Two-step verification

Turn on two-step verification with an authenticator app, and keep your recovery codes safe.

Everyone2 min read

Two-step verification asks, after your password or email code, for a 6-digit code generated by an authenticator app (Microsoft Authenticator, Google Authenticator, 1Password, Bitwarden…). The code changes every 30 seconds.

It is mandatory for the Owner, Admin, Editor and Analyst roles: without it, the pages of these roles ask you to turn it on first. It is optional for Members.

Turn it on

  1. Go to Account → Security → Two-step verification.
  2. Scan the QR code with your app, or type the key shown under it.
  3. Enter the code displayed by the app to confirm.
  4. Save your 10 recovery codes somewhere safe (password manager, printed copy). They are shown only once.

The session you used is immediately considered verified.

Sign in with it

After your password, email code, Google or Microsoft sign-in, enter the current code from your app. You have 5 minutes and 5 attempts; then start again.

Lost your phone? Use one of your recovery codes instead. Each one works only once. When you run low, generate new ones from Account → Security (the old ones stop working).

Turn it off

Confirm it's you (password or emailed code), then turn it off. All your sessions lose their verified status. If one of your organizations requires it, you will be asked to turn it on again.

When is it required?

It is optional, but recommended for any account that manages games or reads results. It becomes mandatory:

  • to manage the security of an organization (security settings, SSO, API keys) and to expose player data (named reports, xAPI connector);
  • in an organization that requires it from your role or from every member, after a 7-day delay announced by a banner and by email (see Security and reporting).

The site also suggests it after your first deployment or your first invitation. "Later" puts the reminder off for 14 days; "Don't show again" hides it for good. Your choice is kept with your account. A reminder required by your organization stays until two-step verification is on.

See also Security and sign-in.

Edit this page on GitHub (opens in a new tab)