Admin

Security and two-factor authentication

Turn on two-factor authentication, keep your recovery codes, and know why sfora sometimes asks who you are again.

Two-factor authentication makes signing in ask for a code from an authenticator app as well as your password. You turn it on in Settings, in the Security group. Every account can use it.

Turn on two-factor authentication

Press 7 to open Settings. In Security, next to Two-factor authentication, click Set up.

Scan the code with an authenticator app, such as 1Password, Google Authenticator or your phone's password app. If you can't scan it, type the key shown under Can't scan it? Enter this key: into the app.

Type the six-digit code the app shows and click Turn on.

Save your recovery codes shows ten codes. Click Copy codes, or write them down, and keep them somewhere safe. They won't be shown again.

Click I've saved them.

From now on, signing in asks for a code. Your other signed-in devices ask for one once.

Sign in with two-factor

After your password, sfora asks you to Enter your code. Type the six-digit code from your authenticator app in Authentication code and click Continue.

If you don't have your phone, click Can't use your app? Use a recovery code, type one of your recovery codes, and click Continue. Each code works once. The next screen says how many you have left; when three or fewer are left, it offers Make new recovery codes.

Make new recovery codes

Recovery codes in Security shows how many of your ten are left. Make a new set before you run out.

Click New codes.

Type a code from your authenticator app, or a recovery code, and click Make new codes.

Your new recovery codes shows ten new codes. Your old ones stop working at once. Save the new ones and click I've saved them.

Turn off two-factor authentication

Click Turn off next to Two-factor authentication, type a code from your app or a recovery code, and click Turn off. Signing in then asks only for your password, and your recovery codes stop working.

Why sfora asks you to confirm it's you

Some actions are serious enough that sfora checks it's really you first, even though you're signed in. This is a step-up: a fresh proof that counts only for the browser session you made it in, and only for a few minutes.

ActionWhat sfora asks forHow long it counts
Change the workspace's paid planA code from your authenticator app if two-factor is on, otherwise your password15 minutes
Turn off two-factor authenticationA code from your app, or a recovery code5 minutes
Make new recovery codesA code from your app, or a recovery code5 minutes

For a plan change, the dialog shows Confirm it's you and says "Changing what the workspace pays needs your password." (or "…needs a code from your authenticator app."). Enter it and click Continue. Within 15 minutes, the next plan change doesn't ask again. Signing out ends every step-up.

Troubleshooting

The code is refused

A code changes every 30 seconds, and each one works once. Wait for the next code and type it. If codes keep failing, check that your phone sets its clock automatically.

Sign-in says "Too many attempts"

Wait until the time on the button has passed, then try again.

You've lost your phone

Sign in with a recovery code: click Can't use your app? Use a recovery code. Then, in Settings › Security, turn two-factor off and on again with your new phone, or click New codes.

Last updated on