NexaDocs
DocsAccount SecurityAccount Security & 2FA

Account Security & 2FA

This one's important enough that it gets its own page instead of a sentence buried somewhere else. If you run a server, help moderate one, or just have an account you care about — read this.

Your password alone is not enough

A password is one layer. That's it. If someone gets your password — through a data breach on some other site you used the same password on, a phishing link, a fake login page, whatever — that's the whole game. They're in. No second check, no second chance.

Two-factor authentication (2FA) adds a second layer on top of your password. Even if someone has your password, they still need the second thing — a code from your phone, a security key, whatever method you set up — before they can actually get into your account. Without that second piece, your password alone doesn't get them anywhere.

Remember this

Any hacker can get your password. It happens constantly, to accounts big and small, and it's rarely because someone was careless — breaches happen on sites you don't even control. 2FA is not optional extra security. It's the difference between a stolen password being useless and a stolen password being everything.

How 2FA actually works

When 2FA is on, logging in takes two steps instead of one:

  1. You enter your email and password like normal
  2. You're then asked for a second code — usually a 6-digit number that changes every 30 seconds, generated by an authenticator app on your phone

Someone with just your password gets stuck at step 2. They don't have your phone, so they don't have the code, so they don't get in. That's the entire point — it turns "I know your password" into "I know your password and I also somehow have physical access to your phone," which is a much harder bar to clear.

How to actually turn it on

  1. Open Discord and go to User Settings
  2. Go to My Account
  3. Under Password and Authentication, find Enable Two-Factor Auth
  4. Download an authenticator app if you don't already have one — Google Authenticator and Authy are both common, free choices
  5. Scan the QR code Discord shows you with the app
  6. Enter the 6-digit code the app generates to confirm it's linked correctly
  7. Discord will give you a set of backup codes — save these somewhere safe, not just a screenshot on the same phone your authenticator app is on

Don't skip the backup codes

If you ever lose your phone, those backup codes are the only way back into your account without going through Discord support. Write them down, put them in a password manager, whatever — just don't skip this step because it feels like an extra hassle. You'll be glad you did it the one time you actually need it.

Why this matters more if you're staff

If you help moderate a server, your account isn't just yours anymore — it has real permissions attached to it. This connects directly to Moderation & Security: anti-nuke exists specifically because a compromised staff account can do real damage fast, mass bans, channel deletions, role wipes. 2FA is the thing that keeps "compromised staff account" from happening in the first place. It's the first line of defense, before anti-nuke ever needs to kick in as the backup plan.

If you're a server owner, this matters even more — your own account level is what unlocks AI chat for your entire server. An account with real consequences attached to it, whether that's moderation power or something tied to your whole community, is exactly the kind of account that should never be running on a password alone.

A few other habits worth building

  • Don't reuse passwords. If one site gets breached and you used that same password on Discord, that breach is now a Discord breach too.
  • Be suspicious of "verify your account" links. Discord will never DM you asking you to click a link and log in somewhere else. That's always a phishing attempt.
  • Check your active sessions occasionally. Discord shows you every device currently logged into your account, under the same Authentication settings — if you see something you don't recognize, that's your sign to change your password immediately.
  • Use an authenticator app, not just SMS, if you have the choice. SMS codes can be intercepted through SIM-swapping; an app tied to your actual device is meaningfully harder to get around.

None of this is complicated. It's a five-minute setup that turns your account from "one leaked password away from being taken over" into something meaningfully harder to break into. Take the five minutes.