---
title: Two-step verification
description: Protect your Lexpoint account with an authenticator app, so access to your email inbox alone is not enough to sign in.
product: Lexpoint — Individuals
audience: People managing their own Canadian immigration
doc_type: guide
canonical_url: https://docs.lexpoint.io/individuals/account/two-step-verification/
app_routes: https://my.lexpoint.io/app/settings/account
requires: A phone or computer with an authenticator app installed
last_verified: 2026-09-03
keywords: two-factor authentication, 2FA Lexpoint, authenticator app, MFA, account security
license: Documentation © Lexpoint. Quote with attribution and a link to the canonical URL.
---
# Two-step verification

Two-step verification adds a second check when you sign in. After you sign in with Google or a magic
link, Lexpoint asks for a six-digit code from an authenticator app on your device.

This matters more on Lexpoint than on a site with passwords. Lexpoint has **no password** — you sign
in with your Google account or with a link sent to your email. That means whoever can read your
email can sign in as you. Two-step verification breaks that chain: the code lives on your device,
not in your inbox.

Lexpoint uses **authenticator apps only** — never text messages. A code generated on your device
cannot be intercepted by someone who takes over your phone number.

## Before you start

Install an authenticator app if you do not have one. Any of these work:

- Google Authenticator
- Microsoft Authenticator
- 1Password, Bitwarden, or another password manager with a built-in authenticator
- Authy

## Turn it on

1. Go to [**Settings → Account**](https://my.lexpoint.io/app/settings/account).
2. Open the **Sign-in & security** tab.
3. Find **Two-factor authentication** and start the setup.
4. A QR code appears. Open your authenticator app and scan it — point the app's camera at the code.
5. Your app now shows a six-digit code for Lexpoint that changes every 30 seconds. Enter the current
   code to confirm the pairing.

Once confirmed, the section reads *Your account is protected with an authenticator app.*

```media
id: account-2fa-setup
type: screenshot
caption: The two-factor authentication panel during setup, showing the QR code to scan.
shot: /app/settings/account → "Sign-in & security" tab → two-factor setup started, QR code visible. Demo account, light mode, 1440×900. Blur the QR code itself.
src: /media/individuals/account-2fa-setup.webp
```

:::caution[Save a copy before you finish]
If your authenticator app supports backup — a password manager that syncs, or an export — set that
up now. If the only copy of your authenticator lives on a phone you might lose, recovery means
contacting support and proving who you are.
:::

## Signing in from then on

Your next sign-in has one extra step. Sign in as usual — Google, or the magic link sent to your
email — and then enter the six-digit code from your authenticator app.

The code is generated on your device and changes every 30 seconds. If it is rejected, the usual
cause is a clock that has drifted — check that automatic date and time is enabled on the device
running the authenticator.

```media
id: account-2fa-challenge
type: screenshot
caption: The sign-in challenge asking for a code from your authenticator app.
shot: /auth/mfa-challenge — the six-digit code entry screen. Light mode, 1440×900. Empty boxes; no account identity on this page.
src: /media/individuals/account-2fa-challenge.webp
```

## Turning it off

Two-step verification can be switched off from the same panel in **Settings → Account →
Sign-in & security**. You will be asked to confirm.

Think carefully first. Because Lexpoint has no password, turning two-step verification off leaves
**your email inbox as the only thing** protecting an account that holds your identity documents and
immigration history. Anyone who can read your email can request a magic link and sign in.

If your reason is that the extra step is inconvenient, moving your authenticator into a password
manager solves the inconvenience without giving up the protection.

## Related

- [Sign-in methods](/individuals/account/sign-in-methods/) — Google and magic-link sign-in
- [Identity verification](/individuals/account/identity-verification/) — a different thing: proving who you are, not securing sign-in
- [Access and sharing](/individuals/account/access-and-sharing/) — who else can see your file

## Frequently asked questions

### Does Lexpoint send two-step codes by SMS?

No. Two-step verification uses an authenticator app that generates a code on your device. Codes are never sent by text message, so a hijacked phone number cannot be used to sign in as you.

### What happens if I lose the phone with my authenticator app?

Contact Lexpoint support through Help and Support. Identity is confirmed before two-step verification is reset — this is deliberate, because an easy reset would defeat the protection.

### Is two-step verification required?

It is not required, but it is strongly recommended. Lexpoint has no password — sign-in is by Google or a magic link sent to your email — so without two-step verification, anyone who can read your email can sign in to an account holding your identity documents, immigration history, and case files.
