security
Two-Factor Authentication
TOTP 2FA on every sign-in, before your code security even runs.
What you get
Works with any authenticator app
Standard TOTP (RFC 6238). Google Authenticator, Authy, 1Password, Bitwarden, Apple Passwords — any app that generates 6-digit time-based codes works. No proprietary app required.
Enforced at sign-in, not optionally enabled
Once enrolled, every sign-in requires the second factor. Not a setting users can quietly disable. The middleware checks Multi-Factor Assurance Level 2 (aal2) on every authenticated request.
Account security before code security
A compromised account bypasses every code-level security check. 2FA addresses the layer below the deploy scanner — it stops an attacker from reaching the deploy interface at all.
How enrollment works
- 1
Go to Settings → Security → Enable Two-Factor Authentication.
- 2
Scan the QR code with your authenticator app.
- 3
Enter the 6-digit code to confirm enrollment.
- 4
From this point, every sign-in requires your password plus a code from the app.
- 5
Recovery codes are generated at enrollment. Store them somewhere safe — they're the only way back in if you lose your device.
What it replaces
Auth0 B2B MFA
Separate MFA layer requiring integration work
Okta Verify
Enterprise SSO/MFA, significant setup overhead
ZipLoom (includes all features)
$99/yrRelated features