Search docs

Search the documentation

Dashboard
For LLMs

Account security (2FA)

FlashProxy supports two-factor authentication (2FA) with an authenticator app. With 2FA enabled, signing in takes your password plus a 6-digit code from your phone — so a stolen password alone can't access your account, your balance, or your proxies.

2FA is optional and free. It applies to password sign-in: if you log in with Google or GitHub, your provider's own two-step verification protects your sign-in instead, and the 2FA option is not shown.

Enabling 2FA

  1. Go to Settings → Security in the dashboard.
  2. In the Two-factor authentication card, click Enable 2FA and confirm your password.
  3. Scan the QR code with any authenticator app — Google Authenticator, Authy, 1Password, Microsoft Authenticator all work. On a laptop, you can instead copy the manual setup key and paste it into your app.
  4. Enter the 6-digit code your app shows to confirm.

You'll then see your backup codes — save them before leaving the page (see below).

Backup codes

When you enable 2FA you receive 10 one-time backup codes. Each code can be used once in place of an authenticator code if you lose access to your phone.

  • They are shown only once. Copy or download them at that moment and store them somewhere safe (a password manager is ideal). They cannot be viewed again later.
  • The Security card shows how many you have left, and Regenerate issues a fresh set of 10 at any time. Regenerating invalidates all previous codes.
  • If you run low (or hit zero), regenerate — the card will warn you.

Signing in with 2FA

After entering your password you'll be asked for the 6-digit code from your authenticator app.

Lost your phone? Choose the backup-code option on the sign-in screen and enter one of your saved backup codes. Each code works once — after you're in, consider regenerating a fresh set in Settings. A security notification email is sent whenever a backup code is used.

Disabling 2FA

In Settings → Security, click Disable, then confirm your password and a current authenticator code. Your enrolled authenticator and any remaining backup codes are removed immediately. You can re-enable at any time — re-enrolling generates a new QR code and secret, so delete the old FlashProxy entry from your authenticator app first.