Skip to content

Set up two-step sign-in

Protect your account with a code from an authenticator app such as Google Authenticator, 1Password or Authy, plus ten one-time recovery codes.

Last updated 2 min read

On this page

Two-step sign-in adds a second check after your password or email link: a six-digit code from an app on your phone. Even if someone learns your password, they cannot get in without your phone.

Before you start

  • Who can do this: everyone, for their own account.
  • Plan: all plans.
  • What you need: a confirmed email address and an authenticator app, such as Google Authenticator, 1Password or Authy.
  • Time: about three minutes.

Step by step

  1. Open the account menu and choose Security and sign-in.
  2. Under Two-step sign-in ("Two-step sign-in is off"), press Turn on.
  3. "Scan the code with your authenticator app." Scan the QR code, or copy the secret into the app.
  4. "Type the 6-digit code the app shows." Type it into Code and confirm.
  5. "Save these recovery codes." Press Copy or Download, store them safely, then press I’ve saved them.

What happens next

The section says "Two-step sign-in is on." and how many recovery codes are left: "Signing in with a password or email link also asks for a code from your authenticator app."

From now on, after your password or email link, you see a step asking for the Code from your authenticator app: "Lost your phone? Type one of your recovery codes (like k7mq-2xwp) instead."

The change is written to your workspaces' audit log.

Managing it later

Action How
Make new recovery codes New recovery codes, then enter a current code from your app
Turn it off Turn off, then enter a code from your app or a recovery code
Move to a new phone Turn it off and on again with the new phone

Tips

  • Store recovery codes in a password manager, not on the phone that holds the app.
  • Add a passkey as well; it skips the code step and is the quickest secure sign-in.
  • Owners and admins should turn this on; their accounts can change settings for everyone.

Troubleshooting

"Confirm your email first (we sent you a code), then add this."

Confirm your email address, then try again.

"That code isn’t right. Use the code your app shows now."

Codes change every 30 seconds. Type the current one. If it keeps failing, check your phone's clock is set automatically.

"Start again: the setup expired"

Press Turn on again and scan the new QR code.

"Two-step sign-in is already on"

It is already set up for your account.

"Set APP_ENCRYPTION_KEY on the server before turning on two-step sign-in"

The server cannot store secrets yet. Ask the server owner.

"That code isn’t right. Use the newest code from your app, or a recovery code."

At sign-in, the code was wrong. Use the newest code.

Frequently asked questions

Which authenticator apps work with Hushdesk?

Any app that makes six-digit time-based codes, such as Google Authenticator, 1Password, Authy or Microsoft Authenticator. You scan a QR code once, and the app then shows a new code every 30 seconds that you type after your password or email link.

When does Hushdesk ask for my authenticator code?

After you sign in with a password or an email link. The page then asks for the code from your authenticator app before letting you in. Signing in with a passkey does not ask for a code, because a passkey already proves both who you are and that you have your device.

What are recovery codes for?

They get you in if you lose your phone. You receive ten codes when you turn on two-step sign-in, each like k7mq-2xwp and each usable once. Type one instead of the six-digit code at the sign-in step. Save them in a password manager or print them.

Do I need to confirm my email before turning on two-step sign-in?

Yes. Two-step sign-in and passkeys are only available once your email address is confirmed, so the account is definitely yours before it is locked down. If you have not confirmed it, use the 6-digit code we emailed you, or send a new one from the Welcome page.

How do I turn two-step sign-in off?

Open Security and sign-in, press Turn off under Two-step sign-in and enter a current code from your app or one of your recovery codes. Hushdesk asks for one of them so that someone with only your password cannot switch it off.

Do admins have to use two-step sign-in?

It is not enforced for workspace members today, so each person chooses. Platform super admins are asked to confirm with an authenticator code or passkey for sensitive console actions. We recommend owners and admins turn it on, or use a passkey.

Was this helpful?

Still stuck?

Chat with the Hushdesk team. A person answers on every plan.