Two-factor authentication

The emailed sign-in code — on by default — trusted devices, and how to require it for everyone.

Signing in asks for a code as well as a password. After the password is accepted, a six-digit code is emailed to the address on the account; the session only exists once that code is entered.

It is on by default

Every account is created with email two-factor switched on. Nobody has to turn it on, and a new staff member you add gets it too. If you were not expecting a code at sign-in, this is why.

The code

RuleValue
LengthSix digits
Valid for10 minutes from when it was sent
Attempts5, then the code is dead and you start again
ResendAllowed after 30 seconds

Asking for a new code cancels the previous one, so always type the most recent email. A wrong code, an expired code and a code for an account that does not exist all produce the same answer — nothing about the account is given away.

Remembering a device

Tick Trust this device for 30 days on the code screen and that browser skips the code until it lapses. It is per browser and per device: the shop iPad and the office laptop are remembered separately, and a private window is not remembered at all.

An admin can clear them. In Settings → Staff, editing a staff member shows a Revoke trusted devices button with the count on it. Use it when a device is lost or a staff member leaves — the next sign-in from anywhere then needs a fresh code.

Turning it off for one person

In Settings → Staff, edit the staff member and clear Email two-factor authentication. The checkbox appears only when editing someone — new staff always start with it on.

Forcing it for everyone

Settings → Access Levels → Sign-in Security carries Require two-factor authentication. Turning it on removes the individual choice: every staff member must enter an emailed code, whatever their own setting says.

Everyone needs an email address first

A staff member with no email address on their record cannot be sent a code. Normally they are simply let through without one, and the skip is written to the audit trail. Once the company-wide requirement is on, that is no longer allowed — so switching it on is refused while any active staff member who can sign in has no email address, and the screen lists exactly who to fix.

If codes stop arriving

Repeated bounces suppress an address, and a suppressed address cannot receive codes. The staff list flags this against the person concerned. Fix the address, or clear the suppression in Settings → Email.

Still stuck? We answer every message.Contact support