Neither. There's no password to set, and there's no 2FA to switch on.
How signing in works
You sign in with the passkey on your device. The sign-in screen shows your email address and a Continue with passkey button — approve with your face, fingerprint or device PIN and you're in.
The email link is a separate thing, and it does a separate job. When you first sign up, Enta sends a one-tap link to confirm the address belongs to you. Sign-up then continues into Secure your wallet, where you register your passkey. From that point on, the passkey is what you use — both to sign in and to authorize every transaction.
Why a passkey instead of a password
Your passkey is held in your device's own security hardware and released only by your biometrics. You never see it and you can't copy it.
Nothing to remember. There's no password to choose, forget or reuse.
Nothing to phish. You can't type your passkey into a fake site, and no "support agent" can talk you into handing it over — because it never leaves your device.
Nothing to install. No authenticator app and no SMS codes. Your passkey already requires both your device and you, which is the job a second factor does.
Your email still matters
Your email address is how Enta reaches you and how account recovery starts, so it's still worth looking after.
Keep it current. If you lose access to the address on file and the device holding your passkey, getting back in means account recovery and a 72-hour wait.
Keep your recovery email on a different provider. If both addresses live with the same provider, one outage or one compromise costs you both.
If you've seen older guidance
Instructions about setting up an authenticator app no longer apply. So does anything saying Enta signs you in with an email link every time — that describes an earlier version of the product.
Being signed out
Enta signs you out after 15 minutes of inactivity by default, with a warning 60 seconds before. You can change the duration under Settings → Security. Signing back in is your passkey again.