Skip to content
,
AI setup from zero · Part 4

2FA, recovery, and shared family or team plans

12 min read
Featured image: 2FA, recovery, shared plans. Editorial illustration for Analytics Made Simple.

Turn on two-factor sign-in (2FA) yourself, on a phone you hold. Store your recovery codes in a password manager or on paper, never in your Camera roll. A family or team plan shares a bill, but a shared password shares your chats and the 6-digit codes too.

Imagine your phone asks for a 6-digit sign-in code the day before an important meeting, and you cannot find a way to get one. The AI account that holds your notes and slides for that meeting is locked until you do.

2FA is a second lock

A password, a magic email link, or “Sign in with Google” or “Sign in with Apple” is the first lock. 2FA is the second: a 6-digit code, a tap on a trusted phone, or a passkey, which is a login that uses your face or fingerprint instead of a typed code. In this story your partner did not steal your password. He sat inside your Apple ID, which is the first lock for every “Sign in with Apple” and for App Store billing. Then a 6-digit prompt appeared that you had never asked for.

Two separate locks get mixed up on an iPhone. Apple’s own 2FA protects the Apple ID (Settings, your name, then Sign-In and Security). The vendor’s 2FA protects ChatGPT, Claude, Gemini, or Grok inside that product. You can have Apple 2FA on and still have ChatGPT’s version off, and you can have ChatGPT’s on while a partner buys Pro on your Apple ID. Turn both on, and do it on a phone or laptop you hold. If you sign in through Google or Apple, secure that account first. Grok follows your X account, and Claude Team can use your company’s single sign-on (SSO), a shared company login. Consumer Claude is different, so open Settings and look, because some accounts lean on email links plus Google or Apple.

Four locks: password or SSO, authenticator or passkey, recovery codes in a real place, backup email or recovery contact
Four locks: password or SSO, authenticator or passkey, recovery codes in a real place, backup email or recovery contact

Rule of thumb: The person who can see the 6-digit code owns the account. If that person is not you, fix the setup before you fix the slides.

Authenticator app, text message, or passkey

OpenAI’s Help Center lists four ways to turn on multi-factor sign-in (MFA, the same idea as 2FA) for consumer ChatGPT. You can use an authenticator app (such as Google Authenticator, Authy, 1Password, or Apple Passwords), a push to a trusted device, a 6-digit text message (SMS, the ordinary phone texting service) or WhatsApp message, or a passkey. You manage them under ChatGPT Settings, then Security. Once MFA is on, it applies across ChatGPT and the developer platform. OpenAI’s page says workspace admins cannot force MFA for every seat, so it is up to each person, or to company SSO if you are on a work plan.

MethodWhat you seeWeak againstUse it when
Authenticator app6-digit code every 30 seconds in an app you choseA stolen unlocked phone, or a QR someone else scannedDefault for ChatGPT, Google, and any vendor that offers TOTP
SMS or WhatsApp6-digit text to a phone numberSIM swap, recycled numbers, a handset you no longer haveTemporary only, then add an app or passkey
PasskeyFace ID, Touch ID, or a hardware key confirmLosing the only device that holds itAdd as a second method, especially on ChatGPT

The US government’s Cybersecurity and Infrastructure Security Agency says plainly in its phishing-resistant MFA note that SMS and voice codes can be stolen with a SIM swap, where an attacker moves your phone number to their own SIM (subscriber identity module, the small card that holds your number). An authenticator app is better because the secret lives on your device and not at the phone carrier. A passkey (built on open web login standards) is stronger still, because a fake login page cannot replay it the way it can replay a typed code. You still need a spare. Scan the ChatGPT QR (quick response) code, the square barcode on the screen, with your authenticator, and write down the recovery material before you close the sheet. On Claude, open Settings and look for security or two-factor. If you only see email links plus Google or Apple, secure that Google or Apple account today. Gemini follows Google 2-Step Verification, and Grok follows X. Names move, so re-check.

Recovery codes live somewhere real

When you set up an authenticator, the vendor usually shows a short list of one-time recovery codes, or one long recovery key. You will not see that list again unless you generate a new one. Photographing it puts a spare key in the same Camera roll as your lunch photos and iCloud Photos, and emailing it to yourself puts it in the inbox an attacker already wants. A real place is a password manager vault (1Password, Bitwarden, or Apple Passwords on accounts you control), or a printed page in a drawer you can open on a Sunday.

