# 2fa Local accounts can enable TOTP from Profile settings. Setup requires the current password, verification of the first six-digit code, and acknowledgement of one-time recovery codes. Users can disable TOTP, regenerate recovery codes, list/revoke trusted devices, and revoke every trusted device. Challenge attempts are rate-limited. Recovery codes are hashed at rest and shown only when generated. See `docs/security/two-factor-authentication.md` for the detailed trust model.