📖 How to enable two-factor authentication (2FA)


What is two-factor authentication?

Two-factor authentication (2FA) adds an extra check when you sign in to NA Chess Hub. You enter your usual password, then a short code from an authenticator app on your phone. Someone who learns your password still needs the second factor to sign in.

2FA is optional for ordinary player and organizer accounts. It is required to use Account Manager delegation.

Before you begin
  • Have access to your NA Chess Hub account and your phone.
  • Install a trusted authenticator app, such as Microsoft Authenticator or Google Authenticator, from your phone's official app store. Both are free.
  • After setup, these apps can generate codes without a mobile signal or internet connection. There is no text-message charge for authenticator-app codes.
  • If possible, open NA Chess Hub on a computer or tablet so you can scan its QR code with your phone. If you have only your phone, use manual setup as explained below.
Step 1: Open your security settings
  1. Sign in to your own NA Chess Hub account.
  2. Open Two-factor authentication in your account settings.
  3. Under Authenticator app, select Add authenticator app or Setup authenticator app.

If your account already uses SMS verification, see the existing-SMS-users section below before switching methods.

Step 2: Add NA Chess Hub to your authenticator app

Using the QR code:

  1. Leave the NA Chess Hub setup page open on your computer or tablet.
  2. Open your authenticator app on your phone.
  3. In Microsoft Authenticator, select Add account or the + button, then Other account. In Google Authenticator, select +, then Scan a QR code. Labels may vary slightly by app version.
  4. Use the authenticator app's scanner to scan the QR code on the NA Chess Hub page.
  5. An entry for USChessHub should appear in the app, with a six-digit code.

If you cannot scan, or are using the same phone: choose manual entry or Enter a setup key in your authenticator app. Give the entry a recognizable name, such as USChessHub - your username, and copy the setup key shown by NA Chess Hub. Select Time-based if asked. Spaces and letter casing in the setup key do not matter.

Keep the QR code and setup key private. Anyone with a copy can generate verification codes for your account. Do not send them to anyone or post screenshots of them.

Step 3: Verify the setup
  1. Find the current six-digit code for your NA Chess Hub entry in the authenticator app.
  2. Type that code into the Verification Code box on the NA Chess Hub setup page.
  3. Click Verify.
  4. Wait for the message confirming that your authenticator app has been verified.

Scanning the QR code alone does not finish setup. You must enter a valid code and click Verify.

Authenticator codes normally change about every 30 seconds. If a code is about to change, wait for the next one and enter it promptly. Use the six-digit code, not the longer setup key.

Step 4: Save your recovery codes

If NA Chess Hub displays recovery codes after setup, save them immediately. These are your backup if your phone is lost, damaged, replaced or unavailable.

  • A generated set contains 10 recovery codes. Store them in a password manager or print them and keep the paper somewhere safe.
  • Keep a backup you can access even if you lose the phone that holds your authenticator app.
  • Each recovery code works once.
  • A recovery code replaces the second-factor code; it does not replace your password.
  • Creating a new set invalidates the previous set. Keep only the current set for future use.
  • If no codes are displayed because you already have a set, make sure you can find those codes. If not, use Reset recovery codes on the two-factor authentication page to generate replacements.

Recovery codes are private account credentials. Do not share them.

Step 5: Test signing in
  1. Keep your current signed-in window open until you have confirmed the setup works.
  2. Open a private or incognito browser window and sign in to NA Chess Hub with your usual username and password.
  3. When asked for an authenticator code, open the app and enter the current code for this account.
  4. Confirm you can reach your account.

If you choose Remember this machine where offered, that browser may skip the extra code on later sign-ins. Use this only on a private, trusted device. To require codes again in that browser, use Forget this browser in your two-factor settings. Existing signed-in sessions may not ask for a new code immediately.

