Two-factor authentication adds a 6-digit code from an authenticator app to your login. It applies the same way whether you sign in with a password or with Google — and works with any standard authenticator app (Google Authenticator, Authy, 1Password, and similar), since they all implement the same underlying standard.
Setup is two steps: scan a QR code with your authenticator app, or enter the code shown next to it manually if your app can't scan images. Then enter the 6-digit code your app just generated to confirm it's working. Scanning the QR code alone doesn't turn 2FA on — it's only enabled once you've entered a code that actually verifies, proving your app is generating the right codes before your account starts requiring them.
There's no separate "re-scan" option once 2FA is on — the same switch that turned it on now turns it off, and turning it off clears every trusted device too (see below). If you need to move your authenticator to a new phone, turn 2FA off and set it up again from scratch on the new phone — but do this while you can still log in with your current authenticator or a trusted device. There are no backup codes and no self-service recovery: if you lose access to your authenticator and don't have a trusted device left, you won't be able to turn 2FA off yourself to get back in.
When you're asked for a 2FA code at login, there's a "Remember this device" checkbox. Check it, and that browser won't be asked for a code again for 30 days — login completes without the code step, whether you're signing in with a password or with Google. You can have more than one device remembered at a time; checking the box on your laptop doesn't affect whether your phone still asks for a code.
At login, entering the wrong code five times within 30 minutes locks out further attempts temporarily — it clears on its own after the 30 minutes passes. This limit only applies at login; it doesn't apply while you're first setting 2FA up.
There's no way to remove one remembered device at a time — clearing trusted devices forgets all of them at once, including the browser you're using when you click it. Every device will be asked for a 2FA code again the next time it logs in.
This affects the next login on each device — it doesn't sign anyone out of a session that's already open right now. If you think someone else is currently signed in to your account, changing your password stops them from getting back in — or, if you sign in with Google rather than a password, securing your Google account does the same job — but neither one ends a session they already have open. Afterward, check the Security page to confirm two-factor authentication is still switched on, since someone with an open session can turn it off without needing your password.
Disabling two-factor authentication doesn't just stop asking for codes going forward — it clears every trusted device in the same step, so you don't need to separately remember to do that afterward.
Turning it off only requires an active logged-in session — it doesn't ask for your password or a 2FA code again first. Anyone who's already logged into your session can disable 2FA without knowing your password.