Lock down your account with two-factor
Add a second layer to your NexGuard account with an authenticator app. A time-based one-time code (TOTP) is required alongside your password, and one-time recovery codes get you back in if you lose your device.
Illustrative data — not a real account
Two-factor (2FA) in one line
Every NexGuard user who wants their account — and the vault behind it — protected even if their password is ever guessed or leaked.
Why it matters
A password alone is a single point of failure. Two-factor means a stolen password isn’t enough on its own, and rotating sessions mean a leaked token can’t linger.
Key benefits
What you get
Standard TOTP
Works with any authenticator app you already use. Codes are generated on your device, following the usual RFC-based standard.
Recovery codes
Enabling 2FA gives you one-time recovery codes so you’re never locked out if your authenticator is lost.
Sessions that self-heal
Turning 2FA on or off ends every other active session. Refresh tokens are single-use and rotate on every use.
How it works
From tap to result
Enable
Scan the setup code into your authenticator app and confirm a code to turn 2FA on.
Save recovery
Store the one-time recovery codes somewhere safe — ideally your encrypted vault.
Sign in securely
From then on, sign-in asks for your authenticator code; other sessions are revoked when 2FA changes.
Where it fits
Everyday use cases
Real situations where two-factor (2fa) earns its place.
Availability & plans
Questions
Two-factor (2FA), explained
Which authenticator apps work?
What if I lose my authenticator?
Does changing 2FA log me out elsewhere?
Get early access
Ready when you are
Get NexGuard free and see your whole security posture in minutes — no card to start, upgrade only if you want higher limits and the advanced engines.