Two-factor authentication
How to set up TOTP-based two-factor authentication on your OrganizeOS account, store recovery codes, and get back in if you lose your phone.
On this page
Two-factor authentication (often shortened to 2FA or MFA) adds a second check on top of your password. After you enter the right password, OrganizeOS asks for a six-digit code from an authenticator app on your phone. Even if your password leaks, no one can sign in without the device that produces those codes.
Two-factor authentication is optional for most members and required for organization owners and admins. If you have an owner or admin role in any organization, the platform will prompt you to enroll on your next sign-in and you cannot dismiss that prompt. Some organizations also require two-factor authentication for their staff members, sometimes phasing it in with a grace period after you join before enforcement starts. If that applies to you, you'll see the same enrollment prompt.
Setting it up
Open Settings from your profile menu and click the Security tab. Under "Two-factor authentication," click Set up.
You'll see a QR code and a six-digit code field. Open an authenticator app on your phone (1Password, Authy, Bitwarden, Google Authenticator, Microsoft Authenticator, and similar all work) and scan the QR code. The app starts producing a fresh six-digit code every 30 seconds. Type the current code into OrganizeOS and click Verify.
That's it. From now on, every sign-in asks for both your password and a fresh code from the app.
Saving your recovery codes
Right after you enroll, OrganizeOS shows you a set of single-use recovery codes. These are your way back in if your authenticator is unavailable (lost phone, factory-reset device, app deleted).
Click Copy all and paste them into your password manager, or click Download CSV to save them as a file. Both are equivalent; pick whichever lives where you'll be able to find it in an emergency. Store them somewhere other than your phone, since the phone is the device you'd be locked out of.
Each code works exactly once. After you use one, it's burned.
What happens when you lose your authenticator
Sign in with your password as normal. On the second screen, instead of typing a six-digit code, click Use a recovery code and enter one of the codes you saved. You're in.
Using a recovery code does two things: it signs you in for this session, AND it removes your existing authenticator from your account. The next time you sign in, OrganizeOS will walk you through setting up a fresh authenticator (likely on a new phone). This is intentional: if your phone was stolen, leaving the old factor active would leave the door open.
Managing your authenticator
Regenerating your recovery codes
If you've used several codes or you think they may have been exposed, you can regenerate the whole set. On the Security tab, under "Recovery codes," click Regenerate. The old codes stop working immediately; the new set appears once and you save them the same way.
You can see how many codes you have remaining at any time on the Security tab.
Removing your authenticator
If you want to take 2FA off your account, click the trash icon next to your authenticator in the Security tab and confirm. Your recovery codes are also cleared. This is only available if your role doesn't require 2FA. For org owners and admins, the platform won't let you disable it; you'd need to step down from that role first.
Why this matters
Passwords leak. The 2024-2026 stretch alone saw billions of credentials exposed in breaches of other services people reuse passwords across, and labor-organizing accounts are subpoena-attractive and politically targeted in ways most apps aren't. Two-factor authentication is the single highest-leverage thing you can do for the security of your OrganizeOS account, and the recovery-code flow makes sure you can always get back in. Setting it up takes 60 seconds; getting locked out without it takes days.