If a code does not work
  • Make sure you selected the correct NA Chess Hub entry, especially if you manage several family accounts.
  • Wait for a new code and try again. Preserve any zero at the beginning.
  • Set your phone's date and time to update automatically. Incorrect device time can make authenticator codes fail.
  • If you reset or set up the authenticator again, use the entry created from the newest QR code. An old entry may no longer work.
  • Avoid repeated guesses. Failed attempts can temporarily lock your account.
If you lose your phone or get locked out of 2FA

After entering your username and password, choose Use a recovery code or the recovery-code link on the verification screen, then enter one unused recovery code.

If you have neither your authenticator nor a recovery code, contact NA Chess Hub support. Authorized staff must verify your identity before disabling and resetting 2FA. Account Managers can assist only with ordinary accounts; privileged accounts require an administrator.

A staff reset invalidates the old authenticator key and recovery codes. You can then sign in with your password and set up 2FA again. Save your new recovery codes. This reset does not change your password or automatically unlock an account that is temporarily locked for failed login attempts.

For accounts already using SMS verification

Existing SMS users can continue receiving text-message codes. New SMS enrollment is currently hidden from the main 2FA settings page; authenticator apps are the offered setup option.

To switch from SMS to an authenticator app, open Manage SMS verification and disable SMS using your password plus a current SMS security code or an unused recovery code. Then return to two-factor authentication settings and configure the authenticator app. Complete the new setup promptly.

The current implementation uses one selected sign-in method at a time: SMS or an authenticator app. Recovery codes remain the backup.

Using FreePair with 2FA

When FreePair opens the NA Chess Hub sign-in page in your browser, complete the usual login and the requested second-factor verification there. FreePair continues after the browser finishes authorization. You do not need to send your authenticator setup key, recovery codes or SMS codes to FreePair support, and a fresh code is not required for every event API call.

Account Manager delegation

If you have Account Manager delegation, keep 2FA enabled. Disabling 2FA immediately suspends your delegated account-management access, even if you are already signed in. Re-enabling 2FA restores that access while the assignment remains in place. Enabling 2FA by itself does not grant Account Manager permissions.

General
What is two-factor authentication?

Two-factor authentication (2FA) adds an extra check when you sign in to NA Chess Hub. You enter your usual password, then a short code from an authenticator app on your phone. Someone who learns your password still needs the second factor to sign in.

2FA is optional for ordinary player and organizer accounts. It is required to use Account Manager delegation.

Before you begin
  • Have access to your NA Chess Hub account and your phone.
  • Install a trusted authenticator app, such as Microsoft Authenticator or Google Authenticator, from your phone's official app store. Both are free.
  • After setup, these apps can generate codes without a mobile signal or internet connection. There is no text-message charge for authenticator-app codes.
  • If possible, open NA Chess Hub on a computer or tablet so you can scan its QR code with your phone. If you have only your phone, use manual setup as explained below.
Step 1: Open your security settings
  1. Sign in to your own NA Chess Hub account.
  2. Open Two-factor authentication in your account settings.
  3. Under Authenticator app, select Add authenticator app or Setup authenticator app.

If your account already uses SMS verification, see the existing-SMS-users section below before switching methods.

Step 2: Add NA Chess Hub to your authenticator app

Using the QR code:

  1. Leave the NA Chess Hub setup page open on your computer or tablet.
  2. Open your authenticator app on your phone.
  3. In Microsoft Authenticator, select Add account or the + button, then Other account. In Google Authenticator, select +, then Scan a QR code. Labels may vary slightly by app version.
  4. Use the authenticator app's scanner to scan the QR code on the NA Chess Hub page.
  5. An entry for USChessHub should appear in the app, with a six-digit code.

If you cannot scan, or are using the same phone: choose manual entry or Enter a setup key in your authenticator app. Give the entry a recognizable name, such as USChessHub - your username, and copy the setup key shown by NA Chess Hub. Select Time-based if asked. Spaces and letter casing in the setup key do not matter.

Keep the QR code and setup key private. Anyone with a copy can generate verification codes for your account. Do not send them to anyone or post screenshots of them.

