Two Minute Reports Logo

Account Security

Two-factor authentication, passkeys and "Confirm it's you": what they are, how they change signing in to the Hub, and where to manage them.

Your Two Minute Reports account reaches your clients' ad accounts, analytics and revenue data. A password on its own, or access to your inbox, is not much of a lock for that. Two-factor authentication (2FA) adds a second step when you sign in to the Hub, so someone who has your password, or has got into your email, still cannot get in.

Everything on these pages lives in the Hub at Settings → Security.

Two-Factor Authentication in Plain Words

When 2FA is on, signing in takes two things instead of one: the usual way you sign in (your password, Google, Microsoft or an email code) and something only you have with you. That second thing is one of two methods, and either is a good choice:

  • A passkey. Your phone or computer confirms it's you with your fingerprint, your face or your screen lock, the same way you unlock the device. There is nothing to type. Passkeys are saved in a password manager such as iCloud Keychain, Google Password Manager or 1Password, and they cannot be used on a fake sign-in page. See Passkeys.
  • An authenticator app. An app on your phone, such as Google Authenticator, Microsoft Authenticator or 1Password, shows a 6-digit code that changes every 30 seconds. You type the code when asked. It works with any computer or browser.

2FA is on as soon as you have at least one of them. You can have both, and you can add more than one passkey. When you set it up you also get ten recovery codes, for the day you cannot use your phone or passkey.

Adding a passkey turns on two-factor authentication. A passkey is a 2FA method, so there is no way to have a passkey with 2FA off.

How Signing In Changes

Once 2FA is on, every way of signing in to the Hub asks for a second step, except a passkey:

You sign in withWhat happens next
Your email and passwordWe ask for your passkey or an authenticator code
GoogleWe ask for your passkey or an authenticator code
MicrosoftWe ask for your passkey or an authenticator code
An email codeWe ask for your passkey or an authenticator code
A passkeyYou're in. A passkey already checks two things: the device you have, and your fingerprint, face or screen lock

We ask even when you sign in with Google or Microsoft, because we cannot see whether your Google or Microsoft account has 2FA of its own.

On the second step you can tick Don't ask for a second step on this browser for 30 days. Only tick it on your own computer. See Trusting a browser.

"Confirm It's You" Before Sensitive Actions

Some actions are worth a second look even when you're already signed in: changing how you sign in, creating an API key, connecting an AI app, changing a team's security setting, or opening billing. Before those, the Hub shows a short Confirm it's you dialog. If you have 2FA, you confirm with your passkey or authenticator app; if you don't, with your password, Google, Microsoft or an email code. See Confirm it's you for the full list.

What Settings → Security Shows

BlockWhat it's for
Two-factor authenticationWhether 2FA is on and since when, your passkeys, your authenticator app, and how many recovery codes you have left. Set up 2FA and Turn off 2FA live here
Ways you sign inEvery way into your account: password, Google, Microsoft (once you've used it), passkey and email code. Google and Microsoft users can Set a password here
Active sessionsEvery browser signed in to your account and every connected app, with Sign out of all other browsers. See Active sessions

What 2FA Does Not Affect

  • The Google Sheets add-on and the Looker Studio connector. Neither uses Hub sign-in, so neither asks for a second step.
  • Existing API keys and MCP connections. They keep working when you turn 2FA on or off.

Security Emails

We email you, from [email protected], whenever something changes how your account can be reached: 2FA turned on or off, a method added, removed or changed, new recovery codes, a new password or API key. Each email says when it happened, in which browser and roughly where. No email ever contains a code, a key or a sign-in link.

The ones you are most likely to see:

EmailSent when
Two-factor authentication is onYou add your first passkey or authenticator app
A passkey was added to your accountYou add another passkey while 2FA is already on
Two-factor authentication was turned off2FA was turned off, your last method was removed, or support turned it off at your request
A recovery code was used to sign inA recovery code was used, with how many you have left
Someone tried to sign in to your accountSomeone entered your password correctly, then the wrong second-step code 5 times
A password was added to your accountA Google or Microsoft user set a password
A new API key was createdAn API key was created on your account. It names the key, never shows it

If you get one of these and did not do it, change your password and email [email protected].

Requiring 2FA for a Whole Team

Owners, Admins and Deputy Admins can make 2FA a requirement for everyone in a team. Members get a week to set it up. See Require two-factor authentication.

In This Section

Two-Factor Authentication
Set it up with a passkey or an authenticator app, save recovery codes, change or turn it off.
Passkeys
Sign in with your fingerprint, face or screen lock. Add, rename and remove passkeys.
Confirm It's You
When the Hub asks you to confirm, and which methods you can use.
Lost Access to 2FA
Lost your phone or passkey? Recovery codes, and how support can help.
Active Sessions
See where you're signed in, and sign out of every other browser.
Copyright © 2026