Jump to content

Taimako: Tantance al’amura-biyu

From Meta, a Wikimedia project coordination wiki
This page is a translated version of the page Help:Two-factor authentication and the translation is 34% complete.
Outdated translations are marked like this.
Shortcut:
2FA
Wannan shafin ya bayyana yadda tabbatar da abubuwa biyu (2FA) ke aiki a kan ayyukan Wikimedia. 2FA yana ƙarfafa tsaro na asusun mai amfani da ku ta hanyar buƙatar fiye da kalmar sirri kawai don samun damar asusunku. Ayyukan Wikimedia suna ba ka damar amfani da aikace-aikacen tabbatarwa da maɓallan tsaro don samun damar asusunku.

Yaushe ne lokacin amfani da Tallafi kan tabbatarwa mataki biyu (2FA)

Saboda tabbatarwa mataki biyu (2FA) na ƙara tsaron asusu, yana da matuƙar muhimmanci musamman ga masu amfani da ke da ƙarin haƙƙoƙi. A shekarar 2025, Gidauniyar Wikimedia ta fara wajabta amfani da 2FA ga wasu daga cikin waɗannan rukunin masu amfani. Duba shafin aikin tsaron asusu domin ƙarin bayani.

Ya zuwa Disamba 2025, 2FA yana samuwa ga duk masu amfani da rajista akan ayyukan Wikimedia.

Hanyoyin tabbatarwa da ake da su

Manhajojin tabbatarwa

Verification code generated in an authenticator app

Manhajojin tabbatarwa galibi manhajoji ne na waya ko kwamfutar hannu, ko kuma ana iya samun su a cikin manhajojin adana kalmomin sirri. Suna samar da lambar tantancewa da za ka yi amfani da ita wajen tabbatar da shiga asusunka. Misalan irin waɗannan manhajoji sun haɗa da Google Authenticator, Microsoft Authenticator, 1Password, da FreeOTP. Domin samun manhajar tabbatarwa da ta dace da na’urarka da tsarin aikinta, duba kwatancen shahararrun manhajojin OTP a Turanci Wikipedia.

Idan ba ka da waya ko kwamfutar hannu da za ka yi amfani da ita don 2FA, za ka iya amfani da manhaja a kan kwamfutarka ta tebur ko laptop, amma wannan ba shi da cikakken tsaro sosai.

Makullan tsaro

YubiKey, a security key

Makullan tsaro galibi na’urorin kayan aiki ne na waje da ake haɗawa da na’urarka domin tabbatar da shiga asusu. Misalan irin waɗannan makullan tsaro sun haɗa da YubiKey, Nitrokey, da Titan Security Key. Manhajojin wayar hannu na Wikipedia ba sa goyon bayan makullan tsaro, saboda haka yana da kyau ka ƙara aƙalla manhajar tabbatarwa guda ɗaya idan kana shirin shiga ta manhajar wayar hannu ta Wikipedia.

Mabudan wucewa

Face ID, a system that uses a passkey

Passkeys hanya ce mafi sauƙi kuma mafi sauri ta shiga asusu: ba sa buƙatar wata na’urar tabbatarwa ta biyu kamar makullin tsaro ko manhaja a waya. Maimakon haka, ana adana passkeys a na’urarka ko cikin manhajar adana kalmomin sirri, kuma suna ba ka damar kammala tabbatarwa ta amfani da sawun yatsa, tantance fuska, ko lambar PIN. Kafin ka iya ƙara passkey, dole ne ka fara saita ɗaya daga cikin sauran hanyoyin 2FA.

Kunna tantance bayanai biyu

Don kunna 2FA don asusunku, dole ne ku sami damar shiga tare da kalmar sirri, kuma ku sami hanyar tabbatarwa ta biyu don saitawa.

