Skip to content
,

2FA, recovery, and shared family or team plans

12 min read
Featured image: 2FA, recovery, shared plans. Editorial illustration for Analytics Made Simple.

Priya’s iPhone lit up at 4:12pm on Tuesday with a gray sheet: Enter the 6-digit code. The client workshop was Wednesday at 10:00am. Eighteen hours. The Claude Project on that account held the agenda, three case slides, and the name list she had promised not to print. She had never turned on two-factor authentication (2FA). Her partner had used her Apple ID the night before, after a new iPhone kicked him out of the App Store, and tapped Claude Pro in the iPhone app because the website felt like extra work. Somewhere in that tap, a 2FA prompt got enrolled against a device she did not hold. The codes rotated on his lock screen. Hers stayed empty.

This is Part 10 of Phase P, and Part 4 of AI setup from zero. Part 7 opened the account and the bill in accounts, Free vs paid. Part 8 picked a surface in browser vs mobile vs desktop. Part 9 split personal vs work. You are here because the lock is still a shared Apple ID, a screenshot in Camera, or a family plan you treated like Netflix. Next is files, uploads, and where your data goes (Part 5 of this series). The chooser stays at Which AI product should I use?. Security screens move. As of writing (August 2026), confirm Settings the week you click.

What you’ll learn

  • How to turn on 2FA on the account you use, on a device you hold
  • When an authenticator app beats SMS, and when a passkey is the stronger add-on
  • Where recovery codes belong (and why Camera is a bad drawer)
  • Why a family or team plan shares a bill, and a shared password shares the chats
  • How Apple Family Sharing can hide who paid for Claude or ChatGPT in the App Store

2FA is a second door

A password, a magic email link, or “Sign in with Google / Apple” is door one. 2FA is door two: a 6-digit code, a tap on a trusted phone, or a passkey. Priya’s partner did not steal her password. He sat inside her Apple ID, which is door one for every “Sign in with Apple” and for App Store billing. Then a 6-digit prompt appeared that she had never asked for.

Two locks get mixed up on iPhone. Apple’s own 2FA protects the Apple ID (Settings, your name, Sign-In and Security). Vendor 2FA protects ChatGPT, Claude, Gemini, or Grok inside that product. You can have Apple 2FA on and still have ChatGPT with MFA off. You can have ChatGPT MFA on and still have a partner buying Pro on your Apple ID. Turn both on. Do it on hardware you hold. If you used Google or Apple to sign in, harden that identity first. Grok follows the X account. Claude Team can inherit company single sign-on (SSO). Consumer Claude still wants you to open Settings and look; as of writing some accounts lean on email links plus Google or Apple.

Four locks: password or SSO, authenticator or passkey, recovery codes in a real place, backup email or recovery contact
Four locks: password or SSO, authenticator or passkey, recovery codes in a real place, backup email or recovery contact

Rule of thumb: The person who can see the 6-digit code owns the account. If that person is not you, fix the enrollment before you fix the slides.

App vs SMS vs passkeys

OpenAI’s Help Center (as of writing) lists four MFA options on consumer ChatGPT: an authenticator app (Google Authenticator, Authy, 1Password, Apple Passwords), a push to a trusted device, a 6-digit text on SMS or WhatsApp, and a passkey. Manage them under ChatGPT Settings, then Security. After MFA is on, it applies across ChatGPT and the API Platform. Workspace admins cannot currently force MFA for every seat. That is on each person, or on company SSO if you are on a work plan.

MethodWhat you seeWeak againstUse it when
Authenticator app6-digit code every 30 seconds in an app you choseA stolen unlocked phone, or a QR someone else scannedDefault for ChatGPT, Google, and any vendor that offers TOTP
SMS or WhatsApp6-digit text to a phone numberSIM swap, recycled numbers, a handset you no longer haveTemporary only, then add an app or passkey
PasskeyFace ID, Touch ID, or a hardware key confirmLosing the only device that holds itAdd as a second method, especially on ChatGPT

CISA’s phishing-resistant MFA note is blunt: SMS and voice codes can be stolen with SIM swap. An authenticator app is better because the secret lives on the device, not at the carrier. A passkey (FIDO / WebAuthn) is stronger still, because a fake login page cannot replay it the way it can replay a typed 6-digit code. You still need a spare. Scan the ChatGPT QR with your authenticator and write the recovery material before you close the sheet. On Claude, open Settings and look for security or two-factor; if the screen is still email-link plus Google or Apple, harden that Google or Apple account today. Gemini follows Google 2-Step Verification. Grok follows X. Re-check. Names move.

