Two-factor authentication
Enabling it on your account
Go to Account → Security → Two-factor authentication. Choose an authenticator app (TOTP) or a hardware security key (WebAuthn). SMS is not offered — it is not a safe second factor against SIM-swap attacks.
Scan the QR code, confirm one code, and save your recovery codes. Each of the ten codes works once.
Enforcing it for the workspace
Admins can require 2FA in Settings → Security. Existing members are prompted at next sign-in and have a grace period you set, from 0 to 14 days, before they are locked out of the workspace.
Losing your device
Use a recovery code. If those are gone too, another Admin can reset your second factor from Settings → Members. If you are the only Admin and have lost everything, contact support — recovery requires proof of domain ownership and takes up to three business days by design.
Sessions
Enabling 2FA revokes every other active session. Review sessions and sign them out individually at any time on the same screen.
Last updated 28 July 2026

