How to Set Up Two-Factor Authentication (2FA) on Telegram
Telegram's Two-Step Verification (2FA) adds a password on top of the SMS/code verification when logging into a new device. This prevents unauthorized access even if someone intercepts your verification code.
Setting Up 2FA
- Open Telegram and go to Settings.
- Tap Privacy and Security.
- Tap Two-Step Verification.
- Set a strong password. You will need this every time you log into a new device.
- Add a password hint (optional but recommended).
- Enter a recovery email. This lets you reset the password if you forget it.
- Telegram sends a confirmation code to your email. Enter it to verify.
- Done. Your account is now protected with 2FA.
Why You Should Enable 2FA
- SIM swap protection: Even if an attacker takes over your phone number, they cannot log in without your password.
- SMS interception defense: Verification codes sent via SMS can be intercepted. The 2FA password cannot.
- Account takeover prevention: Adds a critical second layer of security.
Recovery Email
Your recovery email is crucial. If you forget your 2FA password and do not have a recovery email set, you will need to wait 7 days before Telegram allows you to reset your account (which deletes all cloud chats). Always set a recovery email.
Changing or Removing 2FA
Go to Settings, Privacy and Security, Two-Step Verification. Enter your current password, then you can change it or turn it off.
Frequently Asked Questions
What happens if I forget my 2FA password?
If you set a recovery email, you can reset the password via email. If not, you must wait 7 days, after which Telegram allows you to reset your account. This deletes all your cloud chats and contacts as a security measure.
Does 2FA protect my existing sessions?
No. 2FA only applies when logging into a new device. Existing sessions remain active. To terminate unwanted sessions, go to Settings, Devices, and terminate them manually.
Is Telegram 2FA the same as TOTP apps like Google Authenticator?
No. Telegram uses a static password (not a rotating code). You set a password that you enter when logging into new devices. It does not use TOTP or hardware keys.