Skip to content
Open app

securityHow-to guide

Turn on two-factor authentication

Set up an authenticator app for your ScatterSpoke account, save your recovery codes, and know what sign-in looks like afterwards.

Two-factor authentication (2FA) adds a second step at sign-in so a leaked password is not enough on its own. ScatterSpoke uses TOTP — six-digit codes from an authenticator app — with one-time recovery codes if you lose access to the app.

It is per-account, not per-workspace: you turn it on for yourself, on Settings → Profile, on every plan.

Open Settings → Profile. Under Sign-in & security, find Two-factor authentication and select Set up beside Authenticator app.

Confirm your password. This is required before ScatterSpoke will generate a new setup code, and it is asked again if you later disable 2FA.

Two-factor authentication showing Off and the Set up control.

Scan the QR code with 1Password, Google Authenticator, Authy, or any other TOTP app. The entry will appear under the issuer ScatterSpoke.

If you cannot scan, the Manual setup key below the code is the same secret in text form — paste it into your app instead.

The same dialog shows a block of recovery codes, with a Copy button. Each one works once, and they are what gets you back in if you lose your phone.

Put them in a password manager, not in the same app that generates your codes.

Enter the current six-digit code from your app and select Verify and enable.

2FA is not active until this step succeeds — generating a QR code alone does nothing. When it does succeed, the card flips to On and the Authenticator app row is badged Primary.

After entering your email and password you land on a Two-factor authentication screen.

  • Enter the six-digit code from your app and select Verify code. This path trusts the device, so you are not challenged on every sign-in from it.
  • Or select Use a recovery code, enter one of your saved codes, and select Verify recovery code. This path does not trust the device — it is a way in, not a way to stop being asked.

Select Manage on the Authenticator app row, confirm your password, and select Disable authenticator app. Your existing recovery codes stop working; enrolling again issues a fresh set.

Until 2FA is on, a banner across the top of the app suggests securing your account. Dismiss hides it, remembered per browser and per user — so dismissing it on a shared machine does not hide it from the next person who signs in. The reminder is not shown while 2FA is enabled.

The same prompt appears during onboarding, where you can set 2FA up before inviting anyone else.

Use the newest code for your ScatterSpoke account and check that your phone’s time is set automatically. If you cannot access the authenticator app, use a saved recovery code. Each recovery code works only once.

If you have neither, contact your workspace administrator or ScatterSpoke support for help with account recovery. Do not send anyone your password, QR code, manual setup key, or recovery codes.

You can also add a passkey to sign in without typing a password. If your workspace uses SSO, follow its identity provider’s MFA policy too. ScatterSpoke administrators retain a password recovery path, so their account-level 2FA still matters.