Password with two-factor

A password, then a six-digit code by email or authenticator app. The most common upgrade from plain passwords.

  • Beginner
  • 5 min read
  • Applies to 2.0

Turn it on

User Access → Authentication, select Password + two-factor, and choose the second factor:

  • Email code — a six-digit code sent to the address on the account
  • Authenticator app — a code from Google Authenticator, 1Password, or any other TOTP application

Email is the default, because it needs nothing from the user.

The two-factor settings, with the second-factor choice.

  • Email delivery is tested, if you chose email codes
  • You have signed in with a test account and received the code
  • Your emergency access link is saved outside the site

How a sign-in goes

The member enters username and password as usual. If those are right, the form asks for a code instead of signing them in. The code is six digits and valid for ten minutes; a resend button issues a new one.

Only once the code checks out is the session opened.

Which second factor to choose

Email codes work for everyone with no setup, which is why they are the default. They also inherit every weakness of email: a mailbox that is slow, full, or compromised is a sign-in that is slow, blocked, or compromised.

Authenticator apps do not depend on delivery at all, and are the stronger choice — but each member has to enrol their app before they can use it. Enabling this without warning locks out everyone who has not.

If you choose email codes, test delivery first. A code that does not arrive is not an error message: it is a member who cannot sign in and does not know why.

Backup codes

Members using an authenticator app get ten single-use backup codes for when the phone is lost. They are shown once, stored hashed, and can be regenerated — which invalidates the previous set.

Tell members to save them at that moment. There is no way to display a code again afterwards.

Related articles

Something missing or out of date? Tell support.