Two-factor authentication (2FA, also called two-step verification) adds a second step when you sign in: after your password, you enter a 6-digit code from an authenticator app on your phone. Someone who learns your password still can't get into your account.
Who can do this: Any member, if your community offers two-factor authentication. · Where: Web (Settings → Security) and the Mateflow app. · Plan: Not plan-dependent. Your community's admins decide whether members can turn it on.
Before you start
- Your community must offer 2FA. If Two-Factor Authentication doesn't appear in Settings → Security, your community hasn't turned it on. In the app, you'll see Not available in this community. Ask your community's admins.
- You need an authenticator app, such as Google Authenticator or Authy, on your phone.
- Two-factor authentication is per community. Each Mateflow community has its own account for you, so turning 2FA on in one community doesn't turn it on in another. If you belong to several communities, turn it on in each one.
Turn on two-factor authentication on the web
- Go to Settings → Security and find Two-Factor Authentication.
- Turn on the switch. Set Up Two-Factor Authentication opens.
- In your authenticator app, scan the QR code. If you can't scan it, type the key shown under Or enter this key manually:.
- Enter the 6-digit Verification Code from the app and click Verify & Enable.
- Save your recovery codes opens. Click Copy all or Download .txt and store the codes somewhere safe.
- Select I have saved my recovery codes in a safe place. and click Done.
The section now shows Enabled. The recovery codes are shown only once, so save them before you close the dialog.
Turn on two-step verification in the app
- Open the menu (☰) and tap Settings and privacy → Account → Two-step verification. You can also go to Privacy & safety and tap Two-factor authentication.
- Tap Enable two-step verification.
- Tap Add to authenticator app to open your authenticator on the same phone, or tap Copy key and paste the key into it.
- Enter the 6-digit Verification code and tap Verify & enable.
- Tap Copy codes to save your recovery codes, then tap I've saved them.
Sign in with two-factor authentication
Two-factor authentication applies however you sign in: with your password, a magic link, social login, or your organization's single sign-on (SSO). After that first step, the Two-factor authentication screen asks for a code:
- Open your authenticator app and enter the current 6-digit code.
- Optionally, turn on Trust this device for 30 days so this device doesn't ask again for 30 days.
- Click Verify.
No phone at hand? Click Use a recovery code instead and enter one of your recovery codes. The code prompt expires after a few minutes; if it does, sign in again.
In the app, if you sign in with Google or Apple while 2FA is on, the app asks you to sign in with your email and password instead. Set a password in your account settings if you don't have one.
Manage your recovery codes
Each recovery code works once. Recovery Codes in Settings → Security shows how many you have left, and warns you when only a few remain. To get a new set, click Regenerate and enter a code from your authenticator app; a recovery code doesn't work here. Your old codes stop working. In the app, tap Regenerate codes on the two-step verification screen.
Manage trusted devices
When 2FA is on, Trusted Devices in Settings → Security lists the devices that skip the code for 30 days. Revoke one to require a code there at its next sign-in, or click Revoke all trusted devices. Revoking a trusted device doesn't sign it out; to do that, use Active Sessions. In the app, Trusted devices is on the two-step verification screen.
Turn off two-factor authentication
On the web, turn off the Two-Factor Authentication switch, enter a 6-digit code from your authenticator app, and click Disable 2FA. In the app, tap Turn off two-step verification and enter a code. Turning 2FA off needs a code from your authenticator app; recovery codes aren't accepted.
If your community stops offering 2FA after you've turned it on, you'll still be asked for a code when you sign in until you turn it off yourself. The section stays in your settings so you can.
If you lose your phone or authenticator app
A lost phone doesn't lock you out if you still have recovery codes. Each one signs you in once.
- If your authenticator app is backed up (some apps sync codes to a new phone), restore it on the new phone. You can then turn 2FA off and on again to set it up fresh, and regenerate your recovery codes.
- If the authenticator app is gone, you can keep signing in with recovery codes, but you can't turn 2FA off or get new recovery codes, because both need an authenticator code. Contact Mateflow support before your recovery codes run out; see Get help with your community.
If you've lost both your authenticator app and your recovery codes, you can't finish signing in on your own. Contact Mateflow support. They'll confirm your identity before resetting 2FA on your account.
Related articles
Was this guide helpful?