DocsAccount & settings

Two-factor authentication

Add TOTP two-factor authentication with one-time backup codes to your account, available on every plan and verified before it ever turns on.

Two-factor authentication (2FA) adds a second step at sign-in. On top of your password, you enter a rotating six-digit code from an authenticator app. A stolen password alone can't get anyone in.

It's free on every plan. We use the standard time-based one-time password (TOTP) approach, with one-time backup codes in case you lose your phone.

What it does

With 2FA enabled, signing in needs a current code from your authenticator app on top of your password or your Google/Microsoft sign-in. If you ever lose the device, one-time backup codes let you back in. 2FA is opt-in per user and set up from your account page.

How to use it

Enable it from your account:

  1. Confirm your password to begin. Signed up with Google or Microsoft and never set a password? There is no password step. Enrollment starts right away.
  2. Scan the QR code with any authenticator app, for example 1Password, Google Authenticator, or Authy.
  3. Enter one code the app shows to finish. 2FA is not active until this code verifies.
  4. Save your backup codes. They are shown once, at enrollment, and each one works a single time.

To turn 2FA off, enter a current code from your authenticator app, plus your password if the account has one. The same applies to making a new set of backup codes. Lost the device? A backup code signs you in but does not loosen the account. Write to us and we will help.

After 2FA is on, sign-in for your account is challenged at /two-factor. There you enter a current authenticator code, or a backup code, to continue.

Watch out

Backup codes are displayed only once, right after you enroll, and are never shown again. Save them somewhere safe before you leave the page. They are your way back in if you lose your authenticator device.

How it's computed / enforced

Enrollment is verify-first. Enabling generates the TOTP secret and backup codes, but 2FA does not switch on until you enter one valid code. A misconfigured authenticator cannot lock you out, because the setup fails before it takes effect rather than after.

Enabling asks for your password when the account has one. Disabling, and making new backup codes, ask for a current authenticator code, plus the password on password accounts. So someone with a live session but not your device cannot change your 2FA state. The backup codes screen gives you copy and download buttons.

Limits

  • No plan gate. 2FA is available on every plan.
  • Enrollment is per user. Each member sets 2FA up on their own account. A workspace owner or admin can additionally require 2FA of every member on Security. See Sessions and security policy.
  • Backup codes are shown once and each is usable a single time.