two-factor.txt
Add optional two-factor authentication. Stack: <stack>.

- Use TOTP (an authenticator app) rather than SMS. Say why in one
  line so I can explain it to users.
- Enrolment: show a QR code and the secret as text, then require a
  correct code before it's switched on. Never enable it on the
  strength of the QR being displayed.
- Recovery codes, generated once, shown once, stored hashed.
- Allow a small time window either side for clock drift. Say how much.
- Reject reuse of a code within its window, so a captured code is
  useless.
- Rate limit verification attempts.

Then: what's my process when someone loses both their phone and their
recovery codes?

Answer the lost-everything question before you launch this. Without a process, two-factor turns a support request into a permanently locked account.