IntuBuStart free

Two-factor authentication

A code from your phone as well as your password, and what to do if you lose the phone.

Settings → Security → My account.

With two-factor on, your password alone is not enough to sign in — a six-digit code from your phone is needed as well. It is optional, and it is the single most effective thing you can do to protect a set of books.

Setting it up takes about a minute. Scan the QR code in Google Authenticator, Authy, 1Password or any other authenticator app, then enter the code it shows. If the camera will not cooperate, the same secret is printed underneath in groups of four to type by hand.

Save the recovery codes. Ten of them, shown once, each good for one sign-in. We store a hash, so we cannot show them to you again or read them out over the phone — which is exactly why they are safe, and exactly why losing them matters. If you lose your phone and have no recovery codes left, nobody can let you back in.

"Do not ask again on this computer" remembers that browser for 30 days. It is per browser and per person, and forgetting a device from the Security page makes it ask again immediately.

A code works once. Codes change every 30 seconds and each one can only be used a single time, so a code read over your shoulder is no use a minute later. That also means the code you used to switch two-factor on cannot be reused to sign in — wait for the next one.

Switching it off needs a current code, for the same reason switching it on did: somebody sitting on a stolen session must not be able to remove the control that would have stopped them.

If your organisation requires it, you cannot switch it off here — an owner can lift the requirement in Settings → Security → Organisation.