Short answer: Bluesky's two-factor authentication is email-based. Turn it on in Settings → Privacy and security → Two-factor authentication, and every new sign-in will ask for a one-time code sent to your verified email. As of October 2026 there's no authenticator-app or passkey option on bsky.social.
Below: how to turn it on, what the code protects against, the app password gap most guides skip, and how to keep your account safe if you lose access to your email.
On this page:
- The direct answer
- How to turn on Bluesky 2FA
- How Bluesky 2FA works
- Does Bluesky support authenticator apps or passkeys?
- What 2FA doesn't protect
- If you lose access to your email
- A five-minute security checklist
- FAQ
The Direct Answer
| Question | Answer |
|---|---|
| Does Bluesky have 2FA? | Yes – email sign-in codes |
| Where do I turn it on? | Settings → Privacy and security → Two-factor authentication |
| Authenticator app (TOTP)? | No, as of October 2026, for bsky.social accounts |
| Passkeys or security keys? | No, as of October 2026 |
| Does it apply to app passwords? | No – app passwords sign in without the code |
| Will it log out my current devices? | No – it applies to new sign-ins |
How to Turn On Bluesky 2FA
It takes about a minute in the iPhone, Android or web app:
- Make sure your email is verified: in Settings → Account, confirm the email shows as verified, or follow the prompt to verify it.
- Go to Settings → Privacy and security.
- Under Two-factor authentication, turn on Require email code to log into your account.
- Enter the confirmation code Bluesky emails you to finish turning it on.
- Sign out and back in on one device to confirm the code arrives.
From then on, whenever you sign in with your main password on a new device or browser, Bluesky emails a code. Type it in and you're in. Devices that are already signed in stay signed in.
To turn it off, go back to the same screen and switch the toggle off. Bluesky asks you to confirm with an email code, which stops someone who only has your password from quietly disabling it.
How Bluesky 2FA Works
Normally, signing in takes one thing: your password. With 2FA on, it takes two: your password and proof that you control your email inbox. Someone who guesses, phishes or finds your password in a leaked database still can't get in without the code.
That makes email 2FA a strong defense against the most common way social accounts get taken over: reused passwords. If you used the same password on a site that was breached, attackers will try it on Bluesky. With 2FA on, that attempt stops at the code screen.
Why email and not SMS?
Bluesky doesn't use text messages for 2FA. That avoids SIM-swap attacks, where someone convinces your carrier to move your number to their phone. The trade-off is that your Bluesky account is now only as secure as your email account – more on that below.
Does Bluesky Support Authenticator Apps or Passkeys?
As of October 2026, no, not for accounts hosted by Bluesky. You can't scan a QR code into Google Authenticator, 1Password or Authy, and you can't sign in with a passkey or a YubiKey. Requests for these exist on Bluesky's public issue tracker, but they haven't shipped.
Some independently run servers (PDSes) on the AT Protocol network have added authenticator-app codes for their own users. If your account lives on one of those, check its documentation. Moving hosts just for this is a big step; read our guide to moving a Bluesky account to another PDS before considering it.
Be wary of websites that claim to walk you through setting up Bluesky with an authenticator app. If the option isn't in your Privacy and security settings, it doesn't exist for your account.
What 2FA Doesn't Protect
Email codes close the biggest hole, but not every hole.
App passwords skip the code
Third-party apps that sign in with an app password don't ask for the email code. That's intentional – a bot can't read your inbox – but it means every app password is a key that works without a second factor. Review your app passwords and delete any you don't recognize or no longer use.
Devices already signed in
2FA protects sign-ins. It doesn't kick out a session that already exists. If you think someone else is signed in to your account, change your password and delete every app password you didn't create.
Phishing for the code
A convincing fake login page can ask for your password and your code, then use both immediately. Only enter your code on bsky.app or in an app you trust, and be suspicious of DMs or emails that link to a "Bluesky login" page. Prefer apps that use OAuth sign-in, which sends you to your account's real login page.
Your email account itself
If someone gets into your email, they can receive your Bluesky codes and reset your Bluesky password. Your email account deserves the strongest protection you have: a unique password and an authenticator app or passkey on it.
What's public anyway
2FA protects control of your account, not the visibility of your data. Your posts, likes, follows and blocks are public whether or not 2FA is on. See can you make a Bluesky account private? and are Bluesky likes public?
If You Lose Access to Your Email
Because the code goes to your email, losing the inbox can lock you out. Plan for it before it happens:
- Keep your email current. If you're leaving a work or school address, change your Bluesky email in Settings → Account while you can still receive codes.
- Stay signed in on one device. An existing session lets you change your email or turn off 2FA without signing in again.
- Keep a backup of your data. A recent backup won't get you back in, but it means you don't lose your posts and follower list if the worst happens. Skyscraper's free Account Backups tool works for any public account; our backup guide explains the options.
If you're already locked out, contact Bluesky support from the help pages and explain the situation. Recovery isn't guaranteed, which is why the steps above matter.
A Five-Minute Bluesky Security Checklist
- Use a unique password from a password manager.
- Turn on email 2FA using the steps above.
- Secure your email with its own 2FA, ideally an authenticator app or passkey.
- Audit your app passwords and delete the ones you can't name.
- Prefer OAuth when a third-party app offers it.
- Consider a custom domain handle, which makes impersonation harder.
Frequently Asked Questions
Does Bluesky have two-factor authentication?
Yes. Bluesky offers email-based two-factor authentication. When it's on, every new sign-in with your main password asks for a one-time code sent to your verified email address.
How do I turn on 2FA on Bluesky?
Verify your email, then go to Settings, Privacy and security, and turn on Require email code to log into your account under Two-factor authentication. Enter the code Bluesky emails you to confirm.
Can I use Google Authenticator or a passkey with Bluesky?
Not for accounts hosted by Bluesky, as of October 2026. Bluesky's 2FA only sends codes by email. A few independent PDS servers offer authenticator codes for their own users.
Do app passwords need the 2FA code?
No. Signing in with an app password skips the email code, so bots and third-party tools keep working. That makes each app password sensitive; delete the ones you don't use.
Will turning on Bluesky 2FA sign me out?
No. Devices that are already signed in stay signed in. The code is required the next time you sign in with your main password on a new device or browser.
What happens if I lose access to my email with 2FA on?
You may be unable to sign in on new devices. Change your email from a device that's still signed in, or contact Bluesky support. Keep your email address current to avoid this.
Signing In to Skyscraper Securely
Skyscraper signs in with OAuth using DPoP-bound tokens, so your password is entered on your account's own login page, not in the app. If you prefer, you can use an app password instead. Accounts are stored in the Keychain, and multiple accounts are supported, including accounts on an alternate PDS such as Eurosky.