Security & Two-Factor Authentication
Two-Factor Authentication (2FA)
2FA adds a second verification step at login using an authenticator app (TOTP). No SMS option.
To enable:
- Go to Settings → Account → Security
- Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app (Authy, 1Password, Google Authenticator)
- Enter the 6-digit code to confirm
2FA is optional on all plans.
Recovery Codes
When you enable 2FA, Circuit generates 8 recovery codes in XXXX-XXXX format.
Save them somewhere safe. Codes are displayed once. Each code can be used once. If you lose access to your authenticator app and have no codes, contact support@withcircuit.com.
Sessions After Enabling
Enabling 2FA does not end active sessions. Existing browser sessions continue working. 2FA is enforced at the next login.
Disable or Reset
To disable 2FA, go to Settings → Account → Security and click Disable. Enter your current authenticator code to confirm.
Lost your authenticator app? Use a recovery code to log in, then disable and re-enable 2FA with your new device.
Linked Providers
Go to Settings → Account → Security to see which sign-in methods are linked to your account (email, Google, GitHub). You can unlink providers you no longer use, as long as at least one remains active.
Cookie Preferences
Cookie preferences are saved permanently. Set them once at the banner and Circuit remembers your choice. To change, go to Settings → Account → Privacy.