Account Settings

Two-factor authentication and passkeys

Authenticator app, SMS backup, backup codes, passkeys, and Android biometrics

1 min readUpdated for the current Astral app

Open User Settings → Security & Login → Security. The account must be claimed.

Authenticator app (TOTP)

  1. Click Enable, then scan the QR code or type the secret.
  2. Enter the 6-digit code.
  3. Save the 10 backup codes (xxxx-xxxx). You can download them (Astral_{email}_backup_codes.txt), copy them, or regenerate them. Regeneration invalidates the old set.

At login, an authenticator code and a backup code go in the same field.

SMS as a backup

After TOTP you can add a phone and turn on SMS 2FA. It is a backup, not a replacement. Phone details: Email, password, and phone.

Passkeys

A passkey lets you sign in without a password and confirm sensitive actions.

  • Up to 10 passkeys. Name length 1–64, for example YubiKey or iPhone.
  • Add Passkey, Rename, Delete.
  • Each row shows Added and Last used.

During a domain migration, adding a passkey may be temporarily disabled — use astraof.com.

Android biometrics

In the same section you can unlock a saved session on this device with fingerprint or face.

Verify your identity

Some actions (email change, viewing backup codes, application secrets) open Verify your identity. Methods: password, authenticator, SMS, passkey. Preference order: passkey → TOTP → SMS → password.

If you lost both the phone and the codes, email support@astraof.com from the address on the account. See also I cannot sign in.

Still need help?

If you couldn't find what you're looking for, our support team is here to help.

Contact Support
AI
AI Assistant
📚
Ask anything about Astral
Powered by Grok