Two-factor authentication

Two-factor authentication (2FA) adds a second step when you sign in. After your usual email link, you enter a 6-digit code from an authenticator app on your phone. Even if someone gets into your email, they can’t sign in without that code.

Turn it on

  1. Go to Settings → Security.
  2. Under Authenticator app, click Set up authenticator.
  3. Scan the QR code with an authenticator app: 1Password, Google Authenticator, Authy, or any app that supports authenticator codes. Can’t scan? Type in the key shown below the code instead.
  4. Enter the 6-digit code the app shows and confirm.

That’s it. Next time you sign in, you’ll enter a code after your email link.

Save your recovery codes

When you turn on 2FA, we show you ten recovery codes once. Each one works a single time to sign in if you don’t have your phone. Copy them and keep them somewhere safe, like a password manager. You won’t be able to see them again, but you can generate a fresh set anytime from Settings → Security.

If you lose your device

Use one of your recovery codes on the sign-in screen. Choose Use a recovery code instead, enter a code, and you’re in. Each code works once, so generate a new set afterward if you’re running low.

Turn it off

Go to Settings → Security and choose Turn off. You’ll need a current code (or a recovery code) to confirm, so nobody can remove it without access to your app.

Good to know

  • 2FA is per person, not per company. Turning it on secures your own sign-in.
  • It sits on top of however you normally sign in. If you use Google to sign in, you’ll still enter your Wrenbase code after.
  • You can turn it on right after signing up, or skip and do it later. It’s always in Settings → Security.