---
title: Manage security settings
description: >-
  Turn on two-factor authentication and manage passkeys from Settings → Security
  in the Fuxam mobile app.
sidebar:
  order: 4
---

**Security** lets you manage **Two-factor authentication** and **Passkeys** (shown as **Face ID** on many iPhones) from **Settings** in the Fuxam mobile app. Two-factor authentication asks for a code from an authenticator app when you sign in. Passkeys let you sign in with Face ID, Touch ID, or your device screen lock instead of typing your password every time.

:::tip
Open **Security** from the app menu: tap the floating button next to the tab bar, tap **Settings**, then tap **Security**.
:::

## Why it matters

Authenticator-app two-factor authentication reduces the risk that a stolen password alone grants access to your schedule, chat, and student ID. Passkeys speed up sign-in on a device you trust. Some institutions require two-factor authentication before you can use the rest of the app.

## Before you start

| Requirement | Detail |
| --- | --- |
| Signed in | Complete [Sign in](/docs/fuxam-mobile/getting-started/sign-in) first |
| Authenticator app (for 2FA) | Any TOTP app that can scan a QR code or accept a setup key |
| Device support (for passkeys) | Face ID, Touch ID, or screen lock must work on this device |
| Institution setting (passkeys) | Your institution must allow passkey sign-in; otherwise the list explains that passkeys are turned off |

## How to open Security

1. Tap the floating button next to the tab bar to open the app menu.

2. Tap **Settings**.

3. Tap **Security**. The **Security** screen shows **Two-factor authentication** and **Passkeys**.

## How to enable two-factor authentication

1. On **Security**, turn on **Two-factor authentication**.

2. Confirm your identity if the app asks — enter your password, email code, or use a passkey on **Confirm it's you**.

3. On **Set up authenticator app**, scan the QR code with your authenticator app. If you cannot scan, tap **Copy setup key** and enter the key manually (**Or enter this key manually**).

4. Tap **Continue to verification**, enter the 6-digit code, then tap **Verify and enable**.

5. When you see success, continue. Two-factor authentication is now enabled.

:::info
If your institution requires two-factor authentication, the app may open a required setup screen right after sign-in. Complete the same QR scan and code steps before you can use Calendar, Chat, or Account. You cannot disable two-factor authentication while it is enforced.
:::

## How to disable two-factor authentication

Only available when your institution does **not** enforce two-factor authentication.

1. On **Security**, turn off **Two-factor authentication**.

2. Confirm **Disable** when prompted. You will no longer need a verification code when signing in.

## How to add a passkey

On iPhone the section may be labeled **Face ID** instead of **Passkeys**.

1. On **Security**, tap the **+** control next to **Passkeys** (or **Set up Face ID** on iOS).

2. Complete the device Face ID, Touch ID, or screen-lock prompt.

3. If the passkey has no name yet, the **Rename passkey** sheet opens so you can give it a recognizable name (for example your device name).

:::tip
After sign-in, the app may offer **Add a passkey?** (or **Set up Face ID?**). You can add a named passkey there, tap **Not now** to skip, or **Sign Out**.
:::

## How to rename or remove a passkey

1. On **Security**, tap an existing passkey in the list.

2. Choose **Rename** to open the rename sheet, or **Remove** and confirm deletion.

## Common pitfalls

| Pitfall | What happens | What to do |
| --- | --- | --- |
| Invalid verification code | Setup stays on verify | Wait for a new 6-digit code and try again |
| Institution requires 2FA | Toggle stays on; enforced notice shown | Keep using your authenticator app; contact your administrator if you lost access |
| Passkeys turned off by institution | Empty state explains passkeys are disabled | Contact your administrator |
| Device does not support passkeys | Add control is unavailable | Use password (and 2FA if enabled) to sign in |

## FAQ

**Where is Security if I am on the Account tab?**

Open the floating button next to the tab bar → **Settings** → **Security**. The Account tab shows your student ID and profile; security controls live under **Settings**.

**What authenticator apps work?**

Any app that supports TOTP QR codes or manual setup keys (for example Google Authenticator, Authy, or 1Password). The handbook does not require a specific brand.

**Do I need both two-factor authentication and a passkey?**

No. They solve different problems. Two-factor authentication adds a code at sign-in. Passkeys replace password entry with biometrics on a trusted device. Your institution may require two-factor authentication even if you also use a passkey.

## Related pages

**[Sign in](/docs/fuxam-mobile/getting-started/sign-in)**

Sign in with email, password, SSO, or passkey.

**[Sign out](/docs/fuxam-mobile/account/sign-out)**

End your session on this device.

**[Switch institution, language, and theme](/docs/fuxam-mobile/account/switch-institution-language-and-theme)**

Language also appears under Settings.

**[Troubleshooting](/docs/fuxam-mobile/getting-started/troubleshooting)**

Fix sign-in and account issues.

