> For the complete documentation index, see [llms.txt](https://docs.messageflow.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.messageflow.com/account/login-and-account-management/two-step-authentication-2fa.md).

# Two-step authentication (2FA)

Two-factor authentication (2FA) significantly increases your account's security. It works by requiring an additional, one-time code during login, on top of your standard password.

{% hint style="success" %}
**Good to know**: On every new MessageFlow account, the 2FA feature is active by default with SMS verification. This guide shows you how to manage its settings.
{% endhint %}

## **How to Configure 2FA?**

{% stepper %}
{% step %}

### Locate the Feature&#x20;

You can find the two-factor authentication settings in your panel by navigating to **Account** > **Settings** > **Security**. Look for the **Two-factor Authentication (2FA)** option and make sure it is enabled.

<figure><img src="https://1762163817-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDIGjHYIXYoHyJoOeeUgD%2Fuploads%2Fg4O5MJ9IVDnwEErlNtWE%2Fobraz.png?alt=media&amp;token=1cd1057e-3eb8-4488-9c0e-ad4d6fb268fa" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Choose Your Verification Channel&#x20;

The system allows for a flexible choice of channels for receiving your codes. The available channels are:

* **SMS**&#x20;
* **App** (e.g., Google Authenticator)
* **Hardware security** **key** (U2F standard)

You can select a single, primary verification channel or combine the App/Hardware key with SMS, which can then serve as an alternative method.

{% hint style="warning" %}
**Important**: The 2FA configuration you set here is shared across the entire account. This means that the chosen authentication methods will be mandatory for all of its users.
{% endhint %}
{% endstep %}

{% step %}

### Set Up Trusted Devices&#x20;

You can specify how long your device should be treated as "trusted," which eliminates the need to enter a code at every login.

* Single sign-on
* 1 Day
* 1 Week
* 30 Days
  {% endstep %}
  {% endstepper %}

Finally, save the configuration using the **Save** button. From that point on, during subsequent logins, the system will ask for the additional verification.

{% hint style="info" %}

### **Information for Account Administrators**

* Enabling verification via SMS will trigger a system check to see if all users have phone numbers assigned. You will be notified of any missing information with an additional message.
* With the SMS method active, providing a phone number is mandatory when adding new users to the account.
  {% endhint %}

<figure><img src="https://1762163817-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDIGjHYIXYoHyJoOeeUgD%2Fuploads%2FXOi8LwB3bRRUQN9w3oiU%2FZrzut%20ekranu%202025-09-11%20094136.png?alt=media&amp;token=4eaa30b7-221a-40d9-a174-79d34b3d738e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1762163817-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDIGjHYIXYoHyJoOeeUgD%2Fuploads%2FqW5RVI86i41CMstcT0OQ%2FZrzut%20ekranu%202025-09-11%20094050.png?alt=media&amp;token=ac3a90fa-2fff-4f80-945a-495b7b0f5e0f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1762163817-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDIGjHYIXYoHyJoOeeUgD%2Fuploads%2FG6ULObE7LhFrBBuw6ulA%2FZrzut%20ekranu%202025-09-11%20094108.png?alt=media&amp;token=420994f8-177f-410e-ae33-f4ab052f0150" alt=""><figcaption></figcaption></figure>
