security

Two-Factor Authentication

TOTP 2FA on every sign-in, before your code security even runs.

What you get

Works with any authenticator app

Standard TOTP (RFC 6238). Google Authenticator, Authy, 1Password, Bitwarden, Apple Passwords — any app that generates 6-digit time-based codes works. No proprietary app required.

Enforced at sign-in, not optionally enabled

Once enrolled, every sign-in requires the second factor. Not a setting users can quietly disable. The middleware checks Multi-Factor Assurance Level 2 (aal2) on every authenticated request.

Account security before code security

A compromised account bypasses every code-level security check. 2FA addresses the layer below the deploy scanner — it stops an attacker from reaching the deploy interface at all.

How enrollment works

  1. 1

    Go to Settings → Security → Enable Two-Factor Authentication.

  2. 2

    Scan the QR code with your authenticator app.

  3. 3

    Enter the 6-digit code to confirm enrollment.

  4. 4

    From this point, every sign-in requires your password plus a code from the app.

  5. 5

    Recovery codes are generated at enrollment. Store them somewhere safe — they're the only way back in if you lose your device.

What it replaces

Auth0 B2B MFA

Separate MFA layer requiring integration work

$0–228/yr

Okta Verify

Enterprise SSO/MFA, significant setup overhead

$2+/user/month

ZipLoom (includes all features)

$99/yr

Related features