Two-factor authentication

Enabling it on your account

Go to Account → Security → Two-factor authentication. Choose an authenticator app (TOTP) or a hardware security key (WebAuthn). SMS is not offered — it is not a safe second factor against SIM-swap attacks.

Scan the QR code, confirm one code, and save your recovery codes. Each of the ten codes works once.

Enforcing it for the workspace

Admins can require 2FA in Settings → Security. Existing members are prompted at next sign-in and have a grace period you set, from 0 to 14 days, before they are locked out of the workspace.

Losing your device

Use a recovery code. If those are gone too, another Admin can reset your second factor from Settings → Members. If you are the only Admin and have lost everything, contact support — recovery requires proof of domain ownership and takes up to three business days by design.

Sessions

Enabling 2FA revokes every other active session. Review sessions and sign them out individually at any time on the same screen.

Last updated 28 July 2026