Two-factor authentication (2FA)
Last updated: September 9, 2026
2FA adds an additional layer of security during login — in addition to the password, a time-based code (TOTP) is required.
Set up 2FA
- Profile → 2FA → "Set up"
- Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password)
- Enter the 6-digit code for verification
- 2FA is activated
Login with 2FA
- Enter email + password
- Enter the 6-digit code from the authenticator app
- Optionally: "Trust this device" — skips 2FA on this device for 30 days
Trusted Devices
Trusted devices can be viewed and removed under Profile → 2FA → Devices.
Disable 2FA
Profile → 2FA → "Disable" — Requires the current 2FA code. Cannot be disabled during active impersonation.
2FA Reset (Admin)
If a user has lost access to their authenticator app, an admin can reset the 2FA: Administration → Users → "Reset 2FA"