Skip to content

two locks are better than one

Two-factor authentication

Two-factor authentication (2FA) asks for a 6-digit code from your phone's authenticator app whenever you log in — so a stolen password alone can't open your account. It's optional, free on every plan, and each admin turns it on for their own account.

Turn it on

  1. Open Security.

    Click your name in the top-right of the dashboard, then Security, then Set up two-factor authentication.

  2. Scan the QR code.

    Use any authenticator app — Google Authenticator, 1Password, Authy, Microsoft Authenticator all work. Can't scan? Type the setup key shown next to the QR code into the app instead.

  3. Enter your first code.

    Type the 6-digit code your app shows and click Turn on two-factor. Nothing changes about your login until this step succeeds, so you can't lock yourself out halfway through.

  4. Save your recovery codes.

    You'll be shown ten recovery codes once. Print them or put them in your password manager — each one is a single-use replacement for your phone.

Logging in with 2FA

Log in with your email and password like always. You'll then be asked for the 6-digit code from your authenticator app. If you don't have your phone, enter one of your recovery codes instead — it works once and is then crossed off.

Lost your phone?

  • Have recovery codes? Log in with one, then go to Security, turn two-factor off, and set it up again on your new phone (you'll get fresh recovery codes).
  • Lost the codes too? Contact support and we'll verify it's really you before resetting two-factor on the account.

Turn it off

On the Security page, enter your password next to Turn off two-factor. That removes the authenticator and any unused recovery codes; you can turn it back on any time.

Running low on recovery codes? Turning two-factor off and on again issues a fresh set of ten.