Skip to content
All articles
Access

Two-factor authentication (2FA)

Two-step verification requires, on top of the password, a six-digit code generated by an authenticator app. Each person turns the protection on for their own account, in My account. Once it is on, the server refuses any session that presented only a password.

A password on its own protects very little: if it leaks, whoever has it signs in as you. With two-step verification on, signing in also requires a six-digit code that changes every thirty seconds and exists only on your phone. Even with the right password, someone without the device does not get in.

Turning it on for your account

  1. Click your name at the top and open My account.
  2. Find the Two-factor authentication (2FA) card and click Enable 2FA.
  3. Open your authenticator app (Google Authenticator, Authy, 1Password and the like) and scan the QR code on the screen. If you would rather type it, use the key shown just below under Or enter the key.
  4. Type the six-digit code your app shows into the field and click Confirm and enable.
  5. The card now reads 2FA active on this account.

If the code is refused, the screen shows Invalid code. Try again. It is almost always the phone clock being off, or a code that expired while you were typing: wait for the next one and try again.

What login looks like afterward

The next time you sign in, the system asks for your email and password as always and then shows a second screen asking for the code from your app. Only after you confirm the code is the session released.

That requirement is not just cosmetic. If a session reaches the server having presented only the password while the account has a confirmed second factor, access is interrupted with the notice Two-step verification required, asking you to sign out and sign in again. The same applies to calls made outside the screen, so closing the browser at the code step is no way around it.

Example: Marina, on the sales team, turns 2FA on a Tuesday. On Wednesday she signs in from her laptop: she types the password, the CRM asks for the code, she opens the app, types 481902 and gets in. That same day, someone who found out her password tries to sign in from another computer: the password is accepted, but the code screen appears and that is where they stop.

Turning it off

  1. Open My account.
  2. On the Two-factor authentication (2FA) card, click Disable.
  3. Confirm in the Disable two-factor authentication for this account? dialog.

Who can do what

  • Anyone with access to the system turns verification on and off for their own account. You do not have to be an administrator.
  • Nobody turns verification on or off for someone else. There is no administrator button for that, and there is no setting that forces the whole organization to use two factors: adoption is account by account.
  • To turn it off you only need an open session. The system does not ask for your password again at that moment, so treat an open, unattended session as a real risk.
💡 As soon as you turn 2FA on, click Generate recovery codes on the same card and keep the ten codes somewhere other than the phone. Each one works once: entering it at sign-in gets you past the code screen and turns the second factor off, so you can set it up again on the new device. Generating a new batch cancels the previous one. There is still no administrator button to remove verification for a colleague, and no setting that forces the whole organization to use two factors.

Common questions

  • I lost my phone and cannot get in: without the app and without the saved key, access stays blocked; recover the authenticator app on another device first.
  • Do I have to type the code every time? Yes, at every new login. While the session stays open, no.
  • Does verification apply to the mobile app and to integrations? It protects people signing in. Integration keys used by systems are separate credentials, managed in Settings, API.

Open this article inside the system

Read it and want to see it working?

The account is free and the whole manual is available inside the system, with an assistant that answers from this very content.

Create free account
Two-factor authentication (2FA) · Sellio