> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# Two-factor authentication and recovery codes

> Turn on two-factor sign-in with an authenticator app, save your recovery codes, sign in with a code, make new codes or turn it off.

<Badge color="gray">Everyone</Badge>

Two-factor authentication adds a second step when you sign in: a six-digit code from an authenticator app on your phone. Someone who learns your password still cannot get in without that code.

## Before you start

* You need an authenticator app on your phone. Any app that makes six-digit sign-in codes works.
* You need a safe place for 10 recovery codes, away from your phone. A password manager or a sheet of paper works.
* Two-factor belongs to you, not to a workspace. It protects every workspace you belong to.

## Turn on two-factor

<Steps>
  <Step title="Open your security settings">
    In OnlyX, click **Settings**. Then click **Security**. On a phone, **Settings** is under **More**.
  </Step>

  <Step title="Start the setup">
    In the **Two-factor authentication** card, click **Turn on two-factor**.

    The **Turn on two-factor** window opens with a QR code.
  </Step>

  <Step title="Scan the QR code with your app">
    In your authenticator app, add a new account and scan the QR code. The app adds OnlyX with your email address and shows a new six-digit code every 30 seconds.

    If you cannot scan it, for example because the app is on this same phone, click **Can't scan it?**. Then type the key it shows into your app.
  </Step>

  <Step title="Enter the code from your app">
    In **Code from your app**, enter the six digits your app shows now. Then click **Confirm and continue**.

    OnlyX shows "Two-factor is on", and the window changes to **Save your recovery codes**.

    <Frame caption="**1** Scan this with your authenticator app · **2** The code your app shows now · **3** Confirm and continue">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/turn-on-window-light.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=e37572694d7a31fa011ca6162b3ed380" alt="The Turn on two-factor window with a blurred QR code, a six-digit code typed in Code from your app, and the Confirm and continue button" width="1440" height="1280" data-path="images/help/account/two-factor-authentication/turn-on-window-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/turn-on-window-dark.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=323ef4caf6afdf13ce05f4170a5347b5" alt="The Turn on two-factor window with a blurred QR code, a six-digit code typed in Code from your app, and the Confirm and continue button" width="1440" height="1280" data-path="images/help/account/two-factor-authentication/turn-on-window-dark.png" />
    </Frame>
  </Step>

  <Step title="Save your recovery codes">
    Click **Copy all**, then paste the 10 codes into a safe place. You can also write them down. Keep them away from your phone.

    <Frame caption="**1** Copy all · **2** Tick this after you saved the codes · **3** Done">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/recovery-codes-light.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=10fc2c6830e7d2535809e8fa8c80d9de" alt="The Save your recovery codes window with the ten codes blurred, the Copy all button, the tick box and the Done button" width="1440" height="1096" data-path="images/help/account/two-factor-authentication/recovery-codes-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/recovery-codes-dark.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=04cdaba7f272699f9ca8a9cdd2456694" alt="The Save your recovery codes window with the ten codes blurred, the Copy all button, the tick box and the Done button" width="1440" height="1096" data-path="images/help/account/two-factor-authentication/recovery-codes-dark.png" />
    </Frame>
  </Step>

  <Step title="Finish the setup">
    Tick **I have saved these somewhere safe**. Then click **Done**.

    The card shows **On**, the date, and "10 recovery codes left". OnlyX also emails you "Two-factor authentication is on".
  </Step>
</Steps>

<Warning>
  OnlyX shows your recovery codes only once and cannot show them again. Each code works one time. They are your only way back in if you lose your phone.
</Warning>

If you close the window before you enter a code, two-factor stays off. When you start again, OnlyX makes a new QR code. Remove the old OnlyX entry from your app and scan the new one.

## Sign in with a code

<Steps>
  <Step title="Enter your email and password">
    On the sign-in page, enter your email address and your password. Then click **Sign in**.

    The **Authenticator code** step opens.
  </Step>

  <Step title="Enter the code from your app">
    In **Code**, enter the six digits your app shows now. Then click **Sign in**.

    <Frame caption="**1** The code from your app · **2** Use a recovery code, if you do not have your phone">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/sign-in-code-light.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=c3117f3049a4b17b5811974a9620d622" alt="The sign-in page on a phone asking for the six-digit authenticator code, with the Use a recovery code link under the Sign in button" width="1600" height="1778" data-path="images/help/account/two-factor-authentication/sign-in-code-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/sign-in-code-dark.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=da555ca63bea1769a628a44c139438e9" alt="The sign-in page on a phone asking for the six-digit authenticator code, with the Use a recovery code link under the Sign in button" width="1600" height="1778" data-path="images/help/account/two-factor-authentication/sign-in-code-dark.png" />
    </Frame>
  </Step>
</Steps>

The code step lasts 5 minutes. If it runs out, click **Start over** and enter your password again. After 5 wrong codes in a row, OnlyX refuses every code for 15 minutes: wait 15 minutes, then click **Start over**.

## Sign in with a recovery code

Use a recovery code when you do not have your phone.

<Steps>
  <Step title="Switch to a recovery code">
    On the **Authenticator code** step, click **Use a recovery code**.

