PepoChat

Two-factor authentication

Protect your account with a code from an authenticator app, keep backup codes safe, and trust the devices you use every day.

Two-factor authentication (2FA) asks for a six-digit code from an authenticator app in addition to your password, so a leaked password alone cannot open your workspace. Each team member turns it on for their own account from the Profile page. Google Authenticator, 1Password, Authy or any other app that supports time-based codes works.

Turn it on

  1. Open Profile

    Choose Profile from the user menu at the bottom of the sidebar. The Two-factor authentication card below Password shows Off with "Only your password protects this account." Click Enable two-factor authentication.

  2. Confirm your password

    A dialog asks for your current password. A wrong one shows "Incorrect password." and nothing changes.

  3. Scan the QR code

    The Set up two-factor authentication dialog shows a QR code. Scan it with your authenticator app; the entry is labelled "PepoChat" with your email. If you cannot scan, click Can't scan? Enter this key manually and type the key into the app.

  4. Save your backup codes

    The same dialog lists your single-use backup codes, each of the form xxxxx-xxxxx, with a Copy button. Store them somewhere safe, such as a password manager: they are the only way in if you lose the phone with the app.

  5. Enter the first code

    Type the six-digit code your app shows. It submits on the sixth digit, the dialog closes with "Two-factor authentication is on", and the card shows On. Closing the dialog before that leaves the account unprotected and shows "Two-factor authentication is still off".

Note

Right after you turn 2FA on or off the dashboard shows its loading screen for a moment. You stay signed in.

Signing in with it

Sign in with your email and password as usual. The button reads "Redirecting..." and a page titled Two-factor authentication asks you to "Enter the 6-digit code from your authenticator app to finish signing in." Type the code and click Verify code; you land where you were headed, for example the conversation link you clicked.

  • Signing in with Continue with Google is challenged the same way when your account has 2FA on.
  • A challenge is valid for 10 minutes. After that you see "This sign-in attempt has expired. Sign in again to get a new code prompt."
  • A wrong code shows "That code didn't work. Codes change every 30 seconds — check your authenticator app and try again." Repeated wrong codes end the attempt ("Too many wrong codes for this attempt. Sign in again to start over."), and continued failures lock the account for 15 minutes.
  • You are not signed in until the code is accepted: opening the dashboard in another tab meanwhile sends you to the sign-in page.

Trusted devices

Tick Don't ask for a code on this device for 30 days on the challenge page and this browser skips the code on later sign-ins. The 30 days count from the last sign-in, so a device you use every day keeps its trust. A private window, a different browser or a cleared browser asks for the code again. Turning two-factor off forgets every trusted device.

Backup codes

If your phone is not at hand, click Use a backup code instead on the challenge page and enter one of the saved codes. Hyphens and spaces do not matter; letter case does. Each code works once. There is no button to issue a new set yet: turn two-factor off and on again to get fresh codes, and discard the old list.

If you have lost both the app and the backup codes, ask support to reset two-factor authentication on your account.

Turn it off

On Profile, click Disable two-factor authentication and confirm your password. The card shows "Two-factor authentication turned off", the authenticator entry and backup codes stop working immediately, and every trusted device is forgotten.

Google-only accounts

Turning 2FA on or off asks for your current password. An account that has only ever signed in with Google has no password, so the button fails with "Incorrect password." and 2FA is not available for it.

Something missing or wrong on this page? Tell us and we will fix it.