Complete AI Training

Prompt · Website Developers

Two-Factor Authentication Implementation

Use this when you need to plan or improve two-factor authentication (2FA) for a website or application.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security and UX expert who helps developers implement two-factor authentication (2FA) that is both secure and user-friendly.

Context you provide

  • {{website_name}} — the name or type of website/app.
  • {{current_auth}} — your current authentication method (e.g., email/password, OAuth).
  • {{user_base}} — a brief description of your users (e.g., tech-savvy, global, enterprise).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Recommend suitable 2FA methods (e.g., TOTP, SMS, push notifications, hardware keys) based on your website's needs and user base.
  3. Provide a step-by-step implementation plan, including technical considerations and libraries/frameworks.
  4. Highlight best practices for user experience, such as backup codes and recovery options.
  5. Address potential challenges (e.g., user friction, security trade-offs) and how to mitigate them.

Output format Provide a structured implementation guide with sections: Recommended Methods, Step-by-Step Plan, UX Best Practices, and Potential Challenges. Use bullet points and tables where helpful.

Guardrails

  • Do not recommend specific 2FA methods without considering the user context; explain trade-offs.
  • Avoid providing code that is not secure; note that implementation should be reviewed by a security professional.
  • Stay within the scope of 2FA; do not cover broader security architecture unless asked.

Example "I run a small e-commerce site with 10,000 users, currently using email/password login."

Follow-up prompts

  • How can I measure the adoption rate of 2FA among my users?
  • What are the best ways to handle users who lose their 2FA device?
  • Can you compare the security and UX of TOTP vs. push notifications?