AddThisFeature

Two-Factor Authentication

A password alone isn't enough for accounts that matter.

involved Security & Reliability

What it adds

TOTP-based 2FA with recovery codes.

What your agent is told to do

4
  1. 1

    Use TOTP (authenticator apps). SMS is better than nothing but is defeated by SIM swapping — don't make it the only option.

  2. 2

    Generate single-use recovery codes at setup and make the user save them. This is the difference between a locked account and a support ticket.

  3. 3

    Require the current password before enabling or disabling 2FA.

  4. 4

    Verify a code during setup before you turn it on — otherwise a misconfigured app locks the user out instantly.

Edge cases it handles

6
  • Accept a small time window (±1 period) for clock drift, but no more.
  • A used TOTP code must not be replayable within its window.
  • Recovery codes must be single-use, hashed at rest, and regenerable.
  • Enabling 2FA should invalidate other active sessions.
  • Rate-limit code attempts — six digits is brute-forceable otherwise.
  • Don't lock a user out permanently; define the account recovery path before you ship.

Definition of done

8
  • TOTP setup verifies a code before enabling.
  • Recovery codes are generated, hashed, single-use, and regenerable.
  • The current password is required to enable or disable.
  • Code attempts are rate-limited and codes can't be replayed.
  • Clock drift is tolerated within one period.
  • A documented account recovery path exists.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.