- PayPal 2FA is free and takes under 2 minutes to set up
- Use an authenticator app (TOTP) rather than SMS for stronger security
- PayPal also offers a security key as a physical 2FA option
- Save backup codes in case you lose access to your phone
- 2FA does not affect your ability to send or receive money — it only protects logins
Table of Contents
Why Enable 2FA on PayPal?
PayPal is one of the most targeted accounts for hackers because it provides direct access to money. Stolen PayPal credentials are sold on dark web markets every day. A compromised account can result in unauthorized payments, drained balances, or fraudulent purchases — often before the real owner even notices. Since PayPal transactions are often irreversible, recovering stolen funds after an account takeover can be difficult or impossible.
PayPal's 2-step verification (their name for two-factor authentication) means that even if someone steals your email and password, they still can't log in without the second factor — a code sent to your phone or generated by your authenticator app. For financial accounts in particular, 2FA is one of the most effective ways to prevent credential theft from escalating into real financial loss.
Beyond protecting your balance, PayPal 2FA also secures linked bank accounts, credit cards, and your personal information stored in your profile. A hacked PayPal account doesn't just lose its own balance — attackers can also use saved payment methods to make purchases elsewhere if you have features like One Touch enabled.
Before You Start
A few things to know before enabling PayPal 2FA:
- PayPal 2FA setup must be done through a web browser — it cannot be set up inside the PayPal mobile app.
- You'll need either a mobile phone (for SMS) or an authenticator app already installed.
- You can only have one active 2FA method at a time on PayPal — either SMS or an authenticator app, not both simultaneously.
PayPal's 2FA setup is only available via a web browser, not the mobile app. Open paypal.com on your phone or computer browser to complete these steps.
PayPal 2FA Options
PayPal offers several ways to enable two-factor authentication. Each method has different trade-offs between convenience and security. Here's how they compare:
- Authenticator App (TOTP) — Generates 6-digit codes offline using a time-based algorithm. Recommended because codes can't be intercepted by SIM-swap attacks. Works with apps like Google Authenticator, Microsoft Authenticator, and Authy. See our top authenticator app picks.
- SMS (Text Message) — A 6-digit code is texted to your phone each time you log in. Widely compatible but vulnerable to SIM-swap attacks and carrier outages.
- Security Key — A physical hardware key that plugs into your device via USB or NFC. Considered the most secure option but requires purchasing a separate device. Hardware key vs authenticator app — which is better?
For most users, an authenticator app offers the best balance of security and convenience. Below we cover how to set up both SMS and authenticator app methods.
Enable PayPal 2FA via SMS
Go to paypal.com and sign in to your account in a web browser.
Click the ⚙️ Settings (gear) icon in the top-right corner of the page.
Click Security in the top navigation bar of your account settings.
In the Security section, find 2-step verification and click Set Up to the right of it.
Select Text me a code and click Set It Up.
Select your country code and enter your mobile phone number, then click Next. PayPal will send a 6-digit code to that number.
Enter the 6-digit code from the text message and click Confirm. You'll see a confirmation message that 2-step verification has been successfully added. Click Done.
SMS 2FA is now active on your PayPal account. Every login from an unrecognized device will require the code texted to your phone.
Enable PayPal 2FA via Authenticator App
Using an authenticator app is more secure than SMS — codes are generated offline and can't be intercepted by SIM-swap attacks. PayPal supports any standard TOTP app including Google Authenticator, Microsoft Authenticator, and Authy.
Follow steps 1–4 from the SMS section above to reach the 2-step verification setup page.
On the verification method screen, choose Use an authenticator app and click Set It Up.
PayPal displays a QR code. Open your authenticator app, add a new account, and scan the QR code. Alternatively, click "Can't scan the QR code?" to get a text key you can enter manually into your app.
Your authenticator app will immediately generate a 6-digit TOTP code. Enter it in the PayPal confirmation field under "Step 2" and click Confirm.
PayPal confirms that 2-step verification has been successfully added. Click Done. You can optionally add a second device by clicking "Add another device" before finishing.
Consider adding a second authenticator device as a backup (e.g., a tablet or second phone) in case you lose your primary device. You can do this immediately after setup by clicking "Add another device."
Signing In with 2FA Active
Once 2-step verification is enabled, here's what happens each time you sign in to PayPal from a new or unrecognized device:
- Enter your email and password as usual.
- PayPal sends you a code via SMS, or you open your authenticator app for the code.
- Enter the 6-digit code on the PayPal verification screen.
- You're signed in. PayPal may give you the option to trust this device to skip 2FA in future.
How to Turn Off PayPal 2FA
If you need to disable 2-step verification, go to Settings → Security and click Turn Off next to 2-step verification. Click the Turn It Off button to confirm.
PayPal may recommend enabling passkeys or keeping the mobile app signed in as additional security measures if you disable 2FA. Without 2FA, your account is protected only by your password.
Troubleshooting PayPal 2FA
Not receiving SMS codes
If PayPal isn't sending SMS codes, first check that your phone number is correct in Security settings. Make sure your phone has cellular signal and can receive texts from short codes (5-6 digit numbers). If you're traveling internationally, some carriers block short-code SMS from abroad — in that case, switch to an authenticator app instead.
Authenticator app code isn't working
TOTP codes expire every 30 seconds. Make sure you're entering the code before it refreshes. If codes consistently fail, check that your device's time is set correctly (TOTP relies on accurate time sync). On both iOS and Android, enable automatic time zone and date/time settings for proper code generation.
Locked out of your account
If you can't log in because you lost access to your 2FA method, click the "Having trouble?" or "Try another way" link on the PayPal login screen. PayPal may offer account recovery options such as verifying your email or answering security questions. If those don't work, you'll need to contact PayPal support and complete identity verification — have a government ID ready.
2FA keeps asking on the same device
After logging in successfully, PayPal gives you the option to "Trust this device" so you won't be prompted for 2FA again on that browser. If you're seeing the 2FA prompt every time, you may have declined the trust prompt, or cookies may be cleared regularly by your browser settings.
Frequently Asked Questions
Can I set up PayPal 2FA on the mobile app?
Can I use both SMS and an authenticator app?
What if I'm not receiving the SMS code?
What happens if I lose my phone?
Does PayPal 2FA also protect PayPal payments?
Does PayPal offer backup codes for 2FA?
Can I use a hardware security key with PayPal?
Will 2FA slow down my PayPal login?
Free TOTP Code Generator
Want to generate 2FA codes without an app? Our free browser-based TOTP generator works instantly — no installation needed.
Try the 2FA Code Generator →