How to enable and disable Google Authenticator on MEXC?

MEXC marks Passkey as the recommended login method right in its security settings, and that is how accounts run in 2026: a fingerprint confirms logins, no codes to type. Google Authenticator moved to the supporting role, but it still guards what matters: withdrawals and security changes ask for the offline six-digit code that refreshes every 30 seconds. Setup takes about five minutes; the one thing you must not skip is saving the backup key, because with it a lost phone costs you minutes, and without it, potentially days of verification. And one rule above all: never share, show or disable your authenticator because someone asked you to. MEXC support does not ask for that; scammers do.

Updated Sep 03, 2026 6 min read Checked regularly
How to Set Up Google Authenticator on MEXC

What You Need Before You Start

Install Google Authenticator on your phone first: App Store or Google Play, publisher Google LLC, free. MEXC offers a choice of two apps, its own MEXC Authenticator or Google's; Google is the practical pick if you use more than one exchange, since one app then holds all your codes side by side. Besides the app you need access to your MEXC account and paper for the backup key. Paper, not a screenshot: a screenshot lives in the same cloud an attacker may reach.

How to Enable Google Authenticator on MEXC

  1. Log in to MEXC, click the profile icon and open "Security".
  2. Find "MEXC/Google Authenticator" in the "Two-Factor Authentication (2FA)" section and click "Set Up". MEXC security settings
  3. The setup wizard opens with three steps. The first one offers to download the app; you already have it, click "Next".
  4. Step two shows a QR code and the Key next to it. Write the key down on paper before anything else: it is the recovery key that restores your authenticator if you change or lose your phone.
  5. Open Google Authenticator, tap "+" and either "Scan a QR code" or "Enter a setup key". A MEXC entry with a six-digit code appears.
  6. Type the current code into the "Authenticator Code" field of step three and click "Submit" before the 30-second timer rolls the code over. If it rolls, just enter the fresh one. Code confirmation

Back in "Security", the "MEXC/Google Authenticator" line shows "On" and the Security Level bar reads "High". That pair is the current standard: passkey for everyday logins, the authenticator guarding withdrawals.

2FA enabled

Setting up from the MEXC mobile app works the same way with one catch: the QR code is on the same phone that needs to scan it. Use "Enter a setup key" instead of scanning.

How Google Authenticator Works

The app and MEXC share that secret key and both run the same math on the current time; every 30 seconds the result changes, and the result is your code. No internet involved, which is why it works offline and in roaming, and why the single most common failure is a drifted phone clock: wrong time, wrong codes. The fix is automatic date and time in the phone settings plus "Time correction for codes" → "Sync now" in the app on Android. One caveat of the modern app: entries can sync through your Google Account, and then your MEXC codes are exactly as safe as that Google Account. Give it its own strong 2FA, or the lock ends up weaker than the door.

How to Disable Google Authenticator on MEXC

  1. Open "Security" and click "Remove" next to "MEXC/Google Authenticator".
  2. MEXC opens a confirmation page: withdrawals and fiat withdrawals will be disabled for 24 hours after removal, and dropping to a single verification method raises the account's risk. Tick both boxes.
  3. Click "Unlink Anyway" and confirm with an authenticator code or your passkey.

Unlink confirmation

Three things to know before you do it. If anyone asked you to disable 2FA — support, a "safe account" manager, an investment advisor — stop: that request is the scam itself, no legitimate service needs your protection off. The 24-hour hold is not a bug but the point: it is the window in which you would notice an attacker stripping your protection. And MEXC will not let the account stand naked anyway: it must stay linked to at least an email or a phone number. When switching phones, the right order is: restore the entry from the backup key on the new device, test a login, then wipe the old one.

What If You Lose Your Phone

With the backup key: minutes. Install Google Authenticator on any device, tap "+" → "Enter a setup key", name it MEXC, type the key, the codes are back.

Without the key: MEXC's reset flow. In the app: profile icon → "Security" → select the verification to unlink → tap "Security verification unavailable?" and submit the request; on the web the same lives behind "Reset Your Security Verification". The request goes to review, the account survives, but you trade minutes for days, and that difference is the backup key on paper.

FAQ
They generate the same kind of codes. Google's wins on one thing: it is exchange-agnostic, so Binance, Bybit and KuCoin entries live next to the MEXC one. Pick MEXC's own app only if MEXC is your single exchange.
Almost always the phone clock. Turn on automatic date and time, sync time in the app settings, wait for a fresh code. If you enabled 2FA several times, only the newest entry works: delete the stale ones.
Deleting the app does not turn off 2FA on MEXC, the account still asks for codes. Reinstall Google Authenticator and restore the entry with your backup key. No key: the reset flow above.