Multi-factor authentication (MFA) adds a second check when you sign in, so someone who has your password still can’t get in. Teammate offers three ways to do it, and you can turn on more than one. Everything here is your choice — nothing is switched on for you — unless your organisation has made MFA a requirement (see the last section).
Choosing a method
| Method | What it is | Good to know |
|---|---|---|
| Passkey — recommended | Face ID, Touch ID, Windows Hello or a security key. Nothing to type. | The strongest option: it only works on the real Teammate site, so it can’t be phished. Set up from the web app on a computer. |
| Authenticator app | A 6-digit code from an app such as Google Authenticator, Microsoft Authenticator or Authy. | Works anywhere, including on your phone. Comes with backup codes for emergencies. |
| Email verification | A 6-digit code sent to your email address each time you sign in. | Only available when your login is an email address. Username-only logins should use a passkey or an authenticator app. |
All three are managed in one place: open the account menu at the bottom of the sidebar and choose Security. The page is called Multi-factor authentication, with one card per method.
Turning on a passkey (recommended)
- Sign in to Teammate on a computer using the web app, then go to Security from the account menu.
- On the Passkey card, click Add a passkey.
- Give it a name you’ll recognise later, such as Work MacBook or YubiKey, and click Create.
- Confirm with Face ID, Touch ID, Windows Hello or by touching your security key when your device asks.
- The passkey appears in the list. You can add up to ten — one for each device you sign in from — and remove any of them with the bin icon.
If you use iCloud Keychain, Google Password Manager or a password manager that syncs passkeys, one passkey may follow you to your other devices automatically. Otherwise add one per device.
Turning on an authenticator app
- Go to Security and click the Authenticator app card.
- Scan the QR code with your authenticator app, or type in the key shown below it.
- Enter the 6-digit code the app shows to confirm, then click Verify.
- Save your backup codes somewhere safe — download or copy them. Each code works once and gets you in if you lose your phone.
Turning on email verification
- Go to Security and click the Email verification card.
- We send a 6-digit code to the email address you sign in with. Enter it to confirm.
If the card says Unavailable, your login is a username rather than an email address, so we have nowhere to send the code. Use a passkey or an authenticator app instead — both work without an email address.
Signing in once MFA is on
After your password, a verification screen opens on the strongest method you have set up. If that’s a passkey, click Continue with passkey and confirm on your device. For the code methods, type the 6-digit code. If you’d rather use a different method, choose Use another method, Use a passkey instead or Use email instead — whichever the screen offers — and if you have an authenticator app you can also use a backup code from more options.
On the mobile app, sign in with your authenticator app or email code. Passkeys are set up and used on the web app for now; the mobile app shows the passkeys you have but can’t add or use them yet.
If you lose access
- Lost your phone or authenticator app? Sign in with one of your saved backup codes, or with any other method you turned on — a passkey on another device, or an email code. Then set the authenticator up again on your new phone.
- Lost a passkey device? Sign in another way, go to Security and remove that passkey from the list, then add one for the replacement device.
- No backup codes and no other method? Ask your organisation’s Teammate administrator to reset MFA on your account. You’ll set it up again on your next sign-in.
Turning on two methods — a passkey plus an authenticator app, say — means losing one never locks you out.
Was this helpful?
