If you enable email two-factor authentication from Settings → Security, every email/password sign-in is followed by a one-time 6-digit code sent to your inbox. Enter the code on the prompt that appears immediately after sign-in to complete the session. SAML SSO and OAuth (Google, GitHub, GitLab) sign-ins are not subject to this prompt — your identity provider is treated as the second factor. API keys are also unaffected: they are pre-issued credentials and continue to work without an additional code.