Setting up two-factor authentication
Add an authenticator app or email codes as a second login step, generate backup codes, and see what happens if your organization requires it.
Two-factor authentication (MFA) adds a second step to logging in, beyond your password - so a leaked password alone isn't enough to get into your account.
Choosing a method
From Settings → Two-factor authentication, you can enroll one of two methods:
- Authenticator app (TOTP) - scan a QR code (or enter the setup key manually) into an app like Google Authenticator, 1Password, or Authy, then confirm with the 6-digit code it generates.
- Email codes - we send a 6-digit code to your account email each time it's needed, no separate app required.
Once enrolled, you'll be given a set of backup codes - store them somewhere safe. Each one lets you log in once if you lose access to your authenticator app or your email, and they won't be shown again after this point.
Logging in with MFA enabled
After your password, you'll be asked for a code from whichever method you enrolled. If you have an authenticator app enrolled but it's unavailable, you can switch to email codes or use a backup code instead from the same screen.
If your organization requires it
An organization owner or admin can turn on Require MFA for the whole organization from Team settings. If that's enabled and you haven't enrolled a method yet, you'll be prompted to set one up the next time you log in, before you can continue - there's no way to skip it once it's required.
Managing active sessions
Settings → Sessions lists every device currently logged into your account, with the option to revoke any session you don't recognize or no longer want signed in - useful after changing your password or if you suspect a session was left open somewhere you shouldn't have.
Turning off two-factor authentication
You can remove a method from Settings → Two-factor authentication at any time, unless your organization has MFA required - in that case you'll need to keep at least one method enrolled while that policy is active.