Skip to content

Turn on two-factor authentication

Two-factor authentication (2FA) adds a second step at sign-in so a leaked password is not enough on its own. ScatterSpoke uses TOTP — six-digit codes from an authenticator app — backed by one-time recovery codes.

It is per-account, not per-workspace: you turn it on for yourself, on Settings → Account, on every plan.

Open Settings → Account. Under Sign-in & security, find Two-factor authentication and select Set up beside Authenticator app.

Confirm your password. This is required before ScatterSpoke will generate a new setup code, and it is asked again if you later disable 2FA.

Scan the QR code with 1Password, Google Authenticator, Authy, or any other TOTP app. The entry will appear under the issuer ScatterSpoke.

If you cannot scan, the Manual setup key below the code is the same secret in text form — paste it into your app instead.

The same dialog shows a block of recovery codes, with a Copy button. Each one works once, and they are what gets you back in if you lose your phone.

Put them in a password manager, not in the same app that generates your codes.

Enter the current six-digit code from your app and select Verify and enable.

2FA is not active until this step succeeds — generating a QR code alone does nothing. When it does succeed, the card flips to On and the Authenticator app row is badged Primary.

After entering your email and password you land on a Two-factor authentication screen.

  • Enter the six-digit code from your app and select Verify code. This path trusts the device, so you are not challenged on every sign-in from it.
  • Or select Use a recovery code, enter one of your saved codes, and select Verify recovery code. This path does not trust the device — it is a way in, not a way to stop being asked.

Select Manage on the Authenticator app row, confirm your password, and select Disable authenticator app. Your existing recovery codes stop working; enrolling again issues a fresh set.

Until 2FA is on, a banner across the top of the app suggests securing your account. Dismiss hides it, remembered per browser and per user — so dismissing it on a shared machine does not hide it from the next person who signs in. Turning 2FA on removes it everywhere, permanently.

The same prompt appears during onboarding, where you can set 2FA up before inviting anyone else.

Your account page scores its own posture: 2FA is the single biggest contributor, and adding a passkey is the next. If your workspace uses single sign-on, your identity provider may already enforce MFA — but administrators keep password login as a recovery path, which is exactly the account most worth protecting here.