Skip to main content
Two-factor authentication (2FA) adds an extra security layer to login. In addition to the password, the user must present a code generated by an authenticator app (TOTP). If access to the app is lost, backup codes allow recovering the account.

Enabling 2FA on Your Account

  1. Go to Profile → Security.
  2. Click Enable two-factor authentication.
  3. Scan the QR code with an authenticator app (Google Authenticator, Authy, 1Password, Bitwarden, etc.).
  4. Type the 6-digit code shown by the app to confirm.
  5. Save the backup codes shown on screen in a safe place (password manager, physical vault).
  6. Confirm.
From now on, every login will require password + app code.

Backup Codes

Backup codes are single-use codes that allow logging in without the authenticator app — useful if you lose your phone, switch devices, or the app fails.

How They Work

  • Each code can be used only once. After use, it is invalidated.
  • You receive a set of codes when activating 2FA. When they are about to run out, regenerate the set.
  • Codes are stored as BCrypt hashes in the database (starting in v1.0.0-rc3 — EVO-991). Not even the installation operator can read codes in plaintext.

Regenerating Codes

Profile → Security → Regenerate backup codes.
Attention: when you regenerate, old codes stop working. Do this only when you have access to the authenticator app at the moment, to confirm regeneration.

When to Regenerate

  • After using a code — to keep the stock full.
  • After suspected compromise — if you think someone might have seen your code list.
  • After organizational change — if you moved roles and the old list was somewhere accessible to others.
For installations that existed before v1.0.0-rc3: codes generated at that time were stored as plaintext in the database. If the database history was accessible to anyone outside the installation operator, regenerating is recommended.

Account Recovery Without 2FA or Backup Codes

If you lose both the authenticator app and the backup codes:
  1. Contact the installation administrator (super_admin).
  2. The administrator can disable 2FA on your account via the admin console.
  3. After the subsequent login, re-enable 2FA immediately with a new device and save new backup codes.
The installation administrator cannot read your codes (stored as hashes). The only possible operation is zeroing the 2FA on the account so you can reconfigure.

Security Recommendations

  • Use an authenticator app, not SMS. SMS is vulnerable to SIM swap.
  • Store backup codes in a password manager. Avoid printing and tossing into a drawer.
  • Do not share backup codes. They are equivalent to your second factor.
  • Enable 2FA on administrative accounts. Especially super_admin and account_owner.

Final Considerations

2FA is the cheapest and most effective access control against leaked credentials. Combine with strong passwords (inline validation helps — EVO-1063) and periodic role review in Custom Roles.