Two-factor authentication
Two-factor authentication (2FA) adds a second step when you sign in. After your usual email link, you enter a 6-digit code from an authenticator app on your phone. Even if someone gets into your email, they can’t sign in without that code.
Turn it on
- Go to Settings → Security.
- Under Authenticator app, click Set up authenticator.
- Scan the QR code with an authenticator app: 1Password, Google Authenticator, Authy, or any app that supports authenticator codes. Can’t scan? Type in the key shown below the code instead.
- Enter the 6-digit code the app shows and confirm.
That’s it. Next time you sign in, you’ll enter a code after your email link.
Save your recovery codes
When you turn on 2FA, we show you ten recovery codes once. Each one works a single time to sign in if you don’t have your phone. Copy them and keep them somewhere safe, like a password manager. You won’t be able to see them again, but you can generate a fresh set anytime from Settings → Security.
If you lose your device
Use one of your recovery codes on the sign-in screen. Choose Use a recovery code instead, enter a code, and you’re in. Each code works once, so generate a new set afterward if you’re running low.
Turn it off
Go to Settings → Security and choose Turn off. You’ll need a current code (or a recovery code) to confirm, so nobody can remove it without access to your app.
Good to know
- 2FA is per person, not per company. Turning it on secures your own sign-in.
- It sits on top of however you normally sign in. If you use Google to sign in, you’ll still enter your Wrenbase code after.
- You can turn it on right after signing up, or skip and do it later. It’s always in Settings → Security.