Account security
Two-factor authentication, Google sign-in and recovery codes.
Last updated
Two-factor authentication (2FA)
Turn on 2FA under Settings → Two-factor authentication. Scan the QR code with any TOTP app (Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden) or type the setup key, then confirm with the 6-digit code the app shows. From then on every sign-in, with a password or with Google, asks for a current code.
- 1
Open Settings and press Enable 2FA.
- 2
Scan the QR code, or enter the key manually in your app.
- 3
Enter the 6-digit code to confirm. The setup expires after 10 minutes if you do not.
- 4
Save the eight recovery codes somewhere safe: each one signs you in once if you lose your phone.
Recovery codes
If your phone is lost, choose “Use a recovery code” on the sign-in page. Each code works once. Regenerate a fresh set from Settings whenever you are running low; this invalidates the old ones. Disabling 2FA also needs a current code, so a password alone can never turn it off.
Google sign-in
Press “Continue with Google” on the sign-in or sign-up page. If an account already exists for the same (Google-verified) address, Google is linked to it; otherwise a new account and workspace are created with the address already verified. Accounts that sign in through the Online Backup Portal keep using the portal.
What else protects your account
- Passwords are hashed with bcrypt; sign-in attempts are throttled (8 failures lock the address for 15 minutes), and so are 2FA code attempts.
- Signup addresses are verified with a 6-digit e-mailed code before a workspace is created.
- 2FA secrets are encrypted at rest; recovery codes and API keys are stored only as SHA-256 hashes.
- Security events (2FA on/off, password changes, Google linking, API keys) are written to the workspace audit log.
Didn’t find what you need?
We answer every email, usually within one business day.