FA

If you use trading bots or third-party portfolio trackers connected to Kraken, secure your API keys carefully. Create dedicated API keys with only the permissions the tool needs (read-only for trackers, trade-only without withdrawals for bots). Set an IP restriction on the key if the tool runs from a fixed IP. Rotate API keys periodically and delete unused ones from Security โ†’ API.

Troubleshooting Kraken 2FA

If your 6-digit code is rejected, check that your authenticator app and phone clock are synchronised โ€” TOTP codes depend on accurate time, and a drift of even a few seconds produces codes Kraken will not accept. On iPhone, enable Set Automatically under Settings โ†’ General โ†’ Date & Time; on Android, switch on automatic time under Settings โ†’ System โ†’ Date & Time. If you have lost access to your authenticator app, sign in with one of the backup codes you saved during setup, or use your Master Key if you set one. Kraken may also require phone verification or a support ticket with identity documents to reset 2FA โ€” a process that can take several days, which is why saving backup codes offline matters. If you use the Kraken mobile app, note that it can use your device's biometrics for convenient sign-in, but withdrawals will still ask for your 2FA code.

Kraken 2FA Best Practices

Use a hardware security key for withdrawals rather than a phone-based app if you hold significant funds โ€” keys like a YubiKey are phishing-resistant and cannot be stolen remotely. Keep a printed copy of your backup codes in a physically secure location, and never store them in an email or cloud note an attacker could reach. Enable the Global Settings Lock so that any change to security settings triggers a 24-hour wait, giving you time to notice an attack in progress. Be suspicious of any message claiming to be from Kraken that asks for your 2FA code, password, or Master Key โ€” Kraken support never asks for these. Finally, review your recent sign-in history periodically and log out of sessions you no longer recognise.

Kraken Mobile App and Biometrics

The Kraken mobile app lets you unlock the app with your fingerprint or face for convenience, but biometrics only replace the app's own lock screen โ€” they do not replace your login password or your 2FA code. Every fresh sign-in still requires the full two-factor challenge, and withdrawals will always ask for your withdrawal 2FA regardless of how you unlocked the app. That separation is intentional: a thief who gets your unlocked phone cannot move funds without the second factor.

When you install the Kraken app on a new phone, the app does not inherit the old installation's session. Have your TOTP app (or a backup code) ready during the first sign-in on the new device, and if you reinstall because of a stolen phone, use Kraken's remote logout option from a desktop browser first so the old session is killed before it can be used. If you use your phone's built-in authenticator entries, remember they are tied to the device, so exporting or storing the seed in a place you can recover matters more than the app itself.

Using Separate 2FA Entries for Sign-In and Withdrawals

Kraken lets you register a separate authenticator entry for withdrawals, and it only helps if you actually keep them apart. The common mistake is scanning the same TOTP secret into two entries โ€” one labelled "sign-in" and one labelled "withdrawal" โ€” which gives an attacker who obtains one secret both factors. Instead, enrol the withdrawal entry with a different secret (Kraken shows a separate QR code for it) and, if possible, store it in a different app or on a hardware key so that compromising your sign-in factor does not compromise withdrawals.

Label every entry with its exact purpose, for example "Kraken login" and "Kraken withdraw", because when you hold several accounts across exchanges it is remarkably easy to enter the code from the wrong entry under time pressure. If you notice you have been using one entry for everything, fix it while you still have full access: remove the withdrawal factor, register a fresh secret, and verify a test withdrawal attempt prompts correctly.

Recovering a Kraken Account After Losing Everything

If you lose your phone and never saved backup codes, recovery runs through Kraken's identity verification process, which for accounts holding significant funds can take several days and requires documents proving who you are โ€” and Kraken may restrict withdrawals until the review completes. That delay is a feature: it is the same process that makes it hard for an attacker to reset your account. What you should never do is pay a third-party "account recovery" service that promises to bypass it; these are scams that harvest your identity documents and credentials.

Because recovery is slow, the practical investment is prevention: save your backup codes in two separate offline places, set the Global Settings Lock so no one can change security settings during the window, and keep your Master Key in your password manager. If you set a Master Key, losing it alongside your 2FA device is a second problem, so store it with your recovery documents rather than only in your head.

Frequently Asked Questions About Kraken 2FA

Can I use the same authenticator app for Kraken and my other accounts? Yes โ€” any standard TOTP app can hold multiple entries. Just keep Kraken's sign-in and withdrawal entries separate from each other and clearly labelled, since entering the wrong code from another exchange is the most common reason a valid login fails.

What happens to my 2FA if I change phone number? Withdrawal and sign-in TOTP entries are tied to your authenticator app, not your number, so they keep working. Only SMS-based verification and some account recovery paths use your number, so update it under Security while you can still confirm it.

Does the 24-hour Global Settings Lock apply to 2FA changes? Yes โ€” changing or removing your 2FA methods while the lock is enabled triggers the cooldown period, which is exactly the protection you want if an attacker reaches your security settings.

Related Articles