---
title: "Two-factor authentication · BlastoClean docs"
description: "Adding a second step to sign-in: authenticator apps, security keys and text codes, recovery codes, trusted browsers, and the actions that ask again."
url: "https://www.blastoclean.com/docs/two-factor-authentication"
---

# Two-factor authentication

Running the company · Web and mobile · 2 min read · updated August 22, 2026

**Turn on a second step from Settings → Security and it is asked for however you sign in, social sign-in included, using an authenticator app, a security key or a text code — with recovery codes for the day the phone is lost.**

A password is one thing somebody can lose. A second factor is the difference
between losing it and losing the company's customer list, its schedule and its
payment settings.

Two-factor authentication is **optional and per person**: each member of your
team turns it on for their own account, and the ones who have not are not
locked out.

## Turning it on

Open **Settings → Security** in the web app. You can enroll:

- **An authenticator app** — Google Authenticator, 1Password, Authy or any
  other app that reads a standard six-digit code.
- **A security key or passkey** — a hardware key, or the fingerprint or face
  unlock built into the phone or laptop you already carry.
- **A text message** — a code sent to your phone.

Enroll more than one if you can. Two ways in means a lost phone is an
inconvenience rather than a lockout.

## Recovery codes

Enrolling gives you **ten single-use recovery codes**. Each one signs you in
once when you cannot reach any of your factors. Print them, or keep them
somewhere that is not the phone they are there to replace — a recovery code in
a note on the locked phone is not a recovery code.

You can regenerate them at any time, which invalidates the old set.

## It applies however you sign in

The second step is asked for on every way into your account: with a password,
and with **every connected account** — Google, Apple, Microsoft, Facebook,
LinkedIn, X, Instagram and TikTok alike. Signing in through a social provider is
not evidence that a second factor happened, so it does not count as one. See
[Sign-in and social accounts](/docs/creating-your-account) for how credentials
sit on one account.

Signing in on the mobile app asks for the same second step. Enrolling is done
on the web.

## Trusting a browser

You can let a browser you own skip the second step for **30 days**. It is a
convenience on your own laptop and a bad idea on a shared computer — and
clearing every trusted browser at once is one of the actions below.

## The actions that ask again

Some things are worth proving twice even in a session you already opened.
Changing your password or your email address, enrolling or removing a factor,
regenerating recovery codes, clearing your trusted browsers and deleting your
account all ask for a factor **within the last five minutes**, on a trusted
browser as much as any other.

## If somebody loses everything

An owner cannot reset a colleague's second factor from inside the app — that
would make the factor only as strong as the owner's own account. Contact
support, who can reset it after checking who is asking. See
[Getting help](/docs/getting-help).

## What it does not cover

Two-factor protects a sign-in. It is not a substitute for giving people the
role they actually need: somebody who should not be moving money should not
have the permission to, whether or not their account has a second factor. See
[Team roles and permissions](/docs/team-roles-and-permissions).
