Use this guide to turn on authenticator-based two-factor authentication, add a passkey to an existing account, and keep a recovery route available if you lose a device.
Open the account settings on the site where you registered to follow these instructions. Available sign-in methods depend on that site's configuration. If you use a separate built-in administrator account and do not have these account settings, ask your site administrator which security controls apply.
Choose the protection you want
Authenticator MFA adds a second verification step when Cedros requests it during sign-in. Your authenticator app generates a changing six-digit code. The interface calls this Two-factor authentication or 2FA. Setup also gives you recovery codes for times when the app is unavailable.
A passkey lets you sign in using a credential stored on your device, in a password manager, or on a compatible security key. Your browser asks you to approve its use, for example with a device PIN, fingerprint, or face recognition. A passkey does not require you to enter your Cedros password on every sign-in.
You can have both. Adding a passkey does not turn off existing MFA; complete any additional authentication challenge Cedros shows. A passkey and an MFA recovery code serve different purposes: the recovery code replaces an authenticator code at the MFA challenge, not the initial sign-in method.
Already locked out? Start with Resetting your password and recovering access.
Before you start
Keep your current signed-in window open until you have confirmed your new method works.
- Use the correct site's address and account. An account on one Cedros-powered site is not automatically an account on another.
- For MFA, have an authenticator app ready and somewhere private to save recovery codes that you can access without the authenticator device.
- For a passkey, use a browser and device that support passkeys, open the site over HTTPS, and have access to the device or password manager where you intend to save it.
- Make sure you can still use an existing sign-in method. Adding protection is easier while you can already access your account.
Open the site's profile page, normally /profile. For your account on cedros.ai, open Manage your account. If you see Log in to manage account, sign in first and then return to the profile page.
Use Security for MFA and recovery codes. Use Connected accounts for passkeys.
Turn on authenticator MFA
1. Connect your authenticator
In Security, find Two-factor authentication and select Enable two-factor authentication.
On Scan QR code, add a new account in your authenticator app and scan the displayed QR code. If you cannot scan it, use Or enter this code manually to copy the setup secret into the app instead. Then select Continue.
Keep the QR code and manual setup secret private. Anyone with the secret can generate the same authenticator codes. Do not include either in a support message or screenshot.
2. Save your recovery codes
On Save recovery codes, select Copy all codes and store them somewhere secure that you can reach if your authenticator device is lost. A copy kept only on that device will not help if you lose access to it.
Each recovery code can be used once. The setup screen is your opportunity to save the codes; the account settings later show how many remain, not a list you can reopen.
After saving them, select I have saved these recovery codes, then Continue. Do not tick the checkbox until you have actually saved an accessible copy.
3. Verify and confirm
On Verify setup, enter the current six-digit code from the new authenticator entry. Completing the code can submit it automatically; if it has not submitted, select Enable 2FA.
Wait for the setup to finish, then check that Two-factor authentication shows Enabled and a count of recovery codes remaining. Scanning the QR code alone does not enable MFA.
If the code is rejected, wait for a fresh code and try again. Check the troubleshooting section below before repeatedly retrying.
4. Check a fresh sign-in
Keep your existing window open. In a separate private browser window, open the same site's sign-in page and use your usual sign-in method.
If Cedros shows Two-factor authentication, enter a fresh code from your authenticator app. Confirm that you reach the expected account. Close the private window when you are done.
Use an authenticator code for this check so you do not unnecessarily consume a recovery code.
Add a passkey to your existing account
- Open your profile on the correct site and choose Connected accounts.
- Under Link a new sign-in method, select Passkey, if it is available. Stay signed in to the account you want to protect; do not start a new-account registration flow.
- Follow the browser or device prompt. Choose where to save the passkey and approve creation using the method your device offers.
- Wait for Cedros to finish and confirm that the new passkey appears in Connected accounts. Dismissing the device prompt does not complete registration.
- Keep your existing session open and test in a separate private window. On the same site's sign-in page, choose Continue with passkey, if offered. Select the saved credential, approve the device prompt, and complete any MFA challenge. Confirm that you reach the same account.
