Skip to content

← All documentation · Running the company

Two-factor authentication

Web and mobile2 min readUpdated

Turn on a second step from Settings → Security and it is asked for however you sign in, social sign-in included, using an authenticator app, a security key or a text code — with recovery codes for the day the phone is lost.

A password is one thing somebody can lose. A second factor is the difference between losing it and losing the company's customer list, its schedule and its payment settings.

Two-factor authentication is optional and per person: each member of your team turns it on for their own account, and the ones who have not are not locked out.

Turning it on

Open Settings → Security in the web app. You can enroll:

  • An authenticator app — Google Authenticator, 1Password, Authy or any other app that reads a standard six-digit code.
  • A security key or passkey — a hardware key, or the fingerprint or face unlock built into the phone or laptop you already carry.
  • A text message — a code sent to your phone.

Enroll more than one if you can. Two ways in means a lost phone is an inconvenience rather than a lockout.

Recovery codes

Enrolling gives you ten single-use recovery codes. Each one signs you in once when you cannot reach any of your factors. Print them, or keep them somewhere that is not the phone they are there to replace — a recovery code in a note on the locked phone is not a recovery code.

You can regenerate them at any time, which invalidates the old set.

It applies however you sign in

The second step is asked for on every way into your account: with a password, and with every connected account — Google, Apple, Microsoft, Facebook, LinkedIn, X, Instagram and TikTok alike. Signing in through a social provider is not evidence that a second factor happened, so it does not count as one. See Sign-in and social accounts for how credentials sit on one account.

Signing in on the mobile app asks for the same second step. Enrolling is done on the web.

Trusting a browser

You can let a browser you own skip the second step for 30 days. It is a convenience on your own laptop and a bad idea on a shared computer — and clearing every trusted browser at once is one of the actions below.

The actions that ask again

Some things are worth proving twice even in a session you already opened. Changing your password or your email address, enrolling or removing a factor, regenerating recovery codes, clearing your trusted browsers and deleting your account all ask for a factor within the last five minutes, on a trusted browser as much as any other.

If somebody loses everything

An owner cannot reset a colleague's second factor from inside the app — that would make the factor only as strong as the owner's own account. Contact support, who can reset it after checking who is asking. See Getting help.

What it does not cover

Two-factor protects a sign-in. It is not a substitute for giving people the role they actually need: somebody who should not be moving money should not have the permission to, whether or not their account has a second factor. See Team roles and permissions.