OpenAI’s Advanced Account Security mode, rolled out for eligible consumer accounts in 2026, makes recovery stricter. Email and SMS recovery can go away, passkeys or hardware keys become your sign-in, and a recovery key is your spare. OpenAI’s Advanced Account Security article said, when checked in August 2026, that a valid recovery key starts a 48-hour waiting period before you can sign in again, and that Support will not reset you if you enrolled. Do not turn that mode on until your codes are stored.

SpareWhat it isFails whenPut it here
Recovery codes / keyOne-time strings from the vendorYou screenshotted them into CameraPassword manager, or paper in a drawer
Backup emailA second inbox the vendor can mailIt is the same Gmail you log in withA mailbox you still open this month
Passkey on a second deviceFace ID on the laptop as well as the phoneYou only enrolled the iPhoneWork Mac plus phone, then store recovery too
Recovery contact (Apple)A person who can generate a code for your Apple IDThat person is the one who bought the appSomeone who will pick up, in person

A backup email is not a second copy of the same address. If ChatGPT is on dana.work@gmail.com, a plus-alias in the same inbox is still one lock. Use a mailbox you will still have in a year. In the story, you later find “IMG_4481” in your Camera roll from Monday night: the Apple 2FA QR code your partner pointed at your phone “for a second.” Treat recovery material like cash, not like a meme.

A family plan shares the bill

Four share models: shared login, family-style bill with separate chats, team seats, Apple Family Sharing that hides the payer
Four share models: shared login, family-style bill with separate chats, team seats, Apple Family Sharing that hides the payer

A family or team plan is one invoice with more than one seat or household member. Each person still signs in as themselves, so chats, memory, uploaded files, and 2FA stay on that person’s login. You share the card, not the password. A shared login is a different thing: one email and one password used by two humans. The Project with the client name list is then visible to whoever opens the app, and the 6-digit codes go to whoever set up the authenticator. OpenAI’s terms treat a ChatGPT account as one user, and Anthropic’s consumer terms have the same shape for Claude Pro.

When the ChatGPT pricing page was checked in August 2026, ChatGPT Plus was one person at $20 a month. ChatGPT Team is seats with an admin and a minimum seat count, commonly two. Claude Pro is one person, and Claude Team is seats with standard and premium levels, minimums, and SSO. Anthropic has not shipped a Netflix-style family plan, so if two adults both need Claude, two Pro logins or a real Team organization beat one password on the fridge. Google One AI plans can share storage and, under current family-plan language, AI benefits with other members of the family group, with age limits, so confirm the live page. Each member still has their own Google account, and Gemini chats do not merge. Grok’s paid options follow grok.com and the X account, and sharing an X password is still a shared login.

Family Sharing on an iPhone can hide who pays

Apple Family Sharing is not an AI family plan. It is Apple’s household feature, with an organizer, members, optional Purchase Sharing, and shared subscriptions that Apple itself supports, such as iCloud+ and Apple TV. When Purchase Sharing is on, the organizer’s payment method is the default card. A family member taps Buy, and the charge from Apple.com/bill lands on the organizer, who can open purchase history and see the line. In-app subscriptions are shareable only if the app’s developer turned Family Sharing on for that product, and many AI apps do not. So you get a charge on the organizer’s card and a seat tied to one Apple ID.

In the story you are the Apple ID and your partner is the thumb. The Visa under Family Sharing is yours, so your finance team already knows about the $19.99 line. Settings, your name, then Subscriptions shows Claude. His phone shows it too, because he is signed into your Apple ID in the App Store. That is how it hides: the household sees one bill, two people share one login, and 2FA follows whoever completed Apple’s prompt on the new iPhone. Buy the plan on the vendor’s website while logged into the email you mean to keep, and turn off the in-app subscribe button. Do not sign a partner’s iPhone into your Apple ID “for five minutes,” because five minutes is how 2FA moves house.

