2FA and Passkeys

Two-Factor Authentication and Passkeys

A stolen maintainer password is a stolen repository. On 13 March 2023 GitHub 29 began requiring two-factor authentication (2FA) from everyone who contributes code on GitHub.com, rolled out group by group through 2023. Organizations can require it too (not run here). Factors differ in resisting phishing:

GitHub's second factors, strongest first
Second factor Resists phishing Notes
Passkey or security key (WebAuthn) Yes Bound to github.com; a passkey also replaces the password
GitHub Mobile 29 Partly Approve the sign-in in the app on your phone
Authenticator app (TOTP) No Six-digit codes can be relayed by a fake site
SMS No Only in some countries; exposed to SIM swapping

Passkeys, generally available since 21 September 2023, need neither password nor separate 2FA step: the passkey is itself two factors, a device you hold and the fingerprint or PIN that unlocks it. Register two, and keep the recovery codes offline. 2FA protects sign-ins, not tokens, so keep tokens narrow (only booknest* repositories here), short-lived (this one expires on 24 December 2026) and out of Git 1,932 , which push protection checks.