Two Minute Reports Logo
Account Security

Two-Factor Authentication

Turn on two-factor authentication with a passkey or an authenticator app, save your recovery codes, trust a browser, change your authenticator app, or turn 2FA off.

Two-factor authentication (2FA) adds a second step when you sign in to the Hub, so a stolen password or inbox is not enough to get into your account. You set it up once, in Settings → Security, and it takes about two minutes.

You can use a passkey or an authenticator app. Either one keeps your account safe, and you can add the other later:

PasskeyAuthenticator app
How you use itYour fingerprint, face or screen lock, the same way you unlock your phone or laptopYou type a 6-digit code from an app on your phone
Where it livesA password manager such as iCloud Keychain, Google Password Manager or 1PasswordAn app such as Google Authenticator, Microsoft Authenticator or 1Password
Good to knowNothing to type, and it cannot be used on a fake sign-in pageWorks with any computer or browser. Familiar if you already use 2FA elsewhere

2FA is on as soon as you have one of them. Once it's on, every sign-in to the Hub asks for your passkey or authenticator code as a second step, except a sign-in with a passkey, which counts as both steps on its own.

Turning On 2FA With a Passkey

Open Security settings

Go to Settings → Security. Under Two-factor authentication, click Set up 2FA.

Confirm it's you

Because this changes how you sign in, the Hub first asks you to confirm it's you with your password, Google, Microsoft or an email code.

Choose Passkey

Under Choose your second step, select Passkey and click Continue. Not sure what a passkey is? Click What's a passkey? for a short explanation.

Create the passkey

Click Create passkey. Your browser asks where to save it, then asks for your fingerprint, face or screen lock. Save it to your password manager if you want to use it on your other devices too.

Name it

The Hub suggests a name based on your device, such as MacBook Pro. Change it if you like, so you can tell your passkeys apart later, and click Continue.

Save your recovery codes

Save the ten recovery codes, tick I've saved my recovery codes somewhere safe, and click Finish. See Recovery codes below.

If the Passkey option says Not available here, this browser cannot create passkeys. Choose the authenticator app now, or set up 2FA from your phone or another browser. You can always add a passkey later.

If the browser says your device can't check it's you, the device has no screen lock. Turn on a fingerprint, face or PIN lock and try again, or save the passkey to your phone. We only accept passkeys that check it's you every time, because a passkey that anybody holding the device could use would not be a second factor.

If it says this device already has a passkey for your account, use a different device or password manager, or choose the authenticator app.

Turning On 2FA With an Authenticator App

Open Security settings

Go to Settings → Security. Under Two-factor authentication, click Set up 2FA.

Confirm it's you

Confirm with your password, Google, Microsoft or an email code.

Choose Authenticator app

Under Choose your second step, select Authenticator app and click Continue.

Add Two Minute Reports to the app

Open your authenticator app and tap Add or +. Scan the QR code on screen, or type in the setup key shown under it. Not sure which app to use? Click Which app should I use?. Google Authenticator, Microsoft Authenticator and 1Password all work.

The app adds an entry called Two Minute Reports with your email address.

Enter the code

Type the 6-digit code the app shows and click Verify. The app is only saved once a correct code has been entered.

Save your recovery codes

Save the ten recovery codes, tick I've saved my recovery codes somewhere safe, and click Finish.

"That code didn't match"? The usual cause is a phone clock that is slightly off, because the codes are worked out from the time. Make sure your phone sets its date and time automatically, then enter the code your app shows now. See My 2FA code doesn't work.

You can also start from the method rows in the same block: Add next to Passkey, or Set up next to Authenticator app. Either one turns 2FA on.

Recovery Codes

Recovery codes are for the day you cannot use your phone or your passkey. You get ten of them, straight after you add your first 2FA method. Each one:

  • is 16 characters long, shown as four groups of four, like K7QM-2XPA-9RTE-H4WN
  • works once, in place of your passkey or authenticator code
  • ignores dashes and capital letters, and never uses the characters I, L, O, U, 0 or 1, so nothing looks alike

We show them only once. We store them in a form we cannot read back, so they cannot be shown again later, by the Hub or by support. Click Copy or Download .txt and keep them somewhere safe that is not your phone: a password manager, or a printed copy.

