Help centre · Using the portal
Two-factor authentication
A second check, on top of your password, entered each time you sign in — either a six-digit code from an authenticator app on your phone, or a six-digit code emailed to you at the moment you sign in.
When you would use this: two-factor is optional for most staff, but it becomes required the moment you are given a permission that touches something sensitive — inviting or managing other staff, changing settings or finance settings, data protection requests, API keys, or exporting data. Your firm can also switch on "require two-factor for everyone" for its whole team; if it has, you will be asked to set it up whether or not your own role needs it. Where it is required, only the authenticator app satisfies it — an inbox is not treated as strong enough on its own for that requirement, though you can still use email codes for sign-in generally.
Setting up the authenticator app: go to your profile and choose "Manage two-factor authentication". Scan the code shown with an authenticator app (Google Authenticator, Authy, or similar), then enter the six-digit code it gives you to confirm the two are linked. You will be shown a set of recovery codes — save them somewhere safe; each one lets you sign in once if you lose access to your authenticator app. Turning the app on switches off email codes if you had them on; the app is the stronger method and the two are never both active at once.
Setting up codes by email instead: from the same screen, turn on "Sign in with a code by email". Each time you sign in, a six-digit code is sent to your own email address; it works for ten minutes, once, and a fresh one replaces it if you ask for another. This is not offered as a way to satisfy your firm's "require two-factor for everyone" setting where your own role needs the stronger check.
What each option means: "Turn off two-factor" turns off whichever method is on (only offered where it is not required for you); recovery codes (for the app) can be regenerated, which invalidates the old set.
What happens next: from then on, signing in asks for your password and then a code, by whichever method you set up. Turning either method on or off ends your other signed-in sessions, the same as changing your password does.
When it refuses: an app code that is rejected is usually a clock out of sync on your phone — check the time is set automatically. An email code rejected as "not correct or has expired" means it has already been used, replaced by a newer one, or its ten minutes are up — send a new one. Locked out of the app entirely? Use a recovery code, or ask an Owner or Admin to reset two-factor on your account from the Staff screen.