Setting up TOTP
Download a standard authenticator app on your mobile device. Open your Anubis Market profile settings and select the two factor tab. Scan the QR code displayed on screen with your app. Enter the six digit code it generates into the confirmation field. Save the backup codes immediately. These codes act as emergency keys if your phone gets destroyed. Write them on paper and store them somewhere physical and secure.
Using PGP for login
Import the market operator public key into your local PGP agent. Generate your own key pair if you do not already have one. In the market settings, paste your public key. Log in normally using your username and password. The system prompts you to sign a challenge string. Use your command line tools to sign that string with your private key, then paste the resulting signature back into the browser form and submit. This method is slower but independent of phone battery life or carrier networks.
Losing access to your devices
If you lose your phone and did not save backup codes, TOTP recovery becomes difficult. Contact support immediately with proof of identity. They can reset the two factor binding if you provide sufficient evidence of ownership. The process takes several days. Keeping your PGP key in multiple offline locations offers better resilience. A hardware drive stored at home works well for this purpose. Test your recovery process once a quarter.
Losing both your master password and your active two factor token creates a hard lockout. Support can restore access but only after rigorous verification. There is no instant fix for total credential loss. Plan for redundancy in your storage habits now rather than agonizing over it later during a technical incident.
FAQ
Which method is safer, TOTP or PGP?
PGP is generally stronger because it relies on cryptography rather than synchronized clocks. TOTP is far easier to use daily. Choose based on your comfort with command line tools versus smartphone apps.
How often do I enter the second factor?
Every single login attempt triggers the two factor request. You cannot disable it once enabled. The system treats every session start as potentially suspicious until verified twice.
Can I use two methods at once?
No, you activate either TOTP or PGP, not both simultaneously. Switching requires revoking the current method and activating the other through the settings panel.
What if my authenticator app deletes itself?
Use your written backup codes to log in again. Once inside, regenerate new backup codes and rescan the QR code if needed. Delete the old codes after confirming the new ones work.