Without recovery codes, losing your phone or passkey means asking support to turn 2FA off, which takes three days. Saving them takes ten seconds.

If you close the setup window before saving them, the Hub asks Did you save your recovery codes? 2FA stays on either way. If you did not save them, Settings → Security shows a red Not saved row under Recovery codes until you do: click Generate codes to get a fresh set.

Generating New Codes

Settings → Security shows how many codes you have left, such as 8 of 10 left. At 3 or fewer the row turns amber, and at none it turns red.

To get a fresh set, click Generate new codes, then confirm it's you with your passkey or authenticator app. Your old codes stop working as soon as the new ones are made, so save the new set before closing the window.

Do this whenever you use a code, run low, or think someone else may have seen them.

Trusting a Browser for 30 Days

On the second step at sign-in there is a tick box: Don't ask for a second step on this browser for 30 days. It is unticked by default. Tick it, and this browser skips the second step at sign-in for the next 30 days.

Only tick it on your own computer. Not on a shared, borrowed or public one.

A trusted browser:

  • skips only the second step at sign-in. It never skips Confirm it's you.
  • is marked Trusted for 30 days in your active sessions.
  • is not offered when you sign in with a recovery code.

Every trusted browser is forgotten, and will ask for the second step again, when you:

  • set, change or reset your password
  • add or remove a passkey or authenticator app, or turn 2FA off
  • sign in with a recovery code
  • click Sign out of all other browsers

Changing Your Authenticator App

Moving to a new phone, or switching apps:

Click Change app

In Settings → Security, next to Authenticator app, click Change app.

Confirm it's you

Use your authenticator app, a passkey, or a recovery code. A recovery code is accepted here so that someone whose old phone is gone can still make the change.

Add Two Minute Reports to the new app

Open your new authenticator app, tap Add or +, and scan the QR code or enter the setup key.

Enter the code

Type the 6-digit code from the new app and click Verify.

Your old app keeps working until the new code is verified. After that, codes from the old app no longer work, and you can delete its Two Minute Reports entry. Your recovery codes are unchanged.

Removing One Method

If you have more than one method, you can remove one and 2FA stays on with the rest.

  • To remove the authenticator app, click the bin icon on its row, then Remove app. Codes from the app stop working.
  • To remove a passkey, see Removing a passkey.

Either way, you then confirm it's you with a passkey or the authenticator app. A recovery code is not accepted for removing a single method.

Removing your last method turns 2FA off, with everything described in the next section. The Hub tells you so before you confirm: Remove your last 2FA method?

Turning Off 2FA

Click Turn off 2FA

In Settings → Security, under Two-factor authentication, click Turn off 2FA.

Read what will happen

The dialog lists what will be removed. Click Turn off 2FA.

Confirm it's you

Use a passkey, your authenticator app or a recovery code.

Turning 2FA off:

  • removes every 2FA method: all your passkeys, your authenticator app and your recovery codes. Your passkeys stop working for sign-in too, because they were part of 2FA.
  • signs out your other browsers and forgets every trusted browser.
  • leaves your password, Google and Microsoft sign-in, API keys and connected apps as they were.

After that, signing in needs only your password, Google, Microsoft or an email code. We email you to confirm. To turn it back on, set it up again; you get new recovery codes.

If a team you belong to requires 2FA, you can't turn it off.Settings → Security names the team, for example Northwind Digital requires 2FA, so you can't turn it off, and the same applies to removing your last method. Add another method first if you want to swap one for another. See Require two-factor authentication.

Signing In With 2FA

After the first step (password, Google, Microsoft or email code), the Hub shows Finish signing in, with what already worked shown at the top.

  • It opens on the method you used most recently. Click Use passkey, or type your authenticator code and click Sign in.
  • Use another method lists everything you have: Passkey, Authenticator app and Recovery code.
  • Can't use any of these? explains how to get help signing in.

After 5 wrong codes in one go, or 10 in 15 minutes across signing in and confirming, the Hub says Too many attempts and asks you to try again in 15 minutes. Your account is never locked by wrong 2FA codes.

If someone enters your password correctly and then gets the second step wrong 5 times, we email you: Someone tried to sign in to your account. 2FA stopped them, but they have your password, so change it.

Copyright © 2026