Recovery codes live somewhere real

When you enroll an authenticator, the vendor usually shows a short list of one-time recovery codes, or one long recovery key. You will not see that list again unless you rotate it. Photographing it into Camera puts a spare key in the same roll as lunch photos and iCloud Photos. Emailing it to yourself puts it in the inbox an attacker already wants. A real place is a password manager vault (1Password, Bitwarden, Apple Passwords on accounts you control), or a printed page in a drawer you can open on a Sunday.

If you use OpenAI’s Advanced Account Security (rolled out for eligible consumer accounts in 2026), recovery gets stricter: email and SMS recovery can go away, passkeys or hardware keys become the sign-in, and a recovery key is the spare. OpenAI’s own article says a valid recovery key starts a wait (as of writing, 48 hours) before you can sign in again, and Support will not reset you if you enrolled. Do not turn that mode on until the codes are stored.

SpareWhat it isFails whenPut it here
Recovery codes / keyOne-time strings from the vendorYou screenshotted them into CameraPassword manager, or paper in a drawer
Backup emailA second inbox the vendor can mailIt is the same Gmail you log in withA mailbox you still open this month
Passkey on a second deviceFace ID on the laptop as well as the phoneYou only enrolled the iPhoneWork Mac plus phone, then store recovery too
Recovery contact (Apple)A person who can generate a code for your Apple IDThat person is the one who bought the appSomeone who will pick up, in person

Backup email is not a second copy of the same address. If ChatGPT is on dana.work@gmail.com, a plus-alias in the same inbox is one lock. Use a mailbox you will still have in a year. Priya later found “IMG_4481” in Camera from 11:07pm Monday: the Apple 2FA QR her partner had pointed at her phone “for a second.” Treat recovery material as cash, not as a meme.

A family plan shares the bill

Four share models: shared login, family-style bill with separate chats, team seats, Apple Family Sharing that hides the payer
Four share models: shared login, family-style bill with separate chats, team seats, Apple Family Sharing that hides the payer

A family or team plan is an invoice with more than one seat or household member. Each person still signs in as themselves. Chats, memory, uploaded files, and 2FA stay on that login. You share the card. You do not share the password. A shared login is the other thing: one email, one password, two humans. The Project with the client name list is visible to whoever opens the app. The 6-digit codes go to whoever enrolled the authenticator. OpenAI’s terms treat a ChatGPT account as one user. Anthropic’s consumer terms are the same shape for Claude Pro.

As of writing, ChatGPT Plus is one person at the everyday $20 rung. ChatGPT Team is seats with an admin and a minimum seat count (commonly two). Claude Pro is one person. Claude Team is seats (Standard vs Premium, minimums, SSO). Anthropic has not shipped a Netflix-style family plan. If two adults both need Claude, two Pro logins or a real Team org beat one password on the fridge. Google One AI plans can share storage and, on current family-plan language, AI benefits with other members of the family group (age gates apply; confirm the live page). Each member still has their own Google account. Gemini chats do not merge. Grok paid paths follow grok.com and/or the X account. Sharing an X password is still a shared login.

Apple Family Sharing can hide who pays

Apple Family Sharing is not an AI family plan. It is Apple’s household: an organizer, members, optional Purchase Sharing, and shared subscriptions Apple itself supports (iCloud+, Apple TV, and so on). When Purchase Sharing is on, the organizer’s payment method is the default card. A family member taps Buy. APPLE.COM/BILL lands on the organizer. The organizer can open purchase history and see the line. In-app subscriptions are shareable only if the developer turned Family Sharing on for that product. Many AI apps do not. You get a charge on the organizer card and a seat tied to one Apple ID.

Priya was the Apple ID. Her partner was the thumb. The Visa under Family Sharing belonged to her, so finance already knew the $19.99 from Part 7’s rail. Settings, her name, Subscriptions showed Claude. His phone showed it too, because he was signed into her Apple ID in the App Store. That is the hide: the household sees one bill, two people see one login, and 2FA follows whoever completed Apple’s prompt on the new iPhone. Buy the plan on the vendor website while logged into the email you mean to keep. Turn off the in-app subscribe button. Do not sign a partner’s iPhone into your Apple ID “for five minutes.” Five minutes is how 2FA moves house.

