Settings → Account → Security → Enable Two-Factor Authentication. Scan the QR code with an authenticator app — Authy, 1Password, Google Authenticator — and enter the 6-digit code to confirm. TOTP only; there's no SMS option, and 2FA is optional on every plan.
01Turn on two-factor
02Save your recovery codes
You get 8 codes in XXXX-XXXX format, each usable once. Save them the moment they appear — Annsa only keeps a hashed copy, so they cannot be read back to you afterwards. Need a fresh set? Settings → Account → Security → Generate new codes issues 8 new ones and retires the old. If you lose both your authenticator and your codes, email support@annsa.ai.
03What happens to active sessions
The browser you turned it on in stays signed in — confirming the code verifies that session there and then. Anywhere else you are already signed in, Annsa asks for a code the next time the page loads, not the next time you log in. Have your authenticator to hand before you enable it on a shared or second device.
04Disabling or moving device
Settings → Account → Security → Disable, confirmed with your current code. Lost the app? Enter a recovery code when Annsa asks for your 6-digit code: that switches two-factor off, signs you out everywhere, and lets you sign back in without it. Turn it on again from your new device.
05Linked sign-in methods
Settings → Account → Security shows which methods are linked — email, Google, GitHub. Unlink any you no longer use, as long as one stays active.