Guide

How to Enable Two-Factor Authentication on X (Twitter)

Twitter (now known as X) tightened its 2FA policy in 2023, making SMS-based two-factor authentication a paid feature for X Premium subscribers only. Free accounts must use an authenticator app or a hardware security key โ€” which is actually the more secure choice anyway. Here is how to set it up.

How to Enable 2FA on X (Twitter) โ€” Step by Step

  1. Open x.com or the X mobile app and sign in.
  2. Click or tap your profile icon, then go to Settings and Support โ†’ Settings and privacy.
  3. Navigate to Security and account access โ†’ Security โ†’ Two-factor authentication.
  4. Choose your preferred method: Authentication app or Security key. (SMS requires X Premium.)
  5. For the authenticator app option: click Get started, then scan the QR code with your authenticator app, enter the 6-digit code to confirm, and click Confirm.
  6. X will display a backup code. Save it immediately โ€” you will need it if you lose access to your authenticator app.
Save your backup code. X provides a single backup code when you enable 2FA. Copy it to your password manager or print it. If you lose access to your authenticator and do not have this code, account recovery through X support can be slow and uncertain.

Why X Removed Free SMS 2FA

In March 2023, X announced that SMS two-factor authentication would be restricted to X Premium (paid) subscribers. The stated reason was the cost and abuse of SMS infrastructure. From a security standpoint, this is actually a positive change โ€” SMS 2FA is the weakest form of second factor due to SIM-swap attacks. Authenticator apps are more secure, free, and work without cellular connectivity.

Authenticator App vs Security Key on X

Authenticator App (TOTP)

Any standard TOTP app works with X โ€” Google Authenticator, Authy, Microsoft Authenticator, 1Password, Bitwarden, and others. After entering your password at sign-in, X will ask for the 6-digit code currently showing in your app. The code refreshes every 30 seconds. This method works offline and cannot be SIM-swapped. It is the recommended choice for most users.

Security Key (WebAuthn)

A hardware key like YubiKey provides the highest level of protection. You plug in or tap the key when X prompts you. Because security keys use the WebAuthn standard, they cryptographically verify the domain you are signing in to โ€” making them immune to phishing attacks. If your X account is important (business account, large following, brand account), a hardware key is worth the investment.

How to Disable X 2FA

To turn off two-factor authentication on X, navigate back to Settings โ†’ Security and account access โ†’ Security โ†’ Two-factor authentication and toggle off your current method. You will be prompted to enter your password to confirm.

What If I Lose My X 2FA Device?

Use the backup code X provided when you first set up 2FA. Enter it in place of your 2FA code on the sign-in screen. Once logged in, go to your security settings and either recover your 2FA setup or reconfigure it with a new device. If you do not have your backup code and cannot access your authenticator app, you will need to go through X's account recovery process, which may require email verification and identity checks.

Tips for Keeping Your X Account Secure

Beyond 2FA, use a strong and unique password for your X account. Regularly review the list of connected apps and revoke access to any you no longer use (Settings โ†’ Security and account access โ†’ Connected accounts). Be cautious about third-party tools that request your X credentials โ€” always use OAuth-based authorisation rather than giving out your password directly.

Common Problems When Setting Up X 2FA

Authenticator app shows no code: After scanning the QR code, some apps display nothing until you enter the 6-digit confirmation code and click Confirm on X. If you are adding X to an app that already holds many accounts, make sure you select the correct entry โ€” codes look similar between accounts, and entering the wrong one fails. Most authenticator apps let you rename the entry to "X (Twitter)" so you can tell them apart at a glance.

Backup code not saved: X displays your backup code only once, during setup. If you closed that screen without saving it, remove your 2FA method and re-add it โ€” X will issue a fresh backup code you can save this time. The code is a single long string; copy it exactly, including any dashes, into your password manager rather than a note on your phone.

Method greyed out: If the SMS option appears disabled, your account is not subscribed to X Premium โ€” this is expected since March 2023. The authenticator app option is the intended free path, and it is the more secure one anyway.

How X 2FA Behaves Across Devices

On the web, X marks your browser as trusted for 30 days after a successful 2FA sign-in, so you will not be prompted again on that browser. If you sign in from a new browser, an incognito window, or after clearing cookies, the 2FA prompt returns. Open sessions you do not recognise can be reviewed and terminated under Settings โ†’ Security and account access โ†’ Sessions.

In the mobile app, X prompts for a 2FA code periodically โ€” enter the 6-digit code from your authenticator before it refreshes; most apps warn you visually when a code is about to expire. As of 2024, X also supports passkeys on iOS and Android, which can replace 2FA prompts entirely on supported devices: passkeys are tied to your device's biometrics and are not linked to a phone number, making them resistant to both SIM swapping and phishing.

What X 2FA Actually Protects You From

The most damaging X account takeovers are not about your posts โ€” they are about your identity. Compromised accounts are used to send crypto giveaway scams to followers, post spam that damages a brand's reputation, and DM contacts with phishing links. Because X has no direct customer service chat, recovering a taken-over account can take days; 2FA makes password-only takeover attempts fail at the first hurdle.

2FA also protects against the quieter attacks: an attacker who changes your account email to lock you out, or who registers their own 2FA method so you cannot get back in. When you have your own authenticator registered, both moves are blocked, because every security change on the account requires the current second factor.

If Your X Account Is Hacked: Recovery Steps

Act in this order: request a password reset on the email you registered, which immediately ends the attacker's session; sign out of all sessions under Settings โ†’ Security and account access โ†’ Sessions โ†’ Log out of all sessions; then remove any phone number, email, or 2FA method you did not add. If you still have access, re-enable 2FA and generate a fresh backup code before doing anything else.

If the attacker changed your registered email before you could act, use the request help logging in flow at x.com and provide the information X asks for โ€” the original email address usually carries the most weight. While you wait, check the inbox of the email you originally registered for X's notification messages: they show exactly what changed and when, which speeds up verification.

A Real-World Walkthrough: Your First Sign-In With 2FA

After enabling, your next login on the web looks like this: username, password, then the 6-digit code from your authenticator. X remembers the browser for 30 days, so returning tomorrow needs no code. Enter a wrong code and you get a fresh prompt โ€” codes expire every 30 seconds, so wait for a new one rather than retyping the old figure.

On mobile, the app asks for a code after launch on a new device. If you use the backup code instead โ€” the single long string from setup โ€” X accepts it and marks it used, so save a new backup code afterwards. Passkeys, where available, skip all of this by using your device biometrics and remain valid across phone changes since they live on the device.

X 2FA Questions, Answered

Is 2FA required to use X? No, but accounts with 2FA enabled are significantly less attractive takeover targets.

Does 2FA slow down posting or following? No โ€” the code is only requested at sign-in on new devices.

Can I keep using third-party clients? Yes, 2FA is account-wide; a session that is already signed in on any client is unaffected.

What if I lose both my authenticator and my backup code? You will need X's identity verification process, which is why the backup code deserves a spot in your password manager.

Can I have more than one 2FA method enabled on X? Yes, X lets you add both an authenticator app and a security key at the same time. Keeping a key as a second path is useful if your phone is lost.

Does enabling 2FA affect how I use TweetDeck or API tools? No. Once a session is signed in, tools keep working; the 2FA prompt only appears at the initial sign-in on a new device or browser.

Related Articles