Set up and manage two-factor authentication (2FA)

Set up two-factor authentication, manage recovery options, and require 2FA for admins in your Featurebase Workspace.

Written By Markus from Featurebase

Last updated About 18 hours ago

Overview

Two-factor authentication (2FA) protects your Featurebase account by requiring a verification code from an authenticator app after your usual sign-in method.

Each teammate manages 2FA for their own account. Workspace admins with the required permission can also require every admin to use 2FA.


Set up two-factor authentication

You can use 1Password, Google Authenticator, Authy, or another compatible authenticator app. To enable 2FA:

  1. Go to Settings → Profile

  2. Find the ‘Two-factor authentication’ section and click ‘Set up’

  3. Scan the QR code with your authenticator app, or enter the displayed code manually

  4. Enter the 6-digit verification code generated by your app

  5. Click Verify & enable

  6. Click ‘Copy codes’ and store your recovery codes somewhere secure

  7. Click Done

Featurebase shows 10 recovery codes when you first enable 2FA. They will not be shown again after you leave this section.


Sign in with 2FA

After completing your usual sign-in method, enter the 6-digit code from your authenticator app.

If you cannot access your authenticator app:

  1. Click Use a recovery code instead

  2. Enter one of your saved recovery codes

  3. Click Verify

Each recovery code can only be used once.


Manage your 2FA

Regenerate recovery codes

Your Profile page shows how many recovery codes remain, but it does not display the codes you previously saved. To create a new set:

  1. Go to Settings → Profile

  2. Find Recovery codes and click Regenerate

  3. Enter the 6-digit code from your authenticator app

  4. Click Regenerate codes

  5. Click Copy codes and securely store the new codes

  6. Click Done

Regenerating recovery codes immediately invalidates the previous set.

Add or replace an authenticator app

You can add a backup authenticator app before removing an old device:

  1. Go to Settings → Profile

  2. Under Two-factor authentication, click Add authenticator app

  3. Enter the code from your current authenticator app

  4. Scan the new QR code and verify the 6-digit code from the new app

The new app appears as a Backup factor. Click ‘Set as primary’ if you want to use it as your primary authenticator.

After confirming the new app works:

  1. Select the delete icon beside the old authenticator app

  2. Enter the 6-digit code from your authenticator app

  3. Click Remove factor

Disable 2FA

To disable 2FA:

  1. Go to Settings → Profile

  2. Click Disable 2FA

  3. Enter the code from your authenticator app

  4. Confirm by clicking Disable 2FA

Disabling 2FA removes all connected authenticator apps and recovery codes.

Note: You cannot disable 2FA while any Workspace you belong to requires it.


Require 2FA for all admins

To require 2FA from all of your team members:

  1. Go to Settings → Access & Security → Security

  2. Find Two-factor authentication for admins

  3. Turn on Require 2FA for all admins

Admins who have not enabled 2FA will be prompted to set up an authenticator app the next time they sign in. Admins who already use 2FA can continue signing in with their existing authenticator app.

Turning off the Workspace requirement does not disable 2FA for teammates who enabled it on their own accounts.

Note: Your role needs the Manage SSO permission to change the Workspace-wide 2FA requirement.


FAQs