Skip to content

Two-factor authentication

Add a code from an authenticator app, save your recovery codes, and require two-factor for the whole company.

Two-factor adds a time-based code from an authenticator app to your sign-in. Avaloi stores ten recovery codes when you turn it on.

Turn it on

  1. Open User settings, then Security, then Two-factor.
  2. Scan the QR code with any TOTP app and enter the first code to confirm.
  3. Save the recovery codes. Download or print them. Each code works once. Store them offline.

Who must use it

  • Owners, and anyone who can grant danger:destroy or domains:transfer_out on an API key, must enroll.
  • An Owner or Admin can require two-factor for every member. On their next request those members enroll and cannot skip it.

Require it for the company

Open Company settings, then Security, then Require two-factor for everyone. Members without two-factor are sent to enrollment.

SSO-enforced companies still honor this setting, unless your identity provider already requires a second factor and you accept that as the company control.

Locked out

Use a recovery code on the two-factor screen, then enroll a new authenticator. Each code works once.

If you have no recovery code, support cannot turn two-factor off from chat. Open a recovery request from the sign-in page or email [email protected]. Recovery needs two of three proofs: control of the verified inbox, a government photo ID through the recovery form, or company control. Support will not disable two-factor from chat alone.

Quick answers

Which app do I need? Any TOTP authenticator app.

I got a new phone. Sign in with a recovery code, enroll the new phone, then regenerate your codes.

Does enforced SSO replace two-factor? Not by itself. The company setting still applies unless you accept your provider's second factor as the company control.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.