X (Twitter) Account Verification: Two-Factor Authentication and Recovery
X supports SMS, authenticator apps, and security keys for two-factor authentication, plus backup codes. Learn the setup path and recovery options.

X (formerly Twitter) adds a second login credential beyond your password when you enable two-factor authentication (2FA). Its main listed methods are SMS, an authenticator app, and a physical security key. During setup, X may also ask you to confirm the email address linked to your account and provide a backup code.
Keep these concepts separate: email confirmation is used for account contact, security notices, and parts of the setup process; it is not one of the three standard 2FA methods X lists. The blue verification badge is unrelated to two-factor login.
X account verification methods compared
| Method | How it works at sign-in | Advantage | Consideration |
|---|---|---|---|
| SMS | Enter a code sent to your phone number | Easy to start with | Depends on your number and carrier |
| Authenticator app | Enter a time-based TOTP code | Works offline and is generally reliable | Migrate it before changing phones |
| Security key | Use a USB, NFC, or Bluetooth key | Strong phishing resistance | Keep a spare key if possible |
| Backup code | Enter a recovery code you saved earlier | Useful when a device is lost | Store it safely offline |
How do you enable two-factor authentication on X?
The settings path is broadly similar on Android, iPhone, and the web:
Settings and privacy → Security and account access → Security → Two-factor authentication
Choose SMS, an authentication app, or a security key. Enter your password again and follow the on-screen steps. If your account's email address has not been confirmed, X may first ask you to enter an address and verify a code sent by email.
Method 1: SMS codes
After selecting Text message, confirm your phone number and enter the code you receive. Save the backup code X displays when setup succeeds.
SMS is approachable, but number changes, roaming, delivery delays, SMS filtering, and SIM-swap attacks can interfere with it. For a valuable account, also configure an authenticator app or security key.
Method 2: Authenticator app
Choose Authentication app, then scan the QR code with a TOTP-compatible authenticator or enter the setup key manually. Enter the changing code generated by the app back into X to finish linking it.
The QR code and setup key are equivalent to the authenticator secret. Do not post screenshots of them or send them to anyone. Before changing phones, migrate the authenticator or confirm that your backup code works.
Method 3: Physical security key
A security key can authenticate through USB, NFC, or another supported connection. X says a security key can be the only 2FA method enabled for an account, but in practice you should still prepare a spare key and securely retain recovery codes.
The option to add one is under Manage security keys in the Two-factor authentication settings. Your browser and device must support the relevant standard.
What is a backup code for?
A backup code can help you sign in if your phone is lost, your number is unavailable, or you cannot reach your authenticator. When storing it:
- Use a trusted password manager or secure offline storage.
- Do not keep it in the same plain-text file as your password.
- Do not send it to a group chat or an account-management contractor.
- Generate a new one after use or if you suspect exposure.
What role does your linked email play?
X sends security notices to a confirmed email address and may require email confirmation before enabling 2FA. Give the email account its own strong password and two-step protection. If an attacker controls your email, they may be able to initiate a password reset.
The setting to require an email address and phone number when resetting your password protects password resets. It is not the same as login 2FA, and you can use both.
What if an X verification code does not arrive?
- Check whether you can select another configured 2FA method.
- Try your authenticator app or security key.
- Use the backup code you saved in advance.
- Confirm the phone number, country code, and carrier's SMS service.
- Avoid requesting many codes in quick succession.
- If you still cannot regain access, use X's official form for 2FA access problems.
Do not trust anyone who claims to remove 2FA through an internal channel or asks for your password or verification code.
What if your phone is lost or your number changes?
If you still have a signed-in device, add a new authentication method in Security settings first. Then remove the old phone number or lost key and review active sessions. Without a signed-in device, try your backup code and the official account-access recovery process.
Recommended setup
For most people: an authenticator app, a backup code, and a confirmed email address. For a high-risk account: make a physical security key your primary method, keep a second key in another location, and retain a reliable email address and backup code.
Frequently asked questions
Is an X email code two-factor authentication?
Email may be used to confirm an account or set up security features, but X lists SMS, authenticator apps, and security keys as its standard 2FA methods.
Are Twitter and X the same account system?
Yes. The brand is now X, although older material may still say Twitter.
Will I need a code on every sign-in after enabling 2FA?
A new device or a session that needs reverification will generally require a second factor. The exact prompt depends on the device, session, and risk assessment.
What if I lose my backup code?
If you can still sign in, generate a new code immediately in Two-factor authentication settings. This invalidates the old code.
Summary
X's three core 2FA methods are SMS, authenticator apps, and security keys. An authenticator or security key is better suited as a primary method than SMS alone. Whatever you choose, secure your email account and store a backup code offline.