Protect your account with two factor authentication
Two factor authentication adds a second step to signing in. After your password is accepted, KolleK asks for a six digit code from an authenticator app on your phone. Even if someone learns your password, they cannot get in without that code.
This is the most effective security control KolleK offers, and it takes a few minutes to set up.
What you will need
An authenticator app on your phone, such as any app that supports time based one time codes. If you have ever scanned a QR code to protect another account, you already have one.
Turn it on
Go to your profile and open the security area, then choose to set up two factor authentication.
KolleK shows a QR code. Open your authenticator app, add a new account, and scan the code. The app starts showing a six digit code for KolleK that changes every 30 seconds.
::screenshot{label="Two factor setup screen with the QR code"}
Type the current six digit code from your app into the confirmation field and submit. This proves the app and KolleK are in sync before anything changes about how you sign in.
KolleK generates eight recovery codes. Copy them somewhere safe that is not your phone, such as a password manager or a printed page. Each code can sign you in once if you ever lose your authenticator.
::screenshot{label="The eight recovery codes shown after setup"}
If you lose your authenticator and have no recovery codes, you cannot complete the two factor step, and you may be locked out of your user. Save the codes before you close the page.
What changes when you sign in
From now on, signing in with your email and password takes one extra step. After your password is accepted, KolleK asks for the current code from your authenticator app. Enter it and you are in.
If you cannot reach your app, enter one of your recovery codes instead.
Signing in with a magic link does not ask for a two factor code. Access to your email inbox already acts as the second factor, so protect that inbox accordingly.
Turn it off
You can disable two factor authentication from the same security area. Doing so removes the code step from sign in and also deletes your recovery codes and the pairing with your authenticator app. If you turn it back on later, you will scan a new QR code and receive a fresh set of recovery codes.
Where to next
- Make sure your fallback works: Save and use your recovery codes.
- Understand the passwordless path and its trade off: Magic links explained.
- See every way to get into the app: Signing in.