Settings → Security lets you add a second step to your sign-in. It's optional, but it's the single biggest thing you can do to keep your account safe.
2FA uses an authenticator app - a TOTP app such as Google Authenticator, 1Password, or Authy - that generates a fresh 6-digit code every 30 seconds. After you enter your password, PocketPass asks for that code, so a stolen password on its own is no longer enough to get in.
Turning it on
- Open Settings → Security.
- Scan the QR code with your authenticator app - or enter the setup key by hand if you can't scan.
- Enter the 6-digit code your app shows to confirm the two are linked.
- Save your recovery codes somewhere safe before you finish.
Once it's on, every sign-in from then on asks for a code from your app after your password.
It's per person
2FA is set up per user, not per account. Turning it on protects your sign-in only - it doesn't enable it for your teammates. Each person who signs in enables it on their own account from their own Security page.
If you run an account with several people who can message customers, it's worth encouraging everyone to switch it on. An account is only as protected as its least-protected member. See Team members and roles.
Recovery codes
When you enable 2FA you're given a set of recovery codes. Each one is a one-time way back in if you lose access to your authenticator - a new phone, a wiped device, a deleted app.
Save your recovery codes somewhere safe and separate from your phone - a password manager, or printed and stored securely. If you lose your authenticator and your recovery codes, you can be locked out of your account. The codes are the safety net; don't skip saving them.
Losing your authenticator
If you still have a recovery code, use it in place of the 6-digit code at sign-in, then set up your authenticator again from the Security page.
If you've lost both your authenticator and your codes, contact us so we can help you recover access.
Where to go next
- Your account - your email, role and password.
- Team members and roles - who else can sign in to this account.