Two-Factor Authentication (2FA)
Two-factor authentication adds a second verification step after your password, protecting your account even if your password is compromised. Two methods are available.
Nobody is forced to use it, but each time you sign in without a second factor the dashboard shows a short Protect your account reminder. Pick email codes (nothing to install) or an authenticator app, or choose Not now to skip it until your next sign-in.
Enrolling in 2FA
Click your avatar in the bottom-left corner of the admin panel and select 🔐 Two-Factor Authentication. Choose a method:
- 📱 Authenticator App — Scan a QR code with Google Authenticator, Authy, Microsoft Authenticator, or any TOTP-compatible app. After scanning, enter the 6-digit code shown in the app to verify and activate. A manual entry secret is also shown if you can't scan.
- 📧 Email Code — A 6-digit code is emailed to your account address each time you log in. No app required.
To switch methods, or to re-scan the authenticator on a new phone, turn 2FA off first (this asks for your current code or a recovery code) and then enrol again. 2FA cannot be re-enrolled while it is already on.
Logging In With 2FA
After entering your password correctly, a verification screen appears. App users enter the current 6-digit code from their authenticator. Email users receive a code automatically and can request a resend if needed. You can also enter a recovery code instead of a regular code — see below. If you belong to more than one church, the code is asked for before you choose a church.
If you check Remember Me on the login screen, 2FA is skipped for 7 days on that device after a successful verification. This is stored as a secure token in your browser — no 2FA prompt until the 7 days expire or you clear your browser data.
Recovery Codes
When you first enable 2FA (either method), you receive 8 one-time recovery codes. These are your safety net if you ever lose access to your authenticator app or email.
- Each code can only be used once.
- Recovery codes work anywhere a 2FA code is required: login, disabling 2FA, etc.
- Store them somewhere safe — they are only shown once at enrollment.
- You can check how many remain and regenerate new codes from 2FA settings in your avatar menu.
If you lose your authenticator, enter a recovery code at the login screen, then go to your avatar menu → Two-Factor Authentication to disable and re-enroll.