Two-factor authentication
Turning on an authenticator app, what sign-in looks like afterwards, and how to recover if you lose access.
Two-factor authentication (TOTP) adds a 6-digit code from an authenticator app to your sign-in, on top of your password. It's off by default and optional for everyone — unless your organisation turns on Require two-factor authentication for all members, covered below.
Turning it on
From Your account → Security, choose Set up authenticator app. Scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, or similar), or enter the shown key manually, then confirm with the 6-digit code it generates. From that point on, every sign-in asks for a fresh code from the app.
| Setting | What it does |
|---|---|
| Authenticator app | On or off. Turning it off asks for confirmation — after that, only your password is needed to sign in. |
| Backup phone | Optional, independent of the authenticator app. See below. |
Backup phone (recovery)
A verified backup phone number is a fallback for one situation only: you've lost access to your authenticator app. It's never shown as a normal sign-in option — at the code prompt, it's tucked behind a "Can't access your authenticator app?" link, which reveals a "text me a backup code" button once you have a verified number on file.
Add or replace your backup phone from the same Security section on Your account: enter the number, confirm the code texted to it, done. Text messages cost money to send, so requests are limited to one per minute.
If your organisation requires it
An Owner can turn on Require two-factor authentication for all members from Organisation settings. Once on, anyone without a verified authenticator app is walked through setup the next time they sign in, before they can do anything else in the app — a backup phone is offered as an optional next step, but isn't required to continue.
While this is on, a member can't turn their own authenticator app off from Account — replacing a backup phone is still always allowed, since it's a recovery aid rather than the required factor itself.
Locked out?
Two ways back in, in order:
- Ask an Owner or Admin to reset your two-factor authentication from Team — this clears both your authenticator app and backup phone, and you'll set up two-factor authentication again from scratch.
- Text yourself a backup code, if you'd already verified a backup phone — see above.
If you're a solo organisation (no second Owner or Admin to ask), a verified backup phone is your only way back in if you lose your authenticator app — see Can I use Springtrack solo?.