Protect agents with two-factor authentication (2FA)
Add a time-based one-time code to agent sign-in, with recovery codes — no third-party service required.
Two-factor authentication (2FA) adds a second step to sign-in: after the password, the agent enters a 6-digit code from an authenticator app. Each agent turns it on for themselves under Profile → Two-factor authentication.
Enrolling
- Go to Profile and click Enable two-factor.
- Scan the QR code with Google Authenticator, Authy, 1Password or Microsoft Authenticator — or type the shown key manually.
- Enter the current 6-digit code to confirm. We then show your recovery codes — save them; each works once and they're your way in if you lose your device.
Signing in with 2FA
After a correct password, you're asked for the code. You can enter either a current authenticator code or one of your recovery codes. Attempts are rate-limited.
Managing it
- Regenerate recovery codes any time (the old set stops working).
- Turn off requires your current password.
- Codes and the secret are encrypted at rest, and nothing is enforced until you've confirmed a first code — so a half-finished setup can never lock you out.
Prefer central control? SSO (OIDC) and SCIM are also available under Security & SSO for Google, Microsoft Entra, Okta and more.