Skip to content

Two-factor

Add an authenticator app or emailed codes to sign-in, keep recovery codes, and require two-factor for the whole company.

Two-factor adds a second step after your password: a code from an authenticator app, or a code emailed to you. Avaloi gives you ten recovery codes with the app. The full article is Two-factor authentication.

Turn it on

  1. Open Account settings, then Security, then Two-factor authentication.
  2. Choose Set up for the authenticator app, scan the QR code, and enter the first code. Or choose Turn on for emailed codes.
  3. Save the recovery codes. Each works once.

Require it for the company

An Owner or Admin can require two-factor for every member under Company settings. A member who signs in with a password and has no second step is sent to Security until they set one up. Members who sign in only through Google, GitHub, or your company's single sign-on use that provider's own checks.

Locked out

Use a recovery code on the two-factor screen, then set up a new authenticator. If you have no recovery code, support cannot turn two-factor off from chat. Open a recovery request from the sign-in page or email [email protected]. Recovery needs two of three proofs: control of the verified inbox, a government photo ID through the recovery form, or company control.

Quick answers

Which app do I need? Any app that makes 6-digit time codes.

Can I use text messages? Not yet. The option shows as Coming soon on the Security page.

I got a new phone. Sign in with a recovery code, set up the new phone, then make new recovery codes.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.