Two-Factor Authentication (2FA)
Quick Summary
Two-factor authentication (2FA) adds an extra layer of security to your ResponseIQ account. When enabled, you'll need both your password and a code from your authenticator app to log in, protecting your account even if your password is compromised.
What Is Two-Factor Authentication?
Two-factor authentication (2FA) requires two forms of verification when you log in: something you know (your password) and something you have (a code from your authenticator app). This means that even if someone discovers your password, they still cannot access your account without your phone or authenticator device.
Note
2FA is available for email/password accounts only. If you sign in with Google, your account is protected by Google's own security features, including their 2FA options.
Setting Up 2FA
Before you begin, download an authenticator app on your phone if you don't already have one. Popular options include Google Authenticator, Authy, Microsoft Authenticator, and 1Password.
- Go to Settings and find the "Two-Factor Authentication" section.
- Click "Enable 2FA" and enter your account password when prompted.
- Scan the QR code displayed on screen with your authenticator app. Alternatively, you can manually enter the secret key shown below the QR code.
- Enter the 6-digit code from your authenticator app to verify the setup.
- Save your backup codes in a secure location. These are one-time-use codes that let you log in if you lose access to your authenticator app.
Important
Save your backup codes immediately after setup. They are only displayed once. Store them in a secure location like a password manager, printed copy in a safe, or encrypted file. Without these codes and your authenticator app, you could be locked out of your account.
Logging In with 2FA
Once 2FA is enabled, the login process adds one extra step:
- Enter your email and password as usual on the login page.
- You'll be prompted to enter a verification code.
- Open your authenticator app and enter the current 6-digit code.
- Click "Verify" to complete the login.
Pro Tip
Codes refresh every 30 seconds. If a code doesn't work, wait for the next one. Make sure your phone's clock is set to automatic — an incorrect time can cause codes to be out of sync.
Using Backup Codes
If you can't access your authenticator app (phone lost, app deleted, etc.), you can use a backup code instead of the 6-digit code during login. Each backup code can only be used once.
- On the 2FA verification screen, enter one of your 8-character backup codes in the verification field.
- Click "Verify" — the backup code works the same as a TOTP code.
- The used backup code is automatically invalidated and cannot be reused.
Important
Each backup code can only be used once. After using a backup code, consider regenerating your backup codes from Settings to ensure you always have unused codes available.
Regenerating Backup Codes
You can generate a fresh set of 10 backup codes at any time. This invalidates all previously generated codes.
- Go to Settings and find the "Two-Factor Authentication" section.
- Click "Regenerate Backup Codes".
- Enter your password when prompted.
- Save the new backup codes. All previous backup codes are now invalid.
Disabling 2FA
If you no longer want to use two-factor authentication, you can disable it from your settings. You will need to enter your password to confirm.
- Go to Settings and find the "Two-Factor Authentication" section.
- Click "Disable 2FA".
- Enter your password to confirm.
- 2FA is immediately disabled. You will only need your email and password to log in going forward.
Note
You can re-enable 2FA at any time by going through the setup process again.
Troubleshooting
Here are solutions to common 2FA issues:
- "Invalid code" error — Make sure you're entering the most recent code from your authenticator app. Codes change every 30 seconds. Ensure your phone's clock is set to automatic (Settings > Date & Time > Automatic).
- Lost your phone — Use one of your backup codes to log in, then disable 2FA from Settings and set it up again with your new device.
- Deleted authenticator app — Use a backup code to log in. Then disable 2FA and re-enable it to set up the new app installation.
- No backup codes left — If you've used all backup codes and lost your authenticator app, contact support at support@responseiq.io for account recovery assistance.
- Codes not working after phone reset — If you restored your phone from a backup, some authenticator apps don't transfer codes. Use a backup code to log in, then disable and re-enable 2FA.
Related Articles
Still need help?
Can't find what you're looking for? Our support team is here to assist.
Contact Support