Skip to content

docs: refresh the two-factor authentication pages - #26234

Open
akristen wants to merge 5 commits into
docker:mainfrom
akristen:tier-2-freshness
Open

akristen wants to merge 5 commits into
docker:mainfrom
akristen:tier-2-freshness

Conversation

@akristen

@akristen akristen commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The 2FA section page mixed concepts with enable and disable steps, and the same recovery-code and sign-in details appeared on more than one page. This splits procedures onto a manage page, keeps the overview to how 2FA works and when Docker asks for the code, and leaves the recover page for the recovery-code and Support steps.

akristen and others added 4 commits September 30, 2026 13:53
The 2FA pages described the recovery code as a reusable backup and left
out the lost-device sign-in path, the verified-email and enforced-SSO
conditions, and the exact control names on the settings screens.

Add a callout that the recovery code works once and turns 2FA off, add
the "Sign in with your recovery code" steps, name the Copy, Download,
Print, QR Code, and Text Code controls, scope the authenticator prompt
to password sign-in, shorten the benefits list, and add next steps.

Co-authored-by: Cursor <cursoragent@cursor.com>
The refreshed 2FA pages still used label-and-colon bullets, negative
contractions, generic titles and keywords, and inline links that pushed
lines past 80 characters.

Remove the Key benefits list, rewrite negative contractions, match the
avatar navigation wording used elsewhere, sharpen the page titles,
descriptions, and keywords for search, rename the Support section, and
move long links to reference definitions.

Co-authored-by: Cursor <cursoragent@cursor.com>
The 2FA section page was a procedure: after two sentences it went into
prerequisites, enable steps, and disable steps, and it left out how the
second factor is asked for, when the CLI needs a personal access token,
and what the recovery code does.

Move the prerequisites, enable, and disable steps to a new manage.md and
add a section for moving 2FA to a new device. Rewrite _index.md as an
overview that explains the TOTP pairing and sign-in prompt, lists when
Docker asks for the code, and describes the single-use recovery code and
the emails Docker sends. Move the disable-2fa aliases to manage.md and
point the "enable" links from the accounts pages and the recovery page at
the new manage page.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep how 2FA works, when Docker asks for the code, and recovery-code behavior on the overview so the manage and recover pages stay procedural.

Co-authored-by: Cursor <cursoragent@cursor.com>
@netlify

netlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit 690bc6e
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6abe55da645edb0008ca6d2b
😎 Deploy Preview https://deploy-preview-26234--docsdocker.netlify.app/security/authentication/2fa/
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@akristen akristen added the status/review Pull requests that are ready for review label Sep 30, 2026
@github-actions github-actions Bot added area/security area/accounts Relates to Docker accounts labels Sep 30, 2026
@akristen
akristen requested a review from a team September 30, 2026 19:54
@akristen akristen self-assigned this Sep 30, 2026
Comment thread content/manuals/security/authentication/2fa/_index.md Outdated
Comment thread content/manuals/security/authentication/2fa/manage.md Outdated

@aevesdocker aevesdocker left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice changes, added two non-blocking questions

The sign-in table on the 2FA overview had a row for enforced SSO, which does not apply to the individual accounts this page covers. The manage page opened with a sentence about setup being unavailable while 2FA is on, which repeated the Move 2FA to a new device section.

Co-authored-by: Cursor <cursoragent@cursor.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/accounts Relates to Docker accounts area/security status/review Pull requests that are ready for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants