Set up two-factor authentication
ON THIS PAGE
SleeveFolio uses TOTP: the standard 6-digit codes from an authenticator app (1Password, Google Authenticator, Authy, and friends). 2FA protects every sign-in once enrolled, and it’s one of the two safety checks the Paper → Live gate requires.
- Scan the QR code
Open Settings → Account and start enrollment on the two-factor card. A QR code appears. Scan it with your authenticator app (or type the setup key in manually).
- Verify a code
Type the 6-digit code your app shows. This confirms your app was set up correctly before 2FA is switched on.
- Store your recovery codes
Ten one-time recovery codes appear, once. Download or copy them somewhere safe. They’re your way in if the authenticator device is lost. Details in Recovery codes.
What changes after enrollment
- Every sign-in (magic link, Google, GitHub) is challenged for a code before you’re signed in
- Sensitive actions — enabling live trading, saving or disconnecting broker keys, and deleting your account — require that your signed-in session has passed 2FA before they go through. The check happens on SleeveFolio’s side, so it can’t be skipped. Winding down is the exception: pausing, liquidating, or reverting to paper is never gated, so you can always get out of live
- The gate’s 2FA check turns green
Disabling 2FA
Turning 2FA off requires your current authenticator code (re-entering it is the re-authentication), and it immediately fails the live-trading gate. If you’re live, live trading is suspended until you re-enroll: the account stays marked LIVE, but new live orders are blocked.