OpenAI

Managing multi-factor authentication (MFA)

Learn how to turn multi-factor authentication on or off and use the sign-in methods available for your OpenAI account.

Updated: 8 hours ago

Overview

Multi-factor authentication (MFA) adds an extra verification step when you sign in. When enabled, it applies across OpenAI services, including ChatGPT and the API Platform.

Availability

Your available MFA options may vary depending on your device, country, account tier, and how your account was created. OpenAI is working to make more options available over time.

How MFA works

When MFA is enabled, you may be asked to verify your identity using a second method during sign-in. You can choose from available verification options, including:

  • Authenticator app: Use one-time codes from an app such as Google Authenticator or Authy.

  • Push notifications: Approve sign-ins by responding to a prompt sent to your trusted device.

  • Text message: Receive a 6-digit code by SMS or WhatsApp.

  • Passkey: Use a passkey as an additional form of MFA for your account.

For more information about passkeys, see: Passkeys to secure your OpenAI account.

Some passkeys can be stored on a compatible hardware security key. If you want to use a hardware security key and do not already have one, eligible OpenAI users can learn about the OpenAI + Yubico YubiKey bundle, available at preferred pricing. To learn more, see: OpenAI + Yubico YubiKey bundle.

Turn MFA on or off

You can manage MFA from ChatGPT or the API Platform.

In ChatGPT:

  1. Go to ChatGPT settings.

  2. Select Security and login.

  3. Under Multi-factor authentication (MFA), select the verification method you want to turn on or manage, then follow the setup or removal instructions.

Complete MFA setup

Some MFA methods require additional setup. Depending on the method, you may be asked to:

  • Scan a QR code with your authenticator app and enter a one-time code.

  • Receive a code by SMS or WhatsApp and enter it to confirm.

  • Enter your phone number before enabling SMS or WhatsApp.

After setup, MFA will be active the next time you sign in.

If you have multiple MFA methods enabled, OpenAI defaults to the most secure option first. You can still choose any enabled method when signing in.

Recover access if you lose your MFA method

Email is not available as a standard MFA method. To sign in, you must use an MFA method configured for your account. If you have another configured method available, select it when prompted.

If you cannot access any of your configured MFA methods, contact OpenAI Support. You must complete a verification process, which can take a few days.

After successful verification, Support will provide a one-time email recovery login. This is a temporary recovery option, not an ongoing email MFA method.

After signing in with the recovery option, you must add a backup MFA method you can access or disable MFA in Settings > Security and login.

This recovery option is available only once. After the one-time recovery has been used, it will not be available again if you lose access to your MFA method.

If you enrolled in Advanced Account Security and lost access to your passkeys or security keys, use your recovery key to regain access.

FAQ

Use these answers for common MFA account questions.

Does enabling MFA log you out of other devices?

No. Enabling MFA does not automatically log you out of other devices or sessions.

To manually log out of all active sessions:

  1. Go to ChatGPT settings.

  2. Select Security and login.

  3. Select Log out of all devices.

It may take up to 30 minutes for all sessions to be logged out.

Can admins enforce MFA for a workspace or organization?

Not at this time. MFA cannot currently be enforced at the ChatGPT workspace or API Platform organization level.

Was this article helpful?