Coinbase Pro

2-step verification troubleshooting

Coinbase offers 2-step verification, known also as 2-factor (2FA) or multifactor authentication, as an added security layer when signing in.

2-step verification provides additional protection for your account, by being required to provide a unique verification code, in addition to your username and password.

Some events that can trigger 2-step verification

  • Sign-in attempt from an unrecognized device

  • Sign-in attempt from a unrecognized phone number

  • Sending crypto out of your Coinbase account

Learn about 2 step verification and the various types of 2-step verification here.

Not receiving the SMS (text) codes

  • Due to issues with the SMS network itself, codes may not get delivered to everyone. You may want to instead use an authenticator app to complete this step, since they don't require internet connectivity or SMS coverage

  • Your SMS inbox may be full. Try deleting some messages from your inbox and request another code

  • If you're using an authenticator app (like Google or Duo), you won't get SMS codes sent to your phone. You will need to use your authenticator app for codes instead

Note: After several requests to resend the SMS code, our system may temporarily stop sending them as a security measure. After 24 hours we'll resume sending codes via SMS. If you've already waited 24 hours and still aren't receiving the codes, check with your phone carrier to see if they're blocking our SMS messages

The SMS codes aren't working

If you continue to attempt SMS verification, and are receiving an invalid error, a common reason for this happening is that too many requests are happening back to back. This can invalidate some of the codes before they're able to get to you, as they can take up to 60 minutes to arrive. We recommend re-trying SMS verification, requesting the codes only one time within a 60 minute timeframe.

You may also be using TOTP authenticator rather than SMS for verification. Check your security settings to see. If you are using a TOTP authenticator, see our Duo and Google Authenticator (TOTP) article for further help.

Additionally, you can choose the Try Another Way option. If you’re using SMS as your primary 2FA, Coinbase Security Prompt (Push Notification for 2FA) will be shown as an alternative 2FA method if you have previously enabled it on your account.

If you have a new phone number and still have access to your old number, try the following steps.

  1. Sign in to your account with your username, password, and 2-step verification code from your old number

  2. Go to your Security Settings page

  3. Verify your new phone number in the 'upgrade your 2-factor authentication' section

  4. Go to 'Text Message'

  5. Go to 'Add phone number'

  6. Set your new phone number as the Primary number

  7. (optional) Delete your old number

If you are using a NEW SIM card with your old number, please follow instructions for new phone, new number below instead.

New phone, new phone number

Note: This process takes 48-72 hours

If you have a new phone number and no longer have your old number:

  1. Sign in to your account with your username and password

  2. When prompted for a 2-step verification code, select Try another way > Update your phone number 

    • Note: If you do not get this prompt after logging in, try logging in on an incognito browser or clearing your cache and trying again

  3. For security reasons, you'll be asked to provide:

    • A photo of the front and back of your photo ID

    • A photo of yourself taken live by webcam (this process must be completed through the website and cannot be completed using the mobile app.)

Once you complete all the steps above, it may take up to 48 hours until you are able to sign in to your account. You’ll receive an email confirmation once the review has been completed, then you can log in and update your phone number in your account settings.

Note:

  • Once account access has been restored, sends may be unavailable for 24 hours. After that period, you should have full trading capabilities.

  • If you sign in while the review is still in progress, you’ll be required to enter the PIN code you received during the initial account recovery steps.

If you want to use your new mobile device to access Coinbase and still have your old mobile device:

  1. Sign in to your account with your username, password, and 2-step verification code from your old device (if your old device doesn't have internet service, you'll need to connect to trusted wi-fi network)

  2. Go to your Security Settings page

  3. Enter the code from your authenticator app (Note: regenerating your secret key will invalidate your old device tokens)

  4. Scan the new secret key with your new Authenticator app on your new device 


Disable your authenticator:

1. From a computer, sign in to Coinbase using your email address and password.

2. When prompted for a 2-step verification code, select Try another way > Update your authenticator app

  • Note: If you do not get this prompt after logging in, try logging in on an incognito browser or clearing your cache and trying again

3. Follow the rest of the instructions to complete an Account Recovery.

  • Please note that while the pictures of the front and back of your ID can be uploaded from files, the photo of your face will need to be taken live by webcam. This process must be completed through the website and cannot be completed using the mobile app.

