Supported Methods
Setting Up 2FA
Setting up 2FA requires three steps: authorize the addition of a new method, configure the method, then activate it with a verification code.Step 1: Authorize a new method
Before adding any 2FA method, authorize your account. For your first method, authorization uses email by default. For subsequent methods, use an existing 2FA method.Step 2: Configure the method
For Authenticator App (TOTP):vastai tfa resend-sms --secret <SECRET>.
Email is not a 2FA method you add in this step — it is the verification channel used by
tfa auth-new (Step 1) to authorize adding your first method (TOTP or SMS).Step 3: Activate the method
~/Downloads, to a custom path, or printed to the screen (the CLI warns this option is visible to onlookers). Save these backup codes in a secure location — they are the only way to recover access if you lose your 2FA device. The default file-save options write an unencrypted text file, so treat the resulting file the same as the codes themselves.
Logging In with 2FA
If your account has 2FA enabled and your session key has expired, usetfa login to re-authenticate:
~/.config/vastai/vast_tfa_key. The CLI uses this session key for subsequent authenticated requests. If the session expires, the CLI doesn’t just fail — it deletes the stale session key and automatically retries using your plain API key instead, printing a message like “Your 2FA session has expired… Trying again with your normal API Key”. Run tfa login again only when you actually need a fresh 2FA session for a later command.
Managing Methods
View current status
Update a method
vastai tfa status.
Delete a method
y/n) before deleting, since this invalidates the method’s own codes.
Backup Codes
Backup codes let you log in if you lose access to your 2FA device. Each code is one-time use.Regenerate backup codes
y/n) before regenerating, since this invalidates every existing code. On success, same interactive save prompt as the initial activation (default file under ~/Downloads, a custom path, or print to screen).
Session Key Lifecycle
After a successfultfa login, a session key is saved to ~/.config/vastai/vast_tfa_key (or $XDG_CONFIG_HOME/vastai/vast_tfa_key if XDG_CONFIG_HOME is set). The CLI automatically uses this key for authenticated requests. The session key expires after inactivity. When a command hits an expired session, the CLI deletes the stale key and automatically retries using your plain API key instead — you don’t need to do anything for that fallback to happen. Run vastai tfa login again only when you actually need a 2FA session for a subsequent command.
Error Reference
See Also
- API Reference: Two-Factor Authentication endpoints — REST API 2FA documentation
- Authentication — API key setup and management
- Console: Two-Factor Authentication — managing 2FA from the web console