Start free
Docs / User Guide / Account security
User Guide

Account security

The key icon in the left rail (Account security) opens your own account's sign-in settings. Changes here only affect you: each user turns their own two-step verification on and off.

The Account security screen: setting up two-step verification, with sample data The Account security screen: setting up two-step verification, with sample data
Account security, with sample data. After Turn on two-step verification, the QR code and the setup key appear; Confirm and turn on becomes active once the 6-digit code from the app is entered. The key and QR belong to this sample account.

What is two-step verification?

When it's on, signing in asks for the 6-digit code from the authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, Authy…) after your password. The code changes every 30 seconds; even if someone gets your password, they can't get in without it. Each user turns it on for their own account, and the setting only affects you.

Turning it on

  1. Click the key icon in the left rail (Account security) and press Turn on two-step verification.
  2. Add a new account in your authenticator app: scan the QR code on screen or type the Setup key.
  3. Enter the 6-digit code the app shows and press Confirm and turn on.
  4. Save the 8 recovery codes that appear somewhere safe (Copy codes). They won't be shown again.

Signing in

After your password, the sign-in screen asks for the code. Type the code from your app or a recovery code; if you don't enter it within 5 minutes, sign-in starts over. A wrong code counts as a failed sign-in, just like a wrong password, and hits the same limits. Each code works only once.

Recovery codes

If your phone isn't with you, sign in with one of the recovery codes (for example ABCDE-FGH23); each works once, and the screen shows how many are left. New recovery codes (confirmed with the code from your app) replace the old ones. The codes themselves aren't stored, only a keyed hash, so we can't show you a lost code again.

Turning it off

Turn off needs the code from your app or a recovery code, so someone who takes over your session can't turn it off on their own.

I lost my phone

Sign in with a recovery code, turn verification off and set it up again with your new phone. If you have no recovery code either, ask the account owner or an admin: on the Users screen, the key button on your row (Reset two-step verification) removes it; next time you sign in with your password only and set it up again.

  • Only an account owner can reset an account owner's verification, and nobody can reset their own from the Users screen.
  • Turning it on or off, new recovery codes and resets are written to the Audit Log; wrong codes show up as failed sign-ins.

Security details

  • The authenticator secret is stored encrypted.
  • An accepted code is never accepted again; even if the same code is used in two requests at once, only one gets through.
  • The password step alone never opens a session: you can't get into the panel until the code is verified.
Was this page helpful? Send feedback