Don kunna 2FA don asusunku:

  1. Je zuwa Special:AccountSecurity. Hakanan za ka iya shiga wannan shafin ta hanyar mahaɗin da ke cikin zaɓuɓɓukanka.
  2. Zaɓi hanyar ƙara manhajar tabbatarwa ko makullin tsaro, sannan ka bi matakan da aka nuna domin saita shi.
  3. Saukewa kuma adana ko buga lambobin dawowar ku.
  4. (Zaɓi) Bayan ka kunna 2FA ta amfani da manhajar tabbatarwa ko makullin tsaro, za ka iya ƙara passkey.
Gargadi: Lokacin da ka kunna 2FA, za ka samu jerin lambobin dawo da asusu. Ka buga ko ka sauke waɗannan lambobin kuma ka adana su a wuri mai aminci. Idan ka rasa na’urarka, ko ka samu matsala da manhajar tabbatarwa, za ka buƙaci waɗannan lambobin domin sake samun damar shiga asusunka.

Rijistar aikace-aikacen tabbatarwa da yawa ko maɓallan tsaro don asusunku ta hanyar maimaita matakan da ke sama.

Kunna tantance bayanai biyu

Da farko, shigar da sunan mai amfani da kalmar sirri. Mataki na biyu ya dogara da hanyoyin tabbatar da da ka yi rajista:

  • Idan kana amfani da manhajar tabbatarwa: shigar da lambar tantancewa da manhajar ta bayar. Lura: wannan lambar tana canzawa kusan kowane sakan talatin. Idan lambobinka ba sa aiki, duba Matsalolin gyara kuskure.
  • Idan kana amfani da makullin tsaro: bi umarnin da burauzarka ke bayarwa. Idan ka yi rajistar makullin tsaro da kuma manhajar tabbatarwa, tsarin zai fara neman makullin tsaro, amma za ka iya zaɓar shigar da lambar tantancewa maimakon haka. Ka lura cewa manhajojin wayar hannu na Wikipedia ba sa goyon bayan makullan tsaro; dole ne ka riga ka saita manhajar tabbatarwa domin shiga ta 2FA ta hanyar manhajar wayar hannu ta Wikipedia.
  • Idan kana amfani da passkey: bi umarnin da na’urarka ke bayarwa domin kammala tabbatarwa ta amfani da sawun yatsa, tantance fuska, ko lambar PIN.

Kunna tantance bayanai biyu

  1. Je zuwa Special:AccountSecurity.
  2. Zaɓi hanyar tabbatarwa kuma danna maɓallin don cire shi.
  3. Don cikakkiyar kashe 2FA, maimaita tsarin cirewa don duk hanyoyin tabbatar da ku.
Idan ka kashe 2FA gaba ɗaya, ana share lambobin dawowar ku ta atomatik.

To disable 2FA if you lost your device and the wiki automatically logged you out: see Troubleshooting.

If you can't disable 2FA because you lost access to your authentication device and recovery codes, you can attempt to recover access by asking WMF’s support desk to remove 2FA from your account.

Manage your recovery codes

When you enroll in 2FA, you receive a list of ten recovery codes. Print or download those codes and store them in a safe place. If you lose access to your authenticator apps or security keys, you will need these codes to regain access to your account.

Each recovery code is single use: after you use it once, it is no longer valid. If you use a code, go to Special:AccountSecurity and generate a new set of codes, so you don't run out.

Passkeys and passwordless login

Users who have added a passkey can now log in without entering their username or password (passwordless login). Clicking in the username field will display their passkey as an option to log in with.

To add a passkey:

  1. Follow the instructions on this page to enable 2FA with a security key or an authenticator app.
  2. After you enable 2FA, visit Special:AccountSecurity and click the button to add a passkey. If the button is inactive, see Troubleshooting.
  3. The next time you log in, your device will show the passkey as an autofill option in the username field. Clicking this option will log you in immediately, without entering your username and password. Alternatively, you can enter your username and password as usual, and your device will prompt you to use your passkey for 2FA.

Login verification by email

If you don't enable 2FA, some of your login attempts may require email verification. This type of verification requires you to enter a code sent to the email address associated with your wiki account. You can't opt out of this security feature, which protects user accounts from unauthorized access. However, if you enable 2FA, you won't be asked for email verification since 2FA is a stronger level of protection.

Access for tools and bots

Enabling 2FA for your user account may impact your ability to log in to bot accounts or tools. Use OAuth or bot passwords to restrict API sessions to specific actions, while still using 2FA to protect access to your main user account.

For example, tools like AutoWikiBrowser (AWB) don't support 2FA, but can use bot passwords.

