Turn on two-factor authentication

Authenticator app or SMS-based 2FA, per user and enforced workspace-wide.

4 min read Updated 2026-04-24

Two-factor adds a second step to every login after password. We strongly recommend an authenticator app (Authy, 1Password, Google Authenticator, Microsoft Authenticator) over SMS — SMS 2FA can be defeated by SIM swap attacks.

  1. 1
    Open Profile → Security
    Click "Enable two-factor authentication."
  2. 2
    Choose a method
    Authenticator app (recommended) or SMS.
  3. 3
    Scan the QR code
    Your authenticator app adds an Open Doors entry and starts generating 6-digit codes.
  4. 4
    Enter a code to confirm
    You can only enable 2FA once a valid code is entered.
  5. 5
    Save backup codes
    Store the 10 backup codes in a password manager. Each is single-use, for when you lose your device.

Enforce workspace-wide

Admins can require 2FA for every user. Settings → Security → "Require 2FA for all users." Users without 2FA enabled are prompted on next login.