Two-Factor Authentication
Two-factor authentication (2FA) adds an extra layer of security to your Tidy Names account by requiring a time-based code from an authenticator app in addition to your magic link sign-in.
How It Works
When 2FA is enabled, signing in with a magic link will prompt you for a six-digit code from your authenticator app before granting access. This means even if someone gains access to your email, they cannot sign in without your authenticator device.
Note: If you sign in via SSO (Microsoft Entra ID), your identity provider handles MFA separately. Tidy Names 2FA only applies to magic link sign-ins.
Compatible Authenticator Apps
Any TOTP-compatible authenticator app will work, including:
- Google Authenticator (iOS / Android)
- Microsoft Authenticator (iOS / Android)
- Authy (iOS / Android / Desktop)
- 2FAS (iOS / Android)
- 1Password, Bitwarden, or any password manager with TOTP support
Setting Up 2FA
- Go to User Settings → Security
- Under Two-Factor Authentication, click Enable
- A QR code will appear. Open your authenticator app and scan it. If you cannot scan the code, click "Can't scan? Enter key manually" to reveal the secret key and type it into your app.
- Enter the six-digit code shown in your authenticator app and click Verify
- Save your backup codes in a secure location. You can copy them to your clipboard or download them as a text file.
Backup Codes
When you enable 2FA, you receive a set of one-time backup codes. Each code can be used exactly once to sign in if you lose access to your authenticator app.
- Store them safely - treat backup codes like a password. Save them in a password manager or print them and store them somewhere secure.
- Regenerate if needed - if you run low on backup codes or suspect they have been compromised, you can regenerate a new set from User Settings → Security. This invalidates all previous codes.
Changing Your Authenticator App
If you switch to a new phone or a different authenticator app, go to User Settings → Security and click Change Authenticator. This generates a new QR code and secret key for your new app. Your old app will stop generating valid codes.
Disabling 2FA
You can disable 2FA from User Settings → Security by clicking Disable and confirming with a current authenticator code. If your organisation requires 2FA, you will not be able to disable it.
Organisation-Wide MFA Enforcement
Organisation owners can require all members to use 2FA. When enabled:
- Existing members who have not set up 2FA will be prompted to do so on their next sign-in
- New members must set up 2FA before they can access the organisation
- Members cannot disable their own 2FA while the requirement is active
To enable this, go to Settings → Security and toggle Require two-factor authentication.
Troubleshooting
Codes are not working
- Ensure your device's clock is accurate. TOTP codes depend on your device time being within 30 seconds of the server. Enable automatic time sync in your device settings.
- Make sure you are entering the code for Tidy Names, not a different account in your authenticator app.
Lost access to your authenticator app
- Use one of your backup codes to sign in, then set up a new authenticator from User Settings → Security
- If you have no backup codes remaining, contact your organisation owner or email support@tidynames.com for account recovery
"Your organisation requires two-factor authentication"
This message appears when your organisation owner has enabled MFA enforcement. You must complete the setup wizard before you can access the dashboard. Follow the steps under Setting Up 2FA above.
Next Steps
- Team & Access - roles, permissions, and member management
- Billing & Plans - SSO availability by plan