Share feedback
Answers are generated based on the documentation.

Two-factor authentication for your individual Docker account

Subscription: Personal Pro
For: Individuals

Two-factor authentication (2FA) adds a code from an authenticator app to your password when you sign in to your Docker account. Someone who knows your password still needs the code from your device to sign in.

Tip

Organization and company settings do not include 2FA. To control how members sign in across an organization, use single sign-on.

How two-factor authentication works

When you turn on 2FA, you pair a time-based one-time password (TOTP) authenticator app with your account by scanning a QR code or entering a text code. Any authenticator app that supports TOTP works. Docker keeps one authenticator per account.

After repeated wrong codes, Docker returns Too many failed login attempts and blocks further attempts for a short time.

When Docker asks for the code

Sign-inWhat Docker asks for
Browser sign-in to Docker Home or Docker HubYour password, then the code from your authenticator app
docker login with no usernameThe same browser sign-in, if the browser is not already signed in
docker login -u, scripts, and CIA personal access token in the password prompt. Password sign-in from the CLI is not supported when 2FA is on

Recovery code

Docker gives you one recovery code when you turn on 2FA. The code signs you in if you lose your authenticator app, so copy, download, or print it and store it somewhere safe.

Docker emails the verified address on your account when you turn 2FA on or off, when a recovery code is generated, and when a recovery code is used to sign in. The email does not contain the code.

Next steps