Two-factor authentication
A six-digit code from an authenticator app, on top of the emailed sign-in link. An owner can require it of everybody in the organization.
Save your recovery codes when they are shown. They appear exactly once, they are the only way back if you lose your phone, and nobody — including us — can show them to you again.
What it actually protects against
Being straight about this: signing in here is an emailed link, so both factors are things you have rather than one thing you have and one you know. It is not two-factor in the textbook sense.
What it defends against is inbox compromise, which in a passwordless product is total compromise — whoever reads the mailbox is an admin, indefinitely, and nothing would show it happened. It also covers a link forwarded or intercepted, and the admin whose login is itself a shared mailbox. That is reason enough.
Setting it up
Scan the QR code with any authenticator app, or type the secret in by hand — it is shown beside the code, because plenty of cameras will not cooperate. Then enter one code to confirm the app and yours agree.
Replacing an authenticator keeps the old one working until the new one confirms, so starting a replacement can never lock you out.
Recovery codes
- Ten of them, each usable once. Print them or put them somewhere that is not the phone with the authenticator on it.
- They share the same attempt counter as the app’s codes — two doors, one counter, so guessing at either burns the same allowance.
- Shown once and never again. If you lose them, generate a new set while you can still sign in.
If a code is refused
Five wrong attempts locks the challenge for fifteen minutes. A permanent secret cannot be burned the way a one-off code can, so time is the only available limit.
A code that is too short, or one you have already used, does not spend an attempt — neither is evidence of guessing. A code refused for being a minute out usually means the phone’s clock has drifted; the app has a setting to re-sync it.
Requiring it of everybody
An owner can require it for the whole organization. It cannot be turned on until the owner’s own authenticator is confirmed — otherwise the switch is a loaded gun pointed at whoever holds it.
It applies to sessions already open, not just to the next sign-in, and an admin who has not enrolled is offered enrollment at the challenge rather than being sent somewhere they cannot reach.
It is per organization and per session. Somebody who administers two organizations, only one of which requires it, is challenged once and then works in both.
When somebody loses their phone
Their recovery codes are the first answer. If those are gone too, the owner can waive the requirement for that person — for seven days, visibly, and revocably.
Note what a waiver is not: it does not touch their authenticator. An owner cannot clear somebody’s second factor, and that is deliberate rather than an omission — an authenticator belongs to the person, not to one organization, and anyone can create an organization and add anyone’s address to it. A reset would reach into whatever other organization that person actually belongs to.
If the person who is stuck is the owner and the codes are gone, see the ways back in.
Turning your own off
You need a session that has already passed the challenge — otherwise somebody who compromised the inbox could shed the second factor, which is the exact threat it exists for.