figma

Figma's two-factor authentication | Figma Blog (opens in new tab)

Figma introduced two-factor authentication (2FA) to give users additional protection if their passwords are compromised. Users can receive codes by SMS or an authenticator app, with recovery codes available if they lose access to their phone. After verification, 2FA remains valid for 21 days unless the user logs in from a new device or signs back in after logging out.

Enabling Two-Factor Authentication

  • Users can activate 2FA from the account settings menu in Figma.
  • Supported verification methods include:
    • SMS login codes
    • Authenticator apps such as Google Authenticator
  • The feature works with all mobile phones.

Recovery and Login Behavior

  • Figma provides recovery codes in the account settings.
  • Users are encouraged to record these codes in case they lose their phone.
  • 2FA is required when:
    • Logging in on a new device
    • Signing back in after logging out
  • Once authenticated, the verification remains valid for 21 days.

Figma recommended enabling 2FA as an additional account-security measure and indicated that more security features were planned for the future.