Security and two-factor authentication
Turn on two-factor authentication, keep your recovery codes, and know why sfora sometimes asks who you are again.
Two-factor authentication makes signing in ask for a code from an authenticator app as well as your password. You turn it on in Settings, in the Security group. Every account can use it.
Turn on two-factor authentication
Press 7 to open Settings. In Security, next to Two-factor authentication, click Set up.
Scan the code with an authenticator app, such as 1Password, Google Authenticator or your phone's password app. If you can't scan it, type the key shown under Can't scan it? Enter this key: into the app.
Type the six-digit code the app shows and click Turn on.
Save your recovery codes shows ten codes. Click Copy codes, or write them down, and keep them somewhere safe. They won't be shown again.
Click I've saved them.
From now on, signing in asks for a code. Your other signed-in devices ask for one once.
Sign in with two-factor
After your password, sfora asks you to Enter your code. Type the six-digit code from your authenticator app in Authentication code and click Continue.
If you don't have your phone, click Can't use your app? Use a recovery code, type one of your recovery codes, and click Continue. Each code works once. The next screen says how many you have left; when three or fewer are left, it offers Make new recovery codes.
Make new recovery codes
Recovery codes in Security shows how many of your ten are left. Make a new set before you run out.
Click New codes.
Type a code from your authenticator app, or a recovery code, and click Make new codes.
Your new recovery codes shows ten new codes. Your old ones stop working at once. Save the new ones and click I've saved them.
Turn off two-factor authentication
Click Turn off next to Two-factor authentication, type a code from your app or a recovery code, and click Turn off. Signing in then asks only for your password, and your recovery codes stop working.
Why sfora asks you to confirm it's you
Some actions are serious enough that sfora checks it's really you first, even though you're signed in. This is a step-up: a fresh proof that counts only for the browser session you made it in, and only for a few minutes.
| Action | What sfora asks for | How long it counts |
|---|---|---|
| Change the workspace's paid plan | A code from your authenticator app if two-factor is on, otherwise your password | 15 minutes |
| Turn off two-factor authentication | A code from your app, or a recovery code | 5 minutes |
| Make new recovery codes | A code from your app, or a recovery code | 5 minutes |
For a plan change, the dialog shows Confirm it's you and says "Changing what the workspace pays needs your password." (or "…needs a code from your authenticator app."). Enter it and click Continue. Within 15 minutes, the next plan change doesn't ask again. Signing out ends every step-up.
Troubleshooting
The code is refused
A code changes every 30 seconds, and each one works once. Wait for the next code and type it. If codes keep failing, check that your phone sets its clock automatically.
Sign-in says "Too many attempts"
Wait until the time on the button has passed, then try again.
You've lost your phone
Sign in with a recovery code: click Can't use your app? Use a recovery code. Then, in Settings › Security, turn two-factor off and on again with your new phone, or click New codes.
Last updated on