    The step changes to **Recovery code**.
  </Step>

  <Step title="Enter one of your codes">
    Type one of your recovery codes with its hyphen, like `xxxxx-xxxxx`. Capital letters and spaces do not matter. Then click **Sign in**.

    That code is now spent. The count on the **Two-factor authentication** card goes down by one.
  </Step>
</Steps>

To go back to the app, click **Use authenticator app**.

If you have a new phone, turn two-factor off with a code from your old phone or a recovery code. Then turn it on again, and scan the new QR code with the new phone.

## Make new recovery codes

Make new codes when you are running low, or when someone else may have seen your list.

<Steps>
  <Step title="Open the New recovery codes window">
    In **Settings** > **Security**, in the **Two-factor authentication** card, click **New recovery codes**.

    <Frame caption="**1** On, and the codes you have left · **2** New recovery codes · **3** Turn off">
      <img className="block dark:hidden" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/two-factor-on-light.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=5db300be9b4df15a179806c526eeab1e" alt="The Two-factor authentication card with the On badge, the date and 8 recovery codes left, and the New recovery codes and Turn off buttons" width="1512" height="504" data-path="images/help/account/two-factor-authentication/two-factor-on-light.png" />

      <img className="hidden dark:block" src="https://mintcdn.com/onlyx/uPTnpEc4lb-MnUky/images/help/account/two-factor-authentication/two-factor-on-dark.png?fit=max&auto=format&n=uPTnpEc4lb-MnUky&q=85&s=4ee765ab452a0a3f3dadc9fe91cf5341" alt="The Two-factor authentication card with the On badge, the date and 8 recovery codes left, and the New recovery codes and Turn off buttons" width="1512" height="504" data-path="images/help/account/two-factor-authentication/two-factor-on-dark.png" />
    </Frame>
  </Step>

  <Step title="Confirm that it is you">
    In **Code**, enter the code your app shows now, or one unused recovery code. Then click **Generate**.

    The **Save your recovery codes** window opens with 10 new codes.
  </Step>

  <Step title="Save the new codes">
    Save the codes as you did when you turned on two-factor. Tick **I have saved these somewhere safe**, then click **Done**.

    Your old recovery codes stopped working when you clicked **Generate**.
  </Step>
</Steps>

## Turn off two-factor

<Steps>
  <Step title="Open the Turn off window">
    In **Settings** > **Security**, in the **Two-factor authentication** card, click **Turn off**.

    The **Turn off two-factor?** window opens.
  </Step>

  <Step title="Enter your password and a code">
    In **Password**, enter your password. In **Code**, enter the code your app shows now, or one unused recovery code.
  </Step>

  <Step title="Turn it off">
    Click **Turn off**.

    OnlyX shows "Two-factor is off" and emails you "Two-factor authentication was turned off". OnlyX deletes your setup key and every recovery code. To turn two-factor on again, you scan a new QR code.
  </Step>
</Steps>

## Good to know

* Each six-digit code works only once. After you use one, wait for the next code in your app.
* After 5 wrong codes in a row, OnlyX refuses every code for 15 minutes. Wrong codes at sign-in, in **New recovery codes** and in **Turn off** all count.
* A password reset does not turn two-factor off. See [Change or reset your password](/account/password).
* Owners and admins cannot turn it on or off for you. They also cannot make it required.
* The recovery code count goes down with each code you use. OnlyX does not warn you when it runs low, so make new codes in time.

## If something goes wrong

<AccordionGroup>
  <Accordion title="&#x22;That code was not accepted&#x22; when you turn it on">
    The code was wrong, too old, or already used. Wait for the next code in your app, then enter it.

    If you started the setup twice, your app may have two OnlyX entries. Only the newest QR code works. Remove the old entry.
  </Accordion>

  <Accordion title="&#x22;That code is not right.&#x22; when you sign in">
    The code was wrong or already used. Wait for the next code in your app and try again. If you do not have your phone, click **Use a recovery code**.
  </Accordion>

  <Accordion title="&#x22;Too many wrong codes. Try again in a few minutes.&#x22;">
    After 5 wrong codes in a row, OnlyX refuses every code for 15 minutes. Wait 15 minutes, then try again with a new code.
  </Accordion>

  <Accordion title="&#x22;That sign-in expired. Start again.&#x22; or &#x22;Too many attempts. Start the sign-in again.&#x22;">
    The code step lasts 5 minutes. Click **Start over**, then enter your password again. If you saw "Too many attempts", you entered 5 wrong codes. OnlyX now refuses every code for 15 minutes, so wait 15 minutes before you start over.
  </Accordion>

  <Accordion title="&#x22;Password is incorrect&#x22; when you turn it off">
    The password in the **Turn off two-factor?** window is wrong. Enter the password you sign in with.
  </Accordion>

  <Accordion title="I lost my phone and my recovery codes">
    You cannot turn two-factor off yourself without a code. A password reset does not turn it off either. Email OnlyX support at [support@onlyx.ai](mailto:support@onlyx.ai).
  </Accordion>
</AccordionGroup>

## What's next

<Columns cols={2}>
  <Card title="Check your active sessions and sign-in alerts" icon="monitor-smartphone" href="/account/active-sessions" horizontal />

  <Card title="Change or reset your password" icon="key-round" href="/account/password" horizontal />
</Columns>
