Turn on two-factor authentication
Two-factor authentication (2FA) adds a second step at sign-in so a leaked password is not enough on its own. ScatterSpoke uses TOTP — six-digit codes from an authenticator app — backed by one-time recovery codes.
It is per-account, not per-workspace: you turn it on for yourself, on Settings → Account, on every plan.
1. Start setup
Section titled “1. Start setup”Open Settings → Account. Under Sign-in & security, find Two-factor authentication and select Set up beside Authenticator app.
Confirm your password. This is required before ScatterSpoke will generate a new setup code, and it is asked again if you later disable 2FA.
2. Scan the QR code
Section titled “2. Scan the QR code”Scan the QR code with 1Password, Google Authenticator, Authy, or any other TOTP app. The entry will appear under the issuer ScatterSpoke.
If you cannot scan, the Manual setup key below the code is the same secret in text form — paste it into your app instead.
3. Save your recovery codes
Section titled “3. Save your recovery codes”The same dialog shows a block of recovery codes, with a Copy button. Each one works once, and they are what gets you back in if you lose your phone.
Put them in a password manager, not in the same app that generates your codes.
4. Verify and enable
Section titled “4. Verify and enable”Enter the current six-digit code from your app and select Verify and enable.
2FA is not active until this step succeeds — generating a QR code alone does nothing. When it does succeed, the card flips to On and the Authenticator app row is badged Primary.
What sign-in looks like now
Section titled “What sign-in looks like now”After entering your email and password you land on a Two-factor authentication screen.
- Enter the six-digit code from your app and select Verify code. This path trusts the device, so you are not challenged on every sign-in from it.
- Or select Use a recovery code, enter one of your saved codes, and select Verify recovery code. This path does not trust the device — it is a way in, not a way to stop being asked.
Turning it off
Section titled “Turning it off”Select Manage on the Authenticator app row, confirm your password, and select Disable authenticator app. Your existing recovery codes stop working; enrolling again issues a fresh set.
The security reminder
Section titled “The security reminder”Until 2FA is on, a banner across the top of the app suggests securing your account. Dismiss hides it, remembered per browser and per user — so dismissing it on a shared machine does not hide it from the next person who signs in. Turning 2FA on removes it everywhere, permanently.
The same prompt appears during onboarding, where you can set 2FA up before inviting anyone else.
Worth pairing with
Section titled “Worth pairing with”Your account page scores its own posture: 2FA is the single biggest contributor, and adding a passkey is the next. If your workspace uses single sign-on, your identity provider may already enforce MFA — but administrators keep password login as a recovery path, which is exactly the account most worth protecting here.