All help topics
Account and security

Set up two-factor authentication

Scan a QR code in an authenticator app, verify one 6-digit code, and save the ten backup codes. Sign-in then asks for a code after your password.

Updated Open in app

Two-factor authentication puts a 6-digit code from your phone between your password and your account. Turn it on at Settings > Security with Enable 2FA, and the whole thing takes about a minute.

Who can do this

Any member, on any plan, for their own account. Admins can also make it compulsory for everyone, which is covered in requiring two-factor for your workspace.

Turn on two-factor authentication

  1. Open Settings > Security. The Authenticator app row shows a badge reading Off.

    The two-factor authentication card in security settings with the Enable 2FA button highlighted

  2. Click Enable 2FA.

  3. Scan the QR code with your authenticator app. With no camera to hand, open Can't scan? Enter this secret manually and paste the string into the app instead.

    The setup dialog showing the QR code to scan in an authenticator app

  4. Click I've added the account.

  5. Type the 6-digit code your app is showing and click Verify code.

    The setup dialog asking for a 6-digit code from the authenticator app

  6. Ten backup codes appear under Save these backup codes. Use Copy all or Download to keep them, then click Done.

Those ten codes are shown exactly once, and two-factor is already switched on by the time they appear. Close the dialog without copying them and they're gone: the only way to a fresh set is to disable two-factor with a current code and enroll again. Put them in a password manager before you click Done.

What sign-in looks like with two-factor on

Email and password still come first. After they check out you land on a screen headed Two-factor check, type the current code from your app and click Verify and sign in. Codes rotate every thirty seconds, so grab a fresh one if the timer is nearly out.

Without your phone, click Use a recovery code instead on that screen and paste one of the ten backup codes. Each works a single time and the rest stay valid. The screen takes ten code attempts a minute, and five recovery codes every five minutes; go past either and it refuses everything until that window rolls over.

Your Security page badge now reads Enabled.

Turn two-factor off

Click Disable on the same card, type a current 6-digit code from your app, then Disable two-factor. Your backup codes are wiped along with it. If your workspace requires two-factor, you are sent back through setup on your next sign-in.

Move two-factor to a new phone

There is no transfer button. You turn it off on the old phone and set it up again on the new one, in that order.

  1. While you still have the old phone, click Disable, type a current code from it, and confirm with Disable two-factor.
  2. Click Enable 2FA and run setup again with the new phone. You get ten fresh backup codes, and every code from the old set stops working.

If something goes wrong

  • "That code didn't match. Try again." Almost always clock drift on the phone. Turn on automatic date and time in its settings, then retry.
  • "Two-factor is already enabled on this account." Setup was opened on an account that has it on. Reload the Security page to see the current state.
  • The QR code will not scan. Use the manual secret under the QR instead. It types the same account into the app.
  • A recovery code is rejected. Each one is single use, so a code you have already spent will not work twice. Try the next unused code on your list.
  • You are stuck at the challenge with no phone and no codes. Only our support team can clear the second factor, through the contact form. Nobody, admins included, can bypass that screen from the browser.
FAQ

Frequently asked questions

How many backup codes do I get?

Ten, shown once on the final setup screen and never again. Each one works a single time and then dies. Copy all of them or download the text file before you close that screen, and keep them somewhere that is not the phone holding your authenticator.

I used a backup code. How do I get more?

Disable two-factor from the Security page and turn it straight back on. Enrolling again issues a fresh set of ten and voids every old one, so the codes you printed earlier stop working at that moment. You will scan a new QR code as part of it.

Which authenticator apps work?

Any app that supports standard TOTP codes, which covers Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, Authy and the built-in password manager on recent iPhones. Nothing here is specific to one vendor, and you can add the same account to two apps if you want a spare.

I lost my phone and my backup codes.

Contact our support team through the contact form on our website and ask us to reset it. A workspace admin cannot clear the second factor for you, and there is deliberately no self-service way past the challenge. Expect to prove who you are before we turn it off.

Do I need my password to turn two-factor off?

No, a current code from your authenticator is what the disable dialog asks for. That keeps the option open for accounts that sign in through Google or Microsoft and have no password at all. Turning it off destroys your backup codes as well.

Does two-factor apply to people signing my documents?

No. It protects your own sign-in only. Recipients open a signing link and never touch your account, so they are unaffected. For an extra check on signers, add an access PIN to the envelope instead. Our help article on protecting a document with an access PIN covers it.

Related

Keep going

Did not find what you needed?Send us a message