Protect cPanel with two-factor authentication
Require an authenticator code as well as your password when signing in.
Where Tools → Security → Two-Factor Authentication
Before you start
- Have a compatible authenticator app ready and a recovery plan if you lose the device.
- Keep the setup QR code and secret key private. They can let another person generate your codes.
Steps
-
1
In your authenticator app, add an account by scanning the displayed QR code, or enter the Account and Key manually.
-
2
Enter the app’s current six-digit code in Security Code before it expires.
-
3
Click Configure Two-Factor Authentication and read the confirmation. Other cPanel windows may be signed out.
-
4
Test a new login with your password and a current code. Reconfigure replaces the previous setup; do not use it unless you intend to move to a new configuration.
-
5
Open Two-Factor Authentication and click Set Up Two-Factor Authentication.
Start setup here; the secret QR-code screen is intentionally not published.
Check it worked
- Confirm a fresh cPanel login requests the code.
- If codes fail, check device time and contact support. If the device is lost, use the provider’s identity-verified recovery process.