Two-Factor Sign-In

Add a second step to signing in: a 6-digit code by email, or by text if you prefer. Turn it on for yourself, or require it of everyone.

A password is one secret, and it leaks: reused on another site, guessed, phished, or read off a sticky note by whoever walks past the desk. Two-factor sign-in adds a second step that lives somewhere else, so knowing the password is no longer enough.

Manuall sends a 6-digit code. It goes to your email by default, or to your phone if you set that up. This is often written 2FA, or multi-factor authentication.

Turning it on for yourself

Open Profile, find Two-Factor Sign-In, and tap Turn it on.

The Two-Factor Sign-In card on the profile page in its off state, with a line saying the password is the only protection and a Turn it on button
Off. One button, and nothing to install.

That is the whole setup. There is nothing to install and no code to scan, because the code goes to the email address you already sign in with. Next time you sign in, you enter your password, then a code.

The same card switched on, marked On, showing which email address codes go to and a collapsed Turn two-factor off section
On, and it tells you which inbox to watch.

Getting the code by text instead

If your platform has text messaging switched on, a Prefer a text? field appears once two-factor is on.

  1. Enter your mobile number.
  2. We text a code to it.
  3. Enter that code to confirm.

The number does not take effect until the code comes back. A typo cannot leave you waiting for a code at a handset nobody holds.

This is your number and only you can set it. It is deliberately not read from your team profile: that field can be edited by anyone with permission to manage the team, and a second factor that a colleague can point elsewhere is not a second factor.

If you do not see the option, your platform has not switched on text messaging yet. Email still works.

"Do not ask again on this device"

The code screen has a checkbox that remembers the browser you are on for 7 days. Tick it on your own laptop and you will not be asked again for a week. Leave it unticked on a shared or borrowed machine.

The two-factor verification screen showing a partly masked destination address, a 6-digit code box, a do not ask again for 7 days checkbox, Verify, and Send it again
The code screen. The address is masked, because whoever reached it already has the password.

Changing your password cancels every remembered device at once, everywhere. So does an administrator forcing you out. That is the point: if you think somebody got in, change your password and every browser they marked as trusted stops being trusted.

Requiring it for everyone

Open Settings, then the Users tab, and tick Require two-factor sign-in for everyone.

This is safe to switch on without warning anybody. Nobody has to set anything up first, because email needs no setup: a user who has done nothing simply gets a code at the address they already sign in with. Nobody is locked out waiting to enrol.

The Users tab in Settings with a Require two-factor sign-in for everyone checkbox above the list of user accounts
One checkbox above the people it governs.

Turning it back off leaves individual choices alone. Anyone who turned it on for themselves keeps it.

When somebody cannot get their code

Lost phone, changed number, inbox they cannot reach. An administrator fixes it from Settings, Users: open the row's menu and choose Turn off two-factor.

A user row menu open in Settings showing Edit, Turn off two-factor, and Deactivate
The only lever an admin has over somebody else's second factor, and it only turns it off.

That action only ever turns it off. There is no way for an administrator to set another person's phone number or channel, which is what stops "help me get back in" from becoming a way to redirect somebody else's second factor. Once the user can receive codes again, they turn it back on themselves.

What the code does and does not do

The code expires after 10 minutes, works once, and dies after five wrong tries. Asking for a new one resets that, so a few fat-fingered attempts do not strand you.

It is not a replacement for a good password, and it does not protect a session already signed in on an unlocked screen. It protects the moment of signing in, which is where stolen passwords get used.

Platform administrators

If you sign in with the system company code, your second factor is an authenticator app rather than an emailed code, set up at Two-Factor Authentication in the platform admin area. That is a stronger factor, and appropriate for an account that can reach every business on the platform.

Common questions

Does every user have to use the same channel? No. It is per person. One tech texts, everybody else emails.

Will a tech in the field get stuck without signal? They need signal to receive the code, the same as they need it to reach Manuall at all. Once signed in, the 12-hour session and the offline queue work as they always did.

Does this cost anything? No.

What if our email is down? Then codes do not arrive, and an administrator can turn two-factor off for whoever is stuck. Worth knowing before you require it across a shop that runs its own mail server.

What to read next