What you'll do
Add 2FA or a passkey from Account Security, save a recovery method, and understand the manual recovery path.
Set up 2FA
- Open Account → Security and choose Enable two-factor authentication.
- Scan the QR code with a TOTP authenticator such as Google Authenticator, Authy, 1Password, or Bitwarden.
- Enter the current six-digit authenticator code.
- Save the 10 one-time recovery codes somewhere separate from your phone.
- Confirm that the recovery codes are saved, then enable 2FA.
On the email-code sign-in path, the sequence becomes email address → email code → authenticator code. A registered passkey can complete sign-in directly through its own device or password-manager prompt.
Enter login and authenticator codes only on ezformz.net. EZFormz staff will never ask for a login code, authenticator code, recovery code, QR setup secret, or manual TOTP secret. Store recovery codes securely and separate from the enrolled device.
Add a passkey
- In Account → Security → Passkeys, choose Add a passkey.
- Approve the browser prompt with your device, password manager, or hardware key.
- Give the passkey a recognizable name.
A passkey stored in a syncing password manager can work across the devices connected to that manager. A second passkey or 2FA plus recovery codes provides a backup.
Passkeys may also be device-bound. A hardware key, a passkey stored in another password manager, or 2FA plus saved recovery codes avoids depending on one device or one sync account. The login page lets the browser offer any passkey registered for EZFormz.
Passkeys are phishing-resistant because the browser checks the relying-party domain before creating a valid signature. That does not make every approval prompt safe: begin from ezformz.net, confirm that you intended the sign-in, and do not approve an unexpected prompt.
Use more than one recovery path
A practical setup is one passkey in a trusted syncing password manager, 2FA in an authenticator app, and recovery codes stored separately. Another hardware or device-bound passkey can be a useful backup but is not required.
EZFormz sends security notices when 2FA is enabled or disabled and when a passkey is added or removed. The notices include event context such as the time and request IP. Treat an unexpected notice as an account-security incident; securing only EZFormz is not enough if the account email or password manager is also compromised.
Recover access
Try another registered passkey first. At the 2FA prompt, you can instead use one unused recovery code.
If every passkey, authenticator, and recovery code is unavailable, submit a support ticket with the subject 2FA Account Recovery. EZFormz does not offer email-only 2FA reset. An admin must verify at least two ownership signals before an approved reset.
Do not send the answers or supporting account details until support asks for the specific evidence through the ticket. Never send a live login code, authenticator code, recovery code, QR setup secret, or passkey prompt as evidence.