Troubleshooting

Verification code doesn't work

If you have an existing 2FA device which has stopped generating correct codes, check that its clock is accurate. Time-based one-time password (TOTP) on Wikimedia wikis may fail due to a time difference of just 2 minutes.

Lost access to device or authenticator app

If you still have access to any device or authentication method you registered for 2FA, use that to log in.

If you no longer have access to any of your authentication methods, use one of your recovery codes: on the two-factor login page, instead of entering a code from your authentication device, click the button to use recovery codes. Enter one of the codes you downloaded when you enabled 2FA.

The Wikipedia mobile apps don't have a separate interface to enter recovery codes. Instead, input a recovery code the same way you would a verification code from your authenticator app.

After you successfully log in, register a new 2FA method before you disable the ones associated with your lost device.

Lost or unavailable recovery codes

If you don't have recovery codes and are unable to complete two-step authentication, you can attempt to recover access by asking the Wikimedia Foundation (WMF) support desk to remove 2FA from your account. You should only make this request as a last resort; WMF doesn't guarantee account recovery in this situation.

To file a support request:

  • Send an email to ca(_AT_)wikimedia.org to request removal of 2FA from your account. Send the email using the email address associated with your wiki account.
  • If you have access to Phabricator, you can also file a ticket there to help WMF staff confirm your identity.
  • If your request is approved and 2FA is removed from your account: log in using only your password, and set up two factor authentication again.

If you can't log in to your Developer account, see the documentation on wikitech for instructions on how to request 2FA removal.

Switch to a new device

If you got a new phone or want to use a different device for 2FA, add your new device before you remove your old one:

  1. Log in using your old device for 2FA. If you lost your old device, use a recovery code to complete verification.
  2. Use your new device to enable one or more authentication methods.
  3. Remove the authentication methods associated with your old device.

Cannot add a passkey because button is inactive

To use passkeys, you must first enable 2FA with a security key or an authenticator app. If you have already enabled 2FA, and the button to "Add a passkey" on Special:AccountSecurity is gray or inactive, you may be using an incompatible browser or operating system. To use passkeys, you must use one of the following options:

  • Use an operating system with a built-in password manager, like Windows (Windows Hello) or macOS (iCloud Keychain).
  • Use password manager in your browser, like Google Password Manager in Chrome.
  • Install a third-party password manager that can handle passkeys (like 1Password, Bitwarden, or LastPass).

If you don't have any of those options installed, or if you use an old version of your browser or operating system, you cannot use passkeys, and the button will be grayed out for you.

This is most commonly an issue for users of Firefox on Linux. Neither Firefox nor Linux has a built-in password manager, so the only way users of Firefox on Linux can use passkeys is by installing a third-party password manager, like 1Password, Bitwarden, or LastPass.

Enable 2FA on desktop and laptop computers

If you don't have a separate device to use for 2FA, you can use apps like WinAuth, Authenticator, and KeeWeb to handle 2FA tokens on many computers. This is the recommended way to enable 2FA if you don't have a smartphone or tablet computer.

If you currently use a password manager, check whether it supports 2FA. (Your password manager may also refer to 2FA as "OTP" or "TOTP".) Using your current password manager for 2FA is easier than setting up a new 2FA app.

Note: If you normally edit with your desktop computer, using a desktop 2FA app is slightly less secure than using a mobile 2FA app, as someone with access to both your computer and your password would still be able to log in to your account.

Authentication over SMS or messaging apps

Some platforms allow users to use a mobile phone number. These users receive a text or a messaging app message with a code to authenticate. We have no plans to support 2FA over SMS or similar solutions.

2FA on the private wikis

The private wikis are not connected with the Wikimedia global account, unlike Wikipedias or Meta. For this reason, to have 2FA there, you need to set it up on each private wiki separately, in addition to 2FA for your Wikimedia global account.

Reusing 2FA methods is not like reusing passwords:

  • It is encouraged to set up the same baseline and fallback 2FA methods on each private wiki.
  • It is encouraged to add passkeys from the same providers or on the same devices on each private wiki.
    • You can add as many of these as you like, from as many devices or providers as you like.
    • If you have the option of using a passkey that synchronizes (e.g., a 1Password cloud account or a Google account), you can keep using the same passkeys even if you change out your device, without having to go reset them all.

Duba kuma