Enabling 2FA on Your Account
- Go to
Profile → Security. - Click Enable two-factor authentication.
- Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, Bitwarden, etc.).
- Type the 6-digit code shown by the app to confirm.
- Save the backup codes shown on screen in a safe place (password manager, physical vault).
- Confirm.
From now on, every login will require password + app code.
Backup Codes
Backup codes are single-use codes that allow logging in without the authenticator app — useful if you lose your phone, switch devices, or the app fails.How They Work
- Each code can be used only once. After use, it is invalidated.
- You receive a set of codes when activating 2FA. When they are about to run out, regenerate the set.
- Codes are stored as BCrypt hashes in the database (starting in
v1.0.0-rc3— EVO-991). Not even the installation operator can read codes in plaintext.
Regenerating Codes
Profile → Security → Regenerate backup codes.
Attention: when you regenerate, old codes stop working. Do this only when you have access to the authenticator app at the moment, to confirm regeneration.
When to Regenerate
- After using a code — to keep the stock full.
- After suspected compromise — if you think someone might have seen your code list.
- After organizational change — if you moved roles and the old list was somewhere accessible to others.
For installations that existed before v1.0.0-rc3: codes generated at that time were stored as plaintext in the database. If the database history was accessible to anyone outside the installation operator, regenerating is recommended.
Account Recovery Without 2FA or Backup Codes
If you lose both the authenticator app and the backup codes:- Contact the installation administrator (
super_admin). - The administrator can disable 2FA on your account via the admin console.
- After the subsequent login, re-enable 2FA immediately with a new device and save new backup codes.
The installation administrator cannot read your codes (stored as hashes). The only possible operation is zeroing the 2FA on the account so you can reconfigure.
Security Recommendations
- Use an authenticator app, not SMS. SMS is vulnerable to SIM swap.
- Store backup codes in a password manager. Avoid printing and tossing into a drawer.
- Do not share backup codes. They are equivalent to your second factor.
- Enable 2FA on administrative accounts. Especially
super_adminandaccount_owner.