  • The account recovery process usually takes 48 hours to complete, but can sometimes take longer. When the recovery process has completed and your account has been verified, you will receive an email confirmation and should be able to log in to update your 2FA method in your account settings. 

  • If you log in from a new device while the review is still in progress, you’ll be required to enter the PIN code you received during the initial account recovery steps. 

  • Once account access has been restored, may be unavailable for 24 hours. After that period, you should have full trading capabilities.

For more information on this, see Regain access to your account.

New phone, new phone number

  1. You'll need to first update your phone number in order to disable the authenticator app on your previous phone. You’ll then need to complete the account recovery process to enable the authenticator app on your new phone (this may take up to 48 hours). 

  2. To disable your authenticator app:

    • From a computer, sign in to Coinbase using your email address and password.

    • When prompted for a 2-step verification code, select Try another way > Update your phone number

      • Note: If you do not get this prompt after logging in, try logging in on an incognito browser or clearing your cache and trying again

      • Follow the rest of the instructions to complete an Account Recovery.

        • For security reasons, you'll be asked to provide:

          • A photo of the front and back of your photo ID

          • A photo of yourself taken live by webcam (this process must be completed through the website and cannot be completed using the mobile app.)

        • The account recovery process may take up to 48 hours to complete, but can sometimes take longer. 

        • When the recovery process has completed and your account has been verified, you will receive an email confirmation and should be able to log in to update your 2FA method in your account settings.

My codes aren't working

Check that the clock on your device is set to the correct timezone. An incorrect clock can cause codes to be out of sync.

If you’re not receiving the prompts, select to resend the security prompt (if you haven’t already).

If you’re receiving the prompts but getting an error message, you can select to resent the security prompt, or Try another way from the prompt to receive a text message instead.

If you’re not receiving the prompts on your mobile device, kindly check the following: 

  • If you're using an authenticator app (like Google or Duo), you won't get Coinbase Security Prompt notifications. You’ll either need to use your authenticator app for codes, or switch to Coinbase Security Prompt.

  • Check your mobile device settings to make sure that notifications are enabled for the Coinbase mobile app (note that this is different from the notification settings in your Coinbase mobile app). Learn more about checking your device settings on Android or iOS.

  • Make sure you have a stable internet connection. A poor connection can result in delayed or missed push notifications. Try the following: 

    • Turn on/off your WiFi connection

    • Try switching to mobile data

    • Temporarily turn off your VPN/Proxy connection (if applicable)

    • Close any other apps to reduce bandwidth allocation

  • Make sure you’re using the latest version of the Coinbase mobile app (you can verify by checking the app store for iPhone or Android.) 

  • Make sure you’re using the latest version of your phone software (please be advised that the mobile app may not work on a rooted/jailbroken phone). 

If you’re still having trouble receiving Coinbase Security Prompt notifications after following the above recommendations, please contact us and provide a brief summary of the issue (a screenshot/screen recording is recommended for us to better troubleshoot the issue).

Authy is no longer supported on Coinbase, but these steps will help you disable Authy and add a new authenticator. 

Steps for disabling Authy (you will need to verify your identity):

1. Sign in to your Coinbase account using your email address and password. 

2. When prompted for your 2-step verification code, select I need help > I can’t access my authenticator app anymore.

3. Follow the rest of the instructions to complete the process (a government-issued ID is required for completion).

If you don't receive a 2-step prompt when signing in, try clearing your browser cache and/or following the above steps in your browser’s private or Incognito mode.

The account recovery process usually takes 48 hours to complete but can sometimes take longer. After 24 hours, you should be able to sign in to your account via SMS verification codes and complete buys and sells. After 48 hours, you should have full trading capabilities restored. For your security, sends will be disabled on your account until the full security period has passed. If you sign in before the security period is complete, you’ll receive a pop-up notification informing you that sends are temporarily disabled.

Note: We are not able to remove 2-step verification completely, so you will need to at least have SMS, but we recommend a security key or TOTP authenticators like Google or Duo.