A worked example: 18 hours, one workshop

WhenWhat you thoughtWhat it was
Monday nightMy partner is downloading Claude on my phone for the tripApp Store session on your Apple ID, in-app Pro, QR pointed at your Camera
Tuesday afternoonA glitch. I will retry6-digit 2FA bound to your partner’s device, Project still on that account
Tuesday eveningSupport will sort it before the workshopVendor support cannot see an Apple-billed seat the same way, and you had no recovery codes
Wednesday morningWorkshop with the agendaYou rebuilt the outline from email. The name list stayed in Claude

The 18-hour hole was not a missing feature. You still had your laptop, but you did not have the second lock. Your partner was in back-to-back meetings with Do Not Disturb on, so the 6-digit codes sat unseen. The fix goes in this order. Sign his iPhone out of your Apple ID. Cancel the App Store Claude subscription in Apple’s list, because the claude.ai billing page may not show it. Open Claude on the website with your work email, set up authenticator 2FA on your phone, and save the recovery codes into 1Password before you close the dialog. If the Project is gone, treat the name list as spilled and tell the client. If he wants a Claude account of his own, it should use his email and his card.

A recovery kit you can copy

Paste this into the same team note where you listed your vendor. Fill in the brackets, and if a line is still blank on Friday, that line is the lock that will fail.

Recovery kit (one vendor)
Account email: [work address]
Sign-in method: [email+password / Google work / Apple (only if I own this Apple ID)]
Apple ID on this phone: [mine / signed out of partner]
2FA method: [authenticator app name] on [my phone]
2FA backup: [passkey on this Mac / none yet]
SMS 2FA: [off, or number I still hold]
Recovery codes stored: [1Password vault / printed envelope in desk]
NOT stored: Camera, iCloud Photos, Slack, email to self
Backup email: [different inbox I opened this month]
Recovery contact: [name, in person, not the person who buys apps on my ID]
Family Sharing organizer: [me / partner]
Purchase Sharing: [on / off]
App Store subscribe for this vendor: OFF (website billing)
Shared login with anyone: NO
Owner: [you]
Last checked: [date]
Cancel path: Settings > Security (vendor web), plus Apple Subscriptions if a $19.99 line exists

This checklist names the person who holds the 6-digit app, the drawer that holds the spare codes, and the card that will see Apple.com/bill. If “Apple ID on this phone” is not yours, stop and sign out before you set up anything else. Turning on 2FA on a shared Apple ID gives the other person a stronger grip.

Common mistakes

  • Leaving 2FA off because the vendor sent a magic link last time.
  • Letting a partner scan the QR code “for a second,” which leaves the secret on their phone.
  • Saving recovery codes as a screenshot in Camera or in iCloud Photos.
  • Using SMS as the only second factor, then swapping SIM cards for a trip.
  • Sharing one Plus or Pro password with a household and calling it a family plan.
  • Buying Claude or ChatGPT in the iPhone app on someone else’s Apple ID, then asking finance to read Apple.com/bill.
  • Turning on OpenAI Advanced Account Security before the recovery key is in a vault you can open.
  • Setting the backup email to the same inbox as the login.

How to practice this week

Block 20 minutes and open the one vendor you use most. Confirm the email is your work identity, and turn on authenticator 2FA on a phone in your hand. Store the recovery codes before you close the tab. Sign the App Store out of any Apple ID that is not yours, then check Family Sharing, Purchase Sharing, and Apple Subscriptions for a surprise Claude or ChatGPT line. If two adults both need a paid seat, buy two logins or a real Team organization, and do not paste one password into both phones.

The next post covers files, uploads, and where your data goes. A lock is only useful if you know which files you put behind it. Related paths are AI for writing, privacy and run-it-yourself, Learn, and Practical AI.

Quick recap

  • Turn on 2FA yourself, on a device you hold.
  • Prefer an authenticator app or a passkey, and treat SMS as temporary.
  • Put recovery codes in a vault or on paper, never in Camera.
  • Family and team plans share a bill, while a shared password shares the chats and the 6-digit codes.
  • Apple Family Sharing can put Apple.com/bill on the organizer and still leave you locked out of the seat.

Series notes

This is Part 4 of AI setup from zero. Previous: Personal vs work accounts. Next: Files, uploads, and where your data goes.

Sources

Written by

Jose S

Founder & Lead Analyst · Analytics Made Simple

Hands-on data strategist, analytics engineering lead, and educator. Writing practical, no-fluff guides to help everyday teams, analysts, and engineers master SQL, AI systems, and modern data architectures.

Keep going

Same lessons in your feed

Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.

Google Search Prefer our practical guides in Google Search & Top Stories: