# Two-factor authentication

> Protect your intoCHAT email-and-password sign-in with a code from an authenticator app: setup, signing in with a code, recovery codes, turning it off, Google sign-in and lost access.

Two-factor authentication adds a second step when you sign in with your email and password: after the password, intoCHAT asks for a 6-digit code from an authenticator app on your phone or computer. Someone who learns your password still can't sign in without the code.

It's personal. It protects your own intoCHAT login, whichever accounts you work in, and you turn it on or off yourself under **Settings**, **Account**.

## How it works

- Codes come from an authenticator app such as Google Authenticator, Microsoft Authenticator, 1Password or Authy. The app makes a new 6-digit code every 30 seconds, without needing a connection.
- Each code works once. The code from just before or just after the current one is also accepted, to allow for a clock that's slightly off.
- You get 10 recovery codes when you turn it on. Each works once instead of a code from the app, for when you don't have your phone.
- It applies to signing in with your email and password. Signing in with Google doesn't ask for a code. See [Google sign-in](#google-sign-in).

## Turn on two-factor authentication

Your account needs a password. If you only sign in with Google, see [Google sign-in](#google-sign-in) first.

1. Go to **Settings**, **Account**.
2. In the **Two-factor authentication** card, click **Turn on**.
3. Enter your password and click **Continue**.
4. Add intoCHAT to your authenticator app in one of three ways:
   - scan the QR code;
   - type the **Key** shown next to it into the app (time-based, 6 digits, every 30 seconds);
   - on a device with an authenticator app, click **Open in an authenticator app**.
5. Enter the 6-digit code the app shows and click **Confirm and turn on**.
6. Save your [recovery codes](#recovery-codes). Click **Copy** or **Download (.txt)**, store them somewhere safe, then click **I've saved them**.

The app lists the entry as intoCHAT with your email address. Until you confirm a code in step 5, two-factor authentication stays off. If you leave the page before that, click **Turn on** again for a new QR code.

> The recovery codes are shown only once. After you click **I've saved them**, nobody can show them again, including intoCHAT support. You can [make new ones](#regenerate-recovery-codes) with a code from your app.

## Sign in with a code

1. On the sign-in page, enter your email and password and click **Sign in**.
2. When asked to "Enter the 6-digit code from your authenticator app", enter the current code and click **Verify**.

If you don't have your app, click **Use a recovery code** and enter one of your recovery codes instead. Click **Back** to start over with your email and password.

- **"That code isn't right or was already used. Try again."** The code is wrong, expired or was already used for a sign-in. Wait for the app to show a new code and enter that one. Check that the time on your phone is set automatically.
- **"Too many attempts. Wait 15 minutes and try again."** Codes are limited to 10 tries per account and 30 per network address every 15 minutes. Successful sign-ins count too.
- A wrong email or password shows "Invalid email or password", as it does without two-factor authentication. The code step only appears after the right password.

Every sign-in with your email and password asks for a code. There is no "remember this device".

## Recovery codes

You get 10 recovery codes, each like `abcd-efgh-jkmn`. Each works once, in place of a code from the app: when you sign in, and when you [turn off two-factor authentication](#turn-off-two-factor-authentication). Capitals, spaces and dashes don't matter when you type one.

The **Two-factor authentication** card shows how many are left. When 3 or fewer are left, it suggests making new ones.

intoCHAT keeps only a fingerprint (hash) of each code, never the codes themselves.

### Regenerate recovery codes

1. Go to **Settings**, **Account**.
2. In the **Two-factor authentication** card, click **Regenerate recovery codes**.
3. Enter the current 6-digit code from your app and click **Regenerate**. A recovery code isn't accepted here.
4. Save the 10 new codes as when you turned it on.

Your old recovery codes stop working straight away, including the ones you haven't used.

## Turn off two-factor authentication

1. Go to **Settings**, **Account**.
2. In the **Two-factor authentication** card, click **Turn off**.
3. Enter your password, and either the current code from your app or one of your recovery codes.
4. Click **Turn off two-factor**.

Signing in then needs only your email and password. The entry in your authenticator app no longer works; you can delete it. If you turn two-factor authentication on again, you get a new QR code and new recovery codes.

## Google sign-in

Two-factor authentication in intoCHAT applies to signing in with your email and password. **Signing in with Google never asks for an intoCHAT code**: it relies on your Google account's own security. To protect it, turn on 2-Step Verification in your Google account.

- **You only sign in with Google.** Your intoCHAT account has no password, so the **Two-factor authentication** card explains this instead of offering **Turn on**. To use two-factor authentication, first set a password: sign out, click **Forgot password?** on the sign-in page and follow the email. Google sign-in keeps working, without a code.
- **You use both Google and a password.** Two-factor authentication protects the password. Signing in with Google still works without a code.
- **You turned on two-factor authentication before ever signing in with Google.** Signing in with Google using the same email address is refused with "This account uses two-factor authentication, so Google sign-in can't be linked to it. Sign in with your email, password and code." intoCHAT doesn't link Google to the account automatically then, because that would add a way in without the code.

## Lost your authenticator app

- **You still have recovery codes.** Sign in with one: click **Use a recovery code** on the code step. Then, in **Settings**, **Account**, [turn off two-factor authentication](#turn-off-two-factor-authentication) with your password and another recovery code, and turn it on again with your new phone. The secret behind your old app's codes can't be shown again, so a new phone always needs a new setup.
- **You have neither the app nor a recovery code.** Email support@intochat.ai from the email address of your intoCHAT account. Once support has confirmed it's you, they can turn off two-factor authentication on your account. You then sign in with your email and password and can turn it on again.
- **Google is linked to your account as well.** Signing in with Google doesn't ask for a code, so you can still get into your account that way. Turning two-factor authentication off still needs a code or a recovery code, so without either, contact support as above.

Resetting your password with **Forgot password?** doesn't turn off two-factor authentication: you still need a code after the new password.

## Team members

On **Settings**, **Team**, the members list shows a **2FA** badge next to active members who have two-factor authentication turned on. An account can't require it from its members. See [Team members and roles](/en/docs/team).

A super admin viewing your account for support can't see, turn on or turn off your two-factor authentication.

## Limits

- Codes come only from an authenticator app (TOTP). No codes by text message or email, and no passkeys or security keys.
- It protects email-and-password sign-in only, not [Google sign-in](#google-sign-in) or [single sign-on](/en/docs/single-sign-on), where your identity provider handles multi-factor authentication.
- Turning it on doesn't sign you out elsewhere. Browsers already signed in stay signed in until you sign out there.
- No "remember this device": every sign-in with your password asks for a code.
- One authenticator per account. To move to a new phone, turn it off and on again, or add the same key to both apps while you set it up.
- An account can't require two-factor authentication from its team members.
