> For the complete documentation index, see [llms.txt](https://docs.openreview.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.openreview.net/v1/getting-started/creating-an-openreview-profile/setting-up-multi-factor-authentication.md).

# Setting up multi-factor authentication

Multi-factor authentication (MFA) adds a second verification step to your OpenReview login. After you enter your password, OpenReview asks for a one-time code or a passkey, so your profile stays protected even if someone learns your password.

OpenReview supports three verification methods:

* **Authenticator app** — a 6-digit code generated by an app such as Google Authenticator, Microsoft Authenticator, or 1Password.
* **Passkey** — Touch ID, Face ID, Windows Hello, or a hardware security key.
* **Email** — a 6-digit code sent to your email address.

You can enable more than one method, and you can switch between them when you sign in.

## Opening your security settings

1. Sign in to OpenReview.
2. Click your name in the top right corner and select **Password & Security**.
3. Expand the **Multi-Factor Authentication** section.

Each method is shown as a card that indicates whether it is currently enabled. If you have not set up any method yet, the page displays a notice that multi-factor authentication is disabled, and a similar reminder appears on your profile edit page.

<figure><img src="https://622636955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVorH499wd7ipUjYX5etp%2Fuploads%2FRsmphkrfO8ZR6r9Y12QA%2Fimage.png?alt=media&#x26;token=b7eba4de-7cc1-4acb-b20c-67e50c62e032" alt="The Multi-Factor Authentication panel with Authenticator App, Passkey and Email cards, and a notice that multi-factor authentication is currently disabled"><figcaption><p>The Multi-Factor Authentication section before any method has been set up.</p></figcaption></figure>

## Setting up an authenticator app

1. On the **Authenticator App** card, click **Set up**.
2. Scan the QR code with your authenticator app.
3. Enter the 6-digit code shown in your app and click **Verify**.

<figure><img src="https://622636955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVorH499wd7ipUjYX5etp%2Fuploads%2F8BhrG7Rg2jcc466JE4Kx%2Fimage.png?alt=media&#x26;token=d3640a37-0ed2-4d4c-b229-12bbbabbfba5" alt="The authenticator app setup panel showing a QR code, a field to enter the code from the authenticator app, and a Verify button"><figcaption><p>Scanning the QR code and confirming the first generated code enables the authenticator app.</p></figcaption></figure>

{% hint style="info" %}
The QR code is valid for 10 minutes. If setup expires before you finish, close the panel and click **Set up** again to generate a new code.
{% endhint %}

## Setting up a passkey

1. On the **Passkey** card, click **Set up**.
2. Enter a name that will help you recognise the device later, such as `Laptop Touch ID`. A name is required.
3. Click **Add Passkey** and complete the prompt shown by your browser or operating system.

You can register several passkeys — for example, one per device. To add or remove them later, click **Edit** on the Passkey card. Removing every passkey disables the passkey method.

## Setting up email codes

On the **Email** card, click **Enable**. The method is switched on immediately; there is no confirmation step.

{% hint style="warning" %}
When you sign in, the one-time code is sent to the email address you signed in with, which is not necessarily the preferred address on your profile. Make sure you can receive mail at the address you use to log in.
{% endhint %}

Each emailed code is valid for 10 minutes.

## Saving your recovery codes

The first time you enable any method, OpenReview generates **10 recovery codes** and displays them once. Use **Download** or **Copy to Clipboard** and store them somewhere safe — they are your last way into your account if you lose access to every other method.

Each recovery code can be used only once. The Recovery Codes card shows how many remain unused.

<figure><img src="https://622636955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVorH499wd7ipUjYX5etp%2Fuploads%2FYqaHiFujZv5OeIOKMEFo%2Fimage.png?alt=media&#x26;token=e552c1c5-14c1-43fb-9365-4a2ac2f42cb8" alt="Ten recovery codes listed above Download and Copy to Clipboard buttons, with a warning that the codes will not be shown again"><figcaption><p>Recovery codes are displayed once, when you enable your first method.</p></figcaption></figure>

{% hint style="danger" %}
Recovery codes are shown only once and cannot be retrieved later. Clicking **Generate New Code** issues a fresh set of 10 and invalidates every previously issued code, including unused ones.
{% endhint %}

## Choosing your preferred method

If you enable more than one method, click **Set as Preferred** on the card you want OpenReview to offer first when you sign in. You can still choose any of your other enabled methods at login.

<figure><img src="https://622636955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVorH499wd7ipUjYX5etp%2Fuploads%2FTo1GLQQlcLQ40CAWgwU9%2Fimage.png?alt=media&#x26;token=fe82a8ae-4864-4728-abcd-a4e1584470a3" alt="The Multi-Factor Authentication panel with Authenticator App and Email enabled, Passkey not set up, and a Recovery Codes card showing ten codes unused"><figcaption><p>Enabled methods are highlighted, and the Recovery Codes card tracks how many codes remain.</p></figcaption></figure>

## Signing in with multi-factor authentication

After you enter your username and password, OpenReview shows a verification step using your preferred method. On that screen you can:

* Enter the code from your authenticator app or email, or confirm with your passkey.
* Select **Log in using…** to switch to another method you have enabled.
* Select **Log in using Recovery Code** to use one of your recovery codes.
* Tick **Do not ask for a code on this device for the next 30 days** to skip verification on that browser in future.

<figure><img src="https://622636955-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVorH499wd7ipUjYX5etp%2Fuploads%2FdScIdDEVfbfeGCOIUmFX%2Fimage.png?alt=media&#x26;token=035ea0b4-ecfd-4c1b-af84-5418399ce87b" alt="The Two-Factor authentication login step with a six-digit code field, a checkbox to skip codes on the device for 30 days, and links to log in using Email OTP or a recovery code"><figcaption><p>The verification step shown after your password, with alternative methods listed below.</p></figcaption></figure>

## If you cannot sign in

After 5 consecutive incorrect codes, verification is locked for 15 minutes. Wait for the lockout to expire, then try again.

If you have lost access to your authenticator app, passkey, and email, sign in with one of your recovery codes and set up a new method straight away. If you no longer have your recovery codes either, contact OpenReview through the [Feedback Form](https://openreview.net/contact).

## Turning off a method

Open **Password & Security → Multi-Factor Authentication**, then:

* **Authenticator App** — click **Disable**, then confirm with **Disable Authenticator App**.
* **Email** — click **Disable**.
* **Passkey** — click **Edit** and delete the passkeys you no longer want. Removing the last one disables the method.

Disabling your last remaining method turns multi-factor authentication off for your profile.

{% hint style="info" %}
We strongly recommend keeping at least one method enabled. Author, reviewer, and program chair accounts control submissions and reviews, and a password on its own is a single point of failure.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.openreview.net/v1/getting-started/creating-an-openreview-profile/setting-up-multi-factor-authentication.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
