About this tool
Enable app-based or security-key 2FA on X, save the backup code and drop the SMS fallback, with a readiness score.
The X (Twitter) 2FA Setup Guide takes you through switching on two-factor authentication for an X (formerly Twitter) account under Settings and privacy, Security and account access, Security, Two-factor authentication — and then scores what is still exposed. X offers three methods there: security key, authentication app and text message, with text message restricted to paid subscribers since March 2023. The checklist also covers the single backup code, password reset protect, old sessions and the connected apps that keep working after a password change.
Open X (Twitter) 2FA Setup Guide on AltFTool — it loads instantly in your browser.
Choose Security key, Authentication app or Text message (SMS), and tick the paid X subscription box — X has limited SMS 2FA to subscribers since 20 March 2023.
Work down the Setup checklist, ticking each item; every step shows its Path, such as Settings and privacy, Security and account access, Security, plus a minute estimate.
Watch the Account readiness score out of 100 as you save the single backup code, revoke connected apps and end old sessions, then press Copy result for what is still outstanding.
The text message option is gated behind a paid subscription, exactly as it is in the app.
Existing sessions and OAuth tokens from connected apps survive a password change — both are on the list.
X gives you one backup code, so the score stays capped until you have saved it.
X limited text-message 2FA to paid subscribers from 20 March 2023. On a free account the toggle is unavailable and you must use the authentication app or a security key instead — both are free and both are stronger than SMS.
Settings and privacy, then Security and account access, then Security, then Two-factor authentication. The same screen lists all three methods, and X lets you keep more than one enabled at the same time.
One. X issues a single backup code, which you can regenerate from the Two-factor authentication screen whenever you want a fresh one. Store it in a password manager or on paper rather than as a screenshot on the phone that holds your authenticator app.
No. Sessions that were already signed in stay signed in, and third-party apps keep working through their OAuth tokens. After enabling 2FA, go to Apps and sessions to log out of unknown devices and revoke connected apps you do not recognise. If you think the account was actually compromised, treat this as a starting point and contact X support.