Securing your account with two-factor authentication and passkeys
With two-factor authentication, a leaked password alone is not enough to get into your account. We explain which methods Ohhi supports, what a passkey actually is and how to set everything up in a few minutes.

Illustrative image · a second step next to your password
Your Ohhi account holds your photos and videos, often including those of your children. By default, access to that account hangs on one thing: your password. In practice, passwords leak regularly, usually because the same password was also in use at another service that got hacked, or because someone entered it on a fake login page. Two-factor authentication limits the damage of such a leak: whoever has only your password does not get in.
Which methods Ohhi supports
After entering your email address and password, a second step follows. At Ohhi you can set up two things for it. The first is an authenticator app on your phone or in your password manager, which shows a new six-digit code every thirty seconds. You type that code in when logging in.
The second is a security key or passkey: a YubiKey, Touch ID, Windows Hello or a passkey on your phone. There is nothing to type; you confirm the login with a touch or your fingerprint. A passkey is also bound to the domain it was created for. On a fake login page at a different address the key simply does not work, which makes this method immune to phishing.
The secret of your authenticator app is stored encrypted in our database, and backup codes are kept only as a hash. Whoever has a copy of the database cannot reproduce your second step with it.
How to turn it on
- Log in at ohhi.nl and open the "Two-factor authentication" section in your profile, or go straight to the settings page.
- Choose an authenticator app (scan the QR code and confirm the first code), a security key or passkey, or both. Several keys side by side work too, for example your phone and a YubiKey.
- Keep the ten backup codes you receive during setup, for example in your password manager. Each code works once and is your fallback entrance if you lose the phone or key.
From that moment on, every new login asks for the second step. You can generate new backup codes at any time; you confirm your password first, and the old codes become invalid. If you lose both your second step and your backup codes, you can no longer log in on your own. So keep the codes somewhere you would not lose together with your phone.
Two-factor authentication controls who can log in as you; who you share your photos with remains a separate choice. How to keep that sharing contained, you can read in sharing photos of your kids, only with who you choose. Where your photos are stored is covered in servers in Europe: what it really means. You can turn it on right away in your profile, under "Two-factor authentication".

