Skip to main content

Setting up two-factor authentication

Adding a second step to sign-in, beyond your password, using an authenticator app.

Last updated

Who this is for

Two-factor authentication (2FA) is available today for staff accounts — Administrator, Property Manager, Assistant Manager, Maintenance and Accountant — from Settings → Security in the dashboard. It's optional and self-service: turning it on for your own account doesn't require anyone's approval, and nobody else can turn it on for you. It isn't available yet for the tenant, owner or vendor portals, or from the mobile app — see below.

Turning it on

You'll need an authenticator app on your phone — Google Authenticator, Authy, or similar.

  • Go to Settings → Security and enter your current password to begin.
  • Scan the QR code with your authenticator app (or enter the code shown beneath it manually if you can't scan).
  • Enter the 6-digit code your app generates to confirm the pairing worked and finish turning on 2FA.
  • You'll be shown a set of recovery codes — save these somewhere safe before continuing. Each one can be used once, in place of a code from your app, if you ever lose access to your phone.

Signing in once 2FA is on

After entering your email and password, you'll be asked for a 6-digit code from your authenticator app before you're signed in. Type carefully — repeated incorrect codes count toward the same login-attempt limit as incorrect passwords, so an account can be temporarily locked out the same way it would be from repeated wrong passwords.

Turning it off, or losing your device

Turning 2FA off works the same way it was turned on: from Settings → Security, with your current password and a valid code. If you've lost your phone and don't have a saved recovery code, contact support — see the Support guide.

Not available yet everywhere

2FA setup is currently a dashboard-only feature for staff accounts. It isn't offered in the tenant, owner or vendor portals yet, and the mobile app can't be used to turn it on (though if your account already has it enabled from the dashboard, mobile will still ask for your code at sign-in). See the mobile app guide for what's available there today.