Set up two-factor authentication
Published on 5 October 2026
With two-factor authentication you log in with your password and a code from an app on your phone. A stolen password is then no longer enough to get in. You have two accounts with us: My CakeHosting, for your invoices and services, and the game panel, for your servers. You switch it on separately for each account.
What do you need?
An authenticator app on your phone, such as Google Authenticator or Microsoft Authenticator. An app like that creates a new six-digit code every 30 seconds.
How do you switch it on in My CakeHosting?
- Log in to My CakeHosting and go to Account and then Security.
- Under Two-factor authentication, click Enable two-factor authentication.
- Scan the QR code with your app. If scanning doesn’t work, type the code shown below the QR code into your app.
- Enter the code from your app and click Enable two-factor authentication again.
You’ll see the message Two-factor authentication has been enabled, and you’re logged out on your other devices. The next time you log in, the Verify 2FA page asks for the code from your app.
Note: My CakeHosting doesn’t give you recovery codes. So make sure your app keeps a backup, or add the code to a second device as well.
How do you switch it on in the game panel?
- Log in to the game panel and click Account.
- Under Two-Factor Authentication, click Enable Two-Step.
- Scan the QR code with your app and enter the six-digit code.
- Enter your game panel password under Account Password and click Enable.
- You now see ten recovery codes. Store them somewhere safe, because they won’t be shown again. Then click Done.
The next time you log in, the game panel asks for the code from your app under Authentication Code.
Lost access: what now?
- Game panel: click I’ve Lost My Device when logging in and enter a recovery code. Each code works once. If they’re used up or lost, open a ticket in My CakeHosting.
- My CakeHosting: email us at info@cakehosting.net from your account’s email address. We’ll help you once it’s clear the account is yours.
What are the common mistakes?
- The wrong time on your phone. The codes depend on the time. If your clock runs fast or slow, they’re rejected. Set the time to automatic.
- Mixing up the two entries in your app. Your app gets two entries that are both called CakeHosting, with your email address: one for My CakeHosting and one for the game panel. Give them their own names in your app if it allows that.
- Thinking SFTP asks for a code too. SFTP only uses your game panel password or an SSH key. So choose a strong password.
Running your server with friends? Give them their own account as a subuser and ask them to switch on two-factor authentication too. More about your account is in First steps after your order, and you can ask for help through contact.