Set up strong authentication
Attackers steal and reuse passwords, and one stolen password can be enough to take over an Arcade organization, along with its projects, credentials, and agents. That’s why your organization requires strong authentication to sign in to Arcade. If Arcade refused your sign-in in the dashboard, the Arcade CLI, or an client, this page shows you how to fix it.
This page is for anyone who signs in to Arcade Cloud. If you sign in through your company’s single sign-on (SSO), or your company runs its own Arcade deployment, none of this applies to you.
Strong authentication means signing in with a passkey, or adding a second factor (an authenticator app or a security key) to your password or social sign-in. It takes a minute or two to set up in Manage my .
Choose a method
| Method | How you sign in |
|---|---|
| Passkey (recommended) | Your face, your fingerprint, your device PIN, or your password manager. Nothing to type. |
| Authenticator app | Your password or social sign-in, then a 6-digit code from 1Password, Google Authenticator, or a similar app. |
| Security key | Your password or social sign-in, then a tap on a hardware key like a YubiKey. |
A password or a social sign-in on its own doesn’t count.
A passkey is the strongest choice: nobody can phish it or reuse it, and it counts as strong authentication on its own.
If you have a passkey and then add an authenticator app or a security key, Arcade asks for that second factor every time you sign in, including when you use your passkey.
Set up your method in Manage my account
Open Manage my in either of these ways:
- Open your menu in the Arcade dashboard and select Manage my .
- If the dashboard shows Arcade requires secure sign-in, select Manage my in that dialog.
Then follow the steps for the method you chose.
Add a passkey
- Find Passkey under Sign-in methods and select Add passkey.
- Select Create a passkey, then follow your browser’s prompt. You can use your face, your fingerprint, your device PIN, or your phone.
Add a passkey on each device you use, so losing one device doesn’t lock you out.
Set up an authenticator app
- Find Authenticator app under Second factor and select Set up.
- Scan the QR code with your authenticator app. If your app can’t scan, copy the setup key shown with the QR code into the app instead.
- Enter the 6-digit code from your app, then select Verify.
Add a security key
- Find Security key under Second factor and select Add key.
- Enter a name in Name this key so you can tell your keys apart later, then select Add security key.
- Insert or tap your security key when your browser asks.
When you finish, Manage my shows Your account is protected. Then sign in again wherever Arcade refused you:
- Arcade dashboard: sign in again.
- Arcade CLI: run
arcade loginagain. - client: reconnect to your Arcade . Each client does this differently, so check your client’s guide under MCP clients.
Having trouble?
You set up a method, but Arcade still refuses you
Your browser may still hold an Arcade sign-in from before you set up your method, and Arcade reuses it. Sign out of Arcade in this browser by opening Manage my and selecting Sign out. Then reconnect, and sign in with your new method when Arcade asks.
The passkey prompt closed or timed out
Arcade didn’t save anything. Select Add passkey again, and finish the browser’s prompt before it times out. If your browser or device can’t create passkeys, set up an authenticator app or a security key instead.
The authenticator code doesn’t match
Codes change every 30 seconds, so enter the code your app shows right now. If codes keep failing, make sure your phone sets its time automatically.
You’re locked out
If you can’t sign in with any of your methods, email Arcade support to recover your .