Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To add two-factor authentication (2FA), first identify your WordPress setup. On WordPress.com, turn on two-step authentication in your account’s Security settings. On a self-hosted WordPress site, install and configure a maintained 2FA plugin because WordPress core has no single, universal 2FA switch. In both cases, save the recovery codes before relying on the second factor.

Choose the instructions for your WordPress setup

Setup Where 2FA is configured What you need to know
WordPress.com Your WordPress.com account security settings Built-in options include authenticator apps, SMS, passkeys and physical security keys.
Self-hosted WordPress A 2FA plugin in the site’s WordPress dashboard Methods, menus, enforcement and recovery depend on the plugin and hosting environment.

Enable 2FA on WordPress.com with an authenticator app

WordPress.com’s support instructions, reviewed September 3, 2026, use the following path:

  1. Sign in to WordPress.com, open the account menu and select My WordPress.com account.
  2. Open Security → Two-Step Authentication.
  3. Select Set up using an app.
  4. Install an authenticator app, scan the displayed QR code (or enter the setup key manually), and type the six-digit code generated by the app.
  5. Select Enable.
  6. Save the displayed backup codes. WordPress.com may ask you to verify the setup with one of those codes.

Google Authenticator and Authy are examples named by WordPress.com, not requirements. The backup codes are single-use. You can copy, print or download them; store them somewhere you can reach if your phone is lost, replaced or unavailable. Generating a new set invalidates the previous set.

Use SMS, a passkey or a security key on WordPress.com

SMS

  1. From Security → Two-Step Authentication, choose Set up using SMS.
  2. Enter your phone number with its country code.
  3. Enter the verification code delivered by text and enable two-step authentication.
  4. Save the backup codes shown after setup.

SMS delivery and availability can depend on the number and service circumstances, so keep a recovery option that does not depend solely on that phone number.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Passkeys and physical security keys

WordPress.com lets you add passkeys (credentials stored on a device, browser or password manager) and physical USB security keys such as YubiKey after enabling app- or SMS-based two-step authentication. Its security-key guide describes these credentials as phishing resistant because they are tied to the site. Add a second passkey or key if you depend on one device. A key cannot be used to disable two-step authentication; you still need a code or backup code for that action.

Add 2FA to a self-hosted WordPress site

The WordPress Developer Handbook, updated September 29, 2026, directs self-hosted administrators to the WordPress.org plugin repository. It names Duo, Google Authenticator, Rublon, Two-Factor and WordFence as examples to investigate, not as a guarantee of current compatibility or an endorsement.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Before installing

  • Confirm that you have a current site backup and a tested way to regain administrator access.
  • Check the plugin’s recent maintenance, compatibility with your WordPress version, supported methods, role controls and documented recovery process.
  • Consider how the plugin will affect XML-RPC, REST, mobile apps, hosting panels or other integrations that authenticate separately.

Generic plugin setup

  1. Sign in with an administrator account and open Plugins in the WordPress dashboard.
  2. Search the WordPress.org repository or upload the plugin supplied by a trusted vendor, then install and activate it.
  3. Configure one test administrator first. For a time-based authenticator, scan the plugin’s QR code and enter a newly generated code to confirm pairing.
  4. Save the plugin’s recovery or backup codes and test a secondary login method before enforcing 2FA.
  5. After the test succeeds, enforce 2FA for administrators and other privileged roles as appropriate.
  6. Tell affected users how to enroll, where to store recovery codes and whom to contact if they lose a device.

Exact menu labels and enrollment screens vary. The WP 2FA directory listing reports support for TOTP authenticator codes, email codes, backup codes, passkeys and YubiKey hardware keys; verify the live listing and the plugin’s own documentation before relying on any feature.

Which second factor should you choose?

Method Where it applies Evaluate
Authenticator app (TOTP) WordPress.com and many self-hosted plugins Ease of moving to a new phone, backup or sync behavior, recovery codes and user familiarity.
SMS WordPress.com; plugin support varies Access to the number, delivery reliability and what happens when the number changes.
Passkey or physical security key WordPress.com; plugin support varies Browser and device compatibility, phishing resistance, spare credentials and plugin support.
Plugin enforcement controls Self-hosted WordPress Which roles must enroll, supported methods, maintenance, compatibility, recovery and integration impact.

You do not need to purchase a physical key to use an authenticator app. If you choose one, treat it as an optional device-based factor and confirm that your WordPress.com account or selected plugin supports it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Prevent lockouts and recover access

WordPress.com

  • Keep backup codes before changing phones or deleting an authenticator app.
  • When moving to a new device, use an unused backup code if WordPress.com requests one.
  • If codes are lost or exposed, generate a new set; the old codes then stop working.
  • If both the device and backup codes are unavailable, use WordPress.com’s account-recovery process.

WordPress.com Support warns: “Don’t skip this step — they’ll be your only way to log back into your account without staff assistance if you lose your device!”

Self-hosted WordPress

Recovery is plugin- and hosting-specific. Before enforcing 2FA for every user, read and test the plugin’s administrator reset or recovery procedure. Do not assume that disabling a plugin, editing the database or contacting a host is a universal solution; controls differ by plugin and host.

Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical rollout for teams

  1. Enable and test 2FA on a dedicated administrator account.
  2. Record the recovery procedure and store emergency credentials securely.
  3. Enroll additional administrators and editors with elevated privileges.
  4. Only then enforce 2FA broadly, allowing users time to enroll.
  5. Review inactive accounts, lost devices and recovery-code changes as part of normal access management.

WordPress.com Support says passkeys and security keys are more secure than codes alone because an attacker cannot sign in without the device or physical key, even when the password is known. That statement applies to WordPress.com’s sign-in implementation; support and behavior on self-hosted sites depend on the plugin.

Best Value
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.