Skip to content
Security and sign-in7 min read

Two-factor authentication

Add an authenticator app to your sign-in, so a stolen password alone is not enough to reach your workspace.

Browse topics

What it is

Two-factor authentication adds a second proof of identity to your sign-in. After your password is accepted, Agentency asks for a six-digit code from an authenticator app on your phone.

The code changes every thirty seconds and is generated on your device, not sent to you. That is the point: somebody who steals your password still cannot sign in, because they do not have your phone.

Agentency uses the standard TOTP scheme, which means any mainstream authenticator app works — Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, and others.

When you would use it

Turn it on if any of the following is true, and honestly it is true for most people:

  • Your workspace holds real customer conversations.
  • You are the workspace owner and control billing.
  • You work on a shared or laptop-in-a-bag device.
  • You reuse passwords anywhere (you should not, but two-factor is the safety net if you do).

There is one hard prerequisite: your account must have a password. Enrolment starts by re-checking that password, so an account created purely through Google, which has never set one, cannot enable two-factor. See Sign in with Google.

Where to find it

Open Dashboard → Settings → Security.

Before you start

  • Install an authenticator app on your phone first. Turning this on is easier than turning it off, and half-finishing the flow with no app installed is a waste of a minute.
  • Have somewhere ready to store the backup codes — a password manager is ideal, a printout in a drawer is acceptable, a note in the same phone is not.
  • Do this when you are not in a hurry. The backup codes are shown exactly once.

Steps

  1. Open Dashboard → Settings → Security.
  2. Wait for the status to load. It reads Disabled until the enrolment finishes.
  3. Select Enable 2FA.
  4. Enter your current password. This is a deliberate re-check: it means somebody who has hijacked an open session, but does not know your password, cannot silently attach their own authenticator to your account.
  5. A QR code appears. Scan it with your authenticator app. If you cannot scan — a desktop app, a camera problem — use the "Can't scan? Enter this key manually" option and type the key in.
  6. Your app now shows a six-digit code that changes every thirty seconds. Type the current one into the Authentication code field and confirm.
  7. Your backup codes appear. Save them now. Use Copy codes or Download codes, then tick "I've saved my backup codes somewhere safe." See Backup codes.
  8. Select Done. The status changes to Enabled.
  9. Sign out and back in once, deliberately, to confirm the whole loop works before you rely on it.

What you will see

Security is an inline flow, not a modal: the card itself moves through password, then QR code, then backup codes, then done. You can see where you are the whole time.

The status reads Enabled or Disabled, and briefly shows a loading state while it fetches — a moment of neither is normal, not a fault.

At sign-in with two-factor on, the form gains a field labelled Authentication code, with the placeholder "6-digit code or backup code" and the hint "Enter the 6-digit code from your authenticator app, or one of your saved backup codes." One field accepts either.

Signing in from then on

  1. Enter your email and password as usual.
  2. The code field appears.
  3. Open your authenticator, read the six digits for Agentency, and type them.
  4. You are in.

If the code is refused, the message is "That code is invalid or expired. Please try again." Codes expire quickly, so a code you read thirty seconds ago may already be dead — wait for the next one and use that.

There is one more place a code is asked for: deleting your account. The confirmation dialog asks for an authentication code as well as your typed email. See Delete your account.

Turning it off, and rotating codes

Both Disable 2FA and Regenerate backup codes ask for your password and a current code. That combination is not bureaucracy — it is what stops someone with a stolen session from quietly removing your second factor, or from generating a fresh set of backup codes for themselves.

Note the asymmetry: enabling needs only your password, disabling needs password plus a code. Downgrading your security is deliberately the harder direction. For the same reason, you cannot re-enrol on top of an active setup; disable first, then enable again.

What happens after too many wrong attempts

Failed codes count toward the same account lockout as failed passwords. After repeated failures the account is locked for about 15 minutes, and during that window even correct credentials are refused.

This applies to wrong codes at sign-in and to wrong codes on the Security page. If you are grinding through old backup codes trying to find an unused one, you can lock yourself out — stop, wait, and come back with a fresh authenticator code instead.

Limits and plan notes

  • Two-factor is available on every plan, including Free. It is not a paid feature.
  • Only app-based two-factor is offered. There is no SMS second factor, and no email code. If your installation asks for a phone number at signup, that is a different mechanism — see Phone verification.
  • Two-factor belongs to your login, not to a workspace. It protects you in every workspace you can open, and a workspace owner cannot require it of members or turn it off for them.
  • Each person enrols their own device. There is no shared workspace authenticator.
  • Enrolment requires a password, so Google-only accounts see guidance instead of the Enable button.

Common problems

Enable is missing, or shows a message instead of a button.

You sign in with Google and have never set a password, so there is nothing to re-check. The page says so directly: "Your account signs in with Google, so it has no password to verify. Set a password first to enable two-factor authentication."

My code is always rejected.

Almost always clock drift on your phone. Turn on automatic date and time in your phone's settings — TOTP depends on your phone and the server agreeing on the time. A small drift is tolerated; a large one is not. Also check you are reading the Agentency entry in your app and not another account's.

I scanned the QR code twice and now have two entries.

Only one is valid — the one from the enrolment you actually completed. Delete the other from your app to avoid confusion later.

I lost my phone.

Use a backup code at sign-in. Then, once you are in, disable and re-enable two-factor on the new phone so you get a fresh secret and a fresh set of codes.

I lost my phone and never saved the backup codes.

You cannot sign in yourself. Contact support with proof of ownership — see Contact Support. This is precisely the situation the backup codes exist to prevent, and it is why the flow makes you tick a box saying you saved them.

I get "locked" instead of "wrong code".

Too many failed attempts. Wait about 15 minutes, then use a fresh authenticator code rather than another guess.

Common questions

Which authenticator apps work?

Any standard TOTP app — Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden and others. Agentency does not require a specific one.

Why does enabling need my password again?

So someone who hijacked an open session, but does not know your password, cannot silently attach their own authenticator to your account.

Why is disabling harder than enabling?

Disabling asks for your password and a current code. Downgrading your security is deliberately the harder direction to travel.

My codes are always rejected. What is wrong?

Almost always clock drift. Turn on automatic date and time on your phone — the code depends on your phone and the server agreeing on the time.

Is there an SMS option instead of an app?

No. Only app-based codes are offered. A phone check at signup, where your installation requires one, is a completely separate mechanism.

Was this article helpful?

Ready to try it on your own content?

Create a free workspace, add a document, and ask the questions your team is tired of answering.