Worked example: 18 hours, one prompt

ClockWhat she thoughtWhat it was
Monday 11:07pmHe is downloading Claude on my phone for the tripApp Store session on her Apple ID, in-app Pro, QR pointed at her Camera
Tuesday 4:12pmA glitch. I will retry6-digit 2FA bound to his device, Project still on that account
Tuesday 6:40pmSupport will sort it before 10:00amVendor support cannot see an Apple-billed seat the same way, and she had no recovery codes
Wednesday 10:00amWorkshop with the agendaShe rebuilt the outline from email. The name list stayed in Claude

The 18-hour hole was not a missing feature. She still had her laptop. She did not have door two. The partner was in back-to-back meetings with Do Not Disturb on, so the 6-digit codes sat unseen. Fix, in order: sign his iPhone out of her Apple ID; cancel the App Store Claude subscription in Apple’s list (the claude.ai billing page may not show it); open Claude on the website with her work email from Part 9; enroll authenticator 2FA on her phone; save recovery codes into 1Password before closing the dialog. If the Project is gone, treat the name list as spilled and tell the client. His Claude, if he wants one, is his email and his card.

A recovery kit you can copy

Paste this into the same team note you started in Part 7. Fill the brackets. If a line is still blank on Friday, that line is the lock that will fail.

Recovery kit (one vendor)
Account email: [work address from Part 9]
Sign-in method: [email+password / Google work / Apple (only if I own this Apple ID)]
Apple ID on this phone: [mine / signed out of partner]
2FA method: [authenticator app name] on [my phone]
2FA backup: [passkey on this Mac / none yet]
SMS 2FA: [off, or number I still hold]
Recovery codes stored: [1Password vault / printed envelope in desk]
NOT stored: Camera, iCloud Photos, Slack, email to self
Backup email: [different inbox I opened this month]
Recovery contact: [name, in person, not the person who buys apps on my ID]
Family Sharing organizer: [me / partner]
Purchase Sharing: [on / off]
App Store subscribe for this vendor: OFF (website billing)
Shared login with anyone: NO
Owner: [Priya]
Last checked: [date]
Cancel path: Settings > Security (vendor web), plus Apple Subscriptions if a $19.99 line exists

What that checklist does: it names the human who holds the 6-digit app, the drawer that holds the spare codes, and the card that will see APPLE.COM/BILL. If “Apple ID on this phone” is not yours, stop and sign out before you enroll anything else. Enrolling 2FA on a shared Apple ID gives the other person a stronger grip.

Common mistakes

  • Leaving 2FA off because the vendor sent a magic link last time.
  • Letting a partner scan the QR “for a second.” The secret now lives on their phone.
  • Saving recovery codes as a screenshot in Camera or in iCloud Photos.
  • Using SMS as the only second factor, then swapping SIMs for a trip.
  • Sharing one Plus or Pro password with a household and calling it a family plan.
  • Buying Claude or ChatGPT in the iPhone app on someone else’s Apple ID, then asking finance to read APPLE.COM/BILL.
  • Turning on OpenAI Advanced Account Security before the recovery key is in a vault you can open.
  • Setting the backup email to the same inbox as the login.

How to practice this week

Block 20 minutes. Open the vendor you use (one, from Part 7). Confirm the email is the work identity from Part 9. Turn on authenticator 2FA on a phone in your hand. Store the recovery codes before you close the tab. Sign the App Store out of any Apple ID that is not yours. Check Family Sharing, Purchase Sharing, and Apple Subscriptions for a surprise Claude or ChatGPT line. If two adults both need a paid seat, buy two logins or a real Team org. Do not paste one password into both phones.

Next in this series: files, uploads, and where your data goes (Part 5). The lock is only useful if you know which files you put behind it. Related paths: AI for writing, privacy and run-it-yourself, Learn, and Practical AI.

Quick recap

  • Turn on 2FA yourself, on a device you hold.
  • Prefer an authenticator app or a passkey. Treat SMS as temporary.
  • Put recovery codes in a vault or on paper. Not Camera.
  • Family and team plans share a bill. A shared password shares the chats and the 6-digit codes.
  • Apple Family Sharing can put APPLE.COM/BILL on the organizer and still leave you locked out of the seat.

Sources