If the Passkey button is missing: check whether a passkey is already listed. You can add a passkey only when none is already linked. Browser support and the site's authentication configuration also affect availability. If the sign-in page does not offer passkeys, retain your working method and ask the site administrator whether passkey sign-in is available.
Where a passkey is stored determines where you can use it. Before changing phones, computers, or password managers, check your provider's transfer or sync arrangements and test access on the replacement device. Do not assume a passkey will automatically appear on every device.
Manage recovery codes
Use a recovery code to sign in
At the Two-factor authentication challenge, select Use a recovery code, enter one unused recovery code, and select Verify. Use Use authenticator app to return to the regular code entry.
After a successful recovery-code sign-in, mark that code as used in your saved copy. It cannot be reused. If you lost the authenticator itself, regain a working authenticator setup before relying on recovery codes for everyday access.
Replace your recovery codes
Regenerate your codes if you no longer have a private copy or are running low. This requires a working authenticator code; it is not a way around a lost authenticator.
- Open Security and find Two-factor authentication.
- Select Regenerate recovery codes.
- Enter a fresh six-digit authenticator code. If the form has not submitted automatically, select Regenerate codes.
- On New recovery codes, select Copy all codes, save the new set securely, and select Done.
All previous recovery codes stop working when the new set is generated. Replace your stored copy and discard the old one. Generating new recovery codes does not transfer your authenticator to a new device.
Replace or remove a security method
Move to a new authenticator
If your authenticator app supports transferring an account, follow that app's instructions and test a fresh Cedros sign-in on the new device before erasing the old one.
If you need to set up a new authenticator from scratch, keep access to your account and a usable verification factor. Turn off the existing MFA setup using the steps below, then enable it again with the new app. Save the new recovery codes and confirm Enabled before finishing. MFA is off between those two actions.
Turn off MFA
Open Security, select Disable 2FA, and complete one of the verification methods the form offers. On Cedros Login sites, this may be an authenticator code or an unused recovery code; use Use recovery code or Use authenticator code to switch when shown. Follow a password prompt only if your site's form offers it.
Select Disable 2FA to confirm, then check that the status is Disabled. If you are replacing your authenticator, immediately complete a fresh setup. Do not delete the old authenticator entry before Cedros confirms the change.
If you cannot complete any offered verification method, use the account recovery guide. A password reset does not remove MFA.
Remove a passkey
First confirm that another sign-in method works for this same account. Then open Connected accounts, select Remove beside the passkey you want to remove, and confirm Remove in the dialog.
Check that the passkey no longer appears. Cedros prevents removal of your last login method; add and test another method first if you see that error. MFA itself is managed through Security, not the passkey's removal control.
Removing a passkey from Cedros does not necessarily remove its saved entry from your device or password manager. Follow that provider's controls if you also want to clean up the saved entry.
Troubleshooting
An authenticator code is rejected
Check that you selected the entry for the correct site and account. Use a newly generated code rather than one you already submitted, and check that your device's date and time are set correctly. Codes change quickly; wait for the next one if the current code is about to expire.
If a fresh code still fails, use an unused recovery code at the sign-in challenge. Stop repeated guesses if you see a rate-limit message, and follow the instructions shown.
A security change asks you to sign in again
Sensitive changes can require recent authentication even while your profile is open. Sign in again to the same account and retry. Before signing out of your only working session, confirm you have the sign-in method and any required authenticator or recovery code available.
If you cannot meet that requirement, leave the working session open and follow the recovery guide.
The passkey prompt closes or no credential is found
An interrupted or cancelled prompt does not establish a successful registration or sign-in. Retry on the correct site using the device or password manager where you saved the passkey. If the browser reports that passkeys are unsupported, use a supported browser or another existing sign-in method.
Do not create a replacement account to work around a missing passkey. If another method gets you into the original account, manage its passkey from Connected accounts.
You lost the authenticator, passkey, or all recovery codes
Follow Resetting your password and recovering access for the route that matches what you still have. If no working method remains, contact the site administrator or get help.
Include the site address, the step that fails, and the error text. Never send a password, authenticator secret, QR code, recovery code, or sign-in link.