A stolen password shouldn’t be enough to get into an account. 2FA adds a second login step: after their password, users enter a six-digit code from an authenticator app on their phone. Let users opt in, or require it for the roles that matter most.

Features

  • Works with any standard authenticator app, such as Google Authenticator or Authy
  • Set up by scanning a QR code or entering a key by hand
  • QR codes are generated on your site, so the secret key never goes to a third-party service
  • 10 single-use backup codes for when a phone isn’t handy
  • Require 2FA by role. Users in those roles are sent to set it up before they can continue
  • The current password is needed to turn 2FA off
  • Repeated wrong codes lock out the 2FA step for 10 minutes