WhoisXML API Launches Two-Factor Authentication
WhoisXML API is pleased to announce the addition of support for two-factor authentication (2FA) — an important new security upgrade for user accounts.
What’s new
You can now enable 2FA for your WhoisXML API account by using an authenticator app on your mobile phone. Here’s how it works:
- You can enable 2FA in your WhoisXML API account settings (under General → Two-Factor Authentication).
- You’ll need to scan the displayed QR code with your TOTP (time-based one-time password) app, such as Google Authenticator, Authy, or any other app that supports RFC 6238.
- At each login, you will be prompted to enter both your password and the current 6-digit code from the app, which changes roughly every 30 seconds.
- By default, 2FA is disabled; you must enable it manually in the settings to activate it.
- Currently the only supported method is via authenticator apps (i.e., TOTP), which are more secure than SMS, email, or other weaker second-factor options.

Why this matters
While your WhoisXML API account may not store highly sensitive personal data, aside from the API key, the integrity of your account is still important. Adding 2FA significantly strengthens protection against unauthorized access and is considered a security best practice.
As WhoisXML API CEO Jonathan Zhang says:
“Security is at the heart of what we do at WhoisXML API. Since we're working with many of the leading cybersecurity organisations, it’s only natural that we apply the same high standards to ourselves.”
How to enable 2FA
- Log into your WhoisXML API account.
- Navigate to General → Two-Factor Authentication.
- Click Enable, scan the QR code with your authenticator app, and enter the first 6-digit code that it generates in the respective field in the WhoisXML API settings.
- Save your changes and log out. Next time you log in, you will be asked for your password and the 6-digit code.
If you ever need to disable 2FA, you can return to General → Two-Factor Authentication and turn it off.
Despite not enforcing 2FA, we highly recommend that you enable it.