Two-step verification (TOTP)
This guide describes how to protect your xTool sign-in with an authenticator app (TOTP) and recovery codes.
Two-step verification is optional. It is per user, not per organisation. After it is on, you enter a 6-digit code (or a recovery code) after your password — and also after Microsoft sign-in.
What you need
- Access to Account → Security.
- An authenticator app (for example Google Authenticator, Microsoft Authenticator, or 1Password) on your phone or desktop.
Enable TOTP
- Sign in with email and password.
- Open Account → Security.
- Under TOTP, status is Off. Click Start setup.
- Open your authenticator and add a new account.
- Scan the QR code, or paste the secret URI if you cannot scan.
- Enter the current 6-digit code and click Verify and enable.
xTool then shows recovery codes. Save them now — each code works once and they are not shown again. Use Copy all and store them somewhere safe.
Status on the Security page becomes Active.
Sign in with TOTP
- Enter email and password (or complete Microsoft sign-in).
- On Two-step verification, enter the 6-digit code from the app.
- If you cannot use the app, click Use a recovery code instead and enter one unused recovery code.
If the verification step expires, sign in again from the login page.
Disable TOTP
On Account → Security, click Disable TOTP. Sign-in then only needs your password (and Microsoft, if connected) until you enable TOTP again.