Step 3: Verify the setup
  1. Find the current six-digit code for your NA Chess Hub entry in the authenticator app.
  2. Type that code into the Verification Code box on the NA Chess Hub setup page.
  3. Click Verify.
  4. Wait for the message confirming that your authenticator app has been verified.

Scanning the QR code alone does not finish setup. You must enter a valid code and click Verify.

Authenticator codes normally change about every 30 seconds. If a code is about to change, wait for the next one and enter it promptly. Use the six-digit code, not the longer setup key.

Step 4: Save your recovery codes

If NA Chess Hub displays recovery codes after setup, save them immediately. These are your backup if your phone is lost, damaged, replaced or unavailable.

  • A generated set contains 10 recovery codes. Store them in a password manager or print them and keep the paper somewhere safe.
  • Keep a backup you can access even if you lose the phone that holds your authenticator app.
  • Each recovery code works once.
  • A recovery code replaces the second-factor code; it does not replace your password.
  • Creating a new set invalidates the previous set. Keep only the current set for future use.
  • If no codes are displayed because you already have a set, make sure you can find those codes. If not, use Reset recovery codes on the two-factor authentication page to generate replacements.

Recovery codes are private account credentials. Do not share them.

Step 5: Test signing in
  1. Keep your current signed-in window open until you have confirmed the setup works.
  2. Open a private or incognito browser window and sign in to NA Chess Hub with your usual username and password.
  3. When asked for an authenticator code, open the app and enter the current code for this account.
  4. Confirm you can reach your account.

If you choose Remember this machine where offered, that browser may skip the extra code on later sign-ins. Use this only on a private, trusted device. To require codes again in that browser, use Forget this browser in your two-factor settings. Existing signed-in sessions may not ask for a new code immediately.

If a code does not work
  • Make sure you selected the correct NA Chess Hub entry, especially if you manage several family accounts.
  • Wait for a new code and try again. Preserve any zero at the beginning.
  • Set your phone's date and time to update automatically. Incorrect device time can make authenticator codes fail.
  • If you reset or set up the authenticator again, use the entry created from the newest QR code. An old entry may no longer work.
  • Avoid repeated guesses. Failed attempts can temporarily lock your account.
If you lose your phone or get locked out of 2FA

After entering your username and password, choose Use a recovery code or the recovery-code link on the verification screen, then enter one unused recovery code.

If you have neither your authenticator nor a recovery code, contact NA Chess Hub support. Authorized staff must verify your identity before disabling and resetting 2FA. Account Managers can assist only with ordinary accounts; privileged accounts require an administrator.

A staff reset invalidates the old authenticator key and recovery codes. You can then sign in with your password and set up 2FA again. Save your new recovery codes. This reset does not change your password or automatically unlock an account that is temporarily locked for failed login attempts.

For accounts already using SMS verification

Existing SMS users can continue receiving text-message codes. New SMS enrollment is currently hidden from the main 2FA settings page; authenticator apps are the offered setup option.

To switch from SMS to an authenticator app, open Manage SMS verification and disable SMS using your password plus a current SMS security code or an unused recovery code. Then return to two-factor authentication settings and configure the authenticator app. Complete the new setup promptly.

The current implementation uses one selected sign-in method at a time: SMS or an authenticator app. Recovery codes remain the backup.

Using FreePair with 2FA

When FreePair opens the NA Chess Hub sign-in page in your browser, complete the usual login and the requested second-factor verification there. FreePair continues after the browser finishes authorization. You do not need to send your authenticator setup key, recovery codes or SMS codes to FreePair support, and a fresh code is not required for every event API call.

Account Manager delegation

If you have Account Manager delegation, keep 2FA enabled. Disabling 2FA immediately suspends your delegated account-management access, even if you are already signed in. Re-enabling 2FA restores that access while the assignment remains in place. Enabling 2FA by itself does not grant Account Manager permissions.