App

Secure your account with two-factor authentication

How to set up two-factor authentication (2FA) in Owneli with an authenticator app, save recovery codes, and get back in if you lose your phone.

Updated Sep 19, 2026

Turn on two-factor authentication in Settings → Profile: scan a QR code with any authenticator app, confirm a 6-digit code, and save the recovery codes you're shown once. From then on, sign-in asks for a code from your app — so a stolen password alone can't open your business.

How do I turn on two-factor authentication?

Before you start: install any standard authenticator app — Google Authenticator, Authy, 1Password, Microsoft Authenticator. Every user can do this for their own account; no admin permission needed.

Open your profile settings

Go to Settings → Profile, find the Two-factor authentication row in the Security section, and click Enable.

Scan the QR code

Scan it with your authenticator app. Can't scan? Type the setup key shown beside the QR code into the app instead.

Confirm with a code

Enter the 6-digit code the app now shows and press Verify & enable.

Save your recovery codes

Owneli immediately generates single-use recovery codes and shows them once. Copy or download them into a password manager. When you close the dialog, they can't be viewed again.

What changes at sign-in

After your email and password (or magic link), you're asked for the current 6-digit code from your authenticator app. Enter it and you're in.

What if I lose my phone?

Recovery codes can't yet be typed in at the sign-in screen — self-service redemption is a planned follow-up. If you're locked out, contact an admin or the owner of your business: they can disable your two-factor so you can sign in and re-enrol. Keep your recovery codes available for that conversation.

From Settings → Profile you can always see how many codes remain and regenerate a fresh set — regenerating invalidates every code from the previous batch.

Requiring it for the whole team

ActionWho can do itWhere
Enrol yourselfEveryoneSettings → Profile
See who has enrolled (roster)AdminsSettings → Team & access → Security
Require two-factor org-wideOwner onlySettings → Team & access → Security

Once enforced, everyone is prompted to enrol at sign-in. Admins can use the roster to chase stragglers before flipping enforcement on.

Common questions

Why am I asked to set up two-factor after signing in?

Owners and admins who have not enrolled may see an optional setup reminder. Not now pauses that reminder for seven days for your account in this browser. Don't remind me dismisses the optional reminder for that account in this browser. Clearing browser storage or using a different device can make it appear again.

These choices do not disable two-factor authentication or override your business's requirement to use it. You can still turn it on at any time in Settings → Profile.

Which authenticator apps work?

Any TOTP app — Google Authenticator, Authy, 1Password, Microsoft Authenticator, and the rest.

How do I turn two-factor off?

Settings → Profile → Disable on the two-factor row. If your business requires it, expect to be prompted to enrol again.

Are recovery codes shown again later?

No. They're displayed exactly once when generated. If you didn't save them, regenerate a new batch — the old ones stop working.

Keep reading

Related

2
Log in and reset your passwordHow to log in to Owneli with a password or a magic link, reset a forgotten password, and fix the most common can't-log-in problems.Roles and permissionsThe four starting roles, the two axes that control access, and how to build a custom role without locking yourself out.