Article

Setting up two-factor authentication

Choose between email codes and an authenticator app for two-factor authentication, and keep your recovery codes safe.

Two-factor authentication adds a second check when you sign in with your password, so someone who learns your password still cannot get into your account. Every Structurell account uses it. You can receive codes by email, or use an authenticator app on your phone, which is more secure. This article explains both methods, how to switch between them and how recovery codes work.

How two-factor authentication works in Structurell

  • Two-factor authentication is always on and cannot be switched off.
  • If your account does not have a method yet, the first time you sign in with your password we email you a code and switch on email codes for you.
  • When you sign in with a passkey, you do not need a separate code. See Logging in and using passkeys.
  • On a device you have chosen to remember, you are not asked for a code for 30 days. See Keeping your account secure.

To see your current method, open the user menu in the top right, select Account, then the Sign-in methods tab. The Two-factor authentication panel shows either Email code ("Login codes are sent to your account email address.") or Authenticator app ("Login codes come from a compatible authenticator app.").

Email codes

With email codes, each time you sign in with your password we email you a 6-digit code.

  • Codes expire after 10 minutes.
  • Each code can only be used once.
  • You can ask for a new code once a minute using Resend code.

Email codes are convenient, but anyone who can read your email could use them. For stronger protection, switch to an authenticator app.

Switch to an authenticator app

You need an authenticator app on your phone or computer. Any app that supports standard time-based codes will work.

  1. In Account → Sign-in methods, go to the Two-factor authentication panel and select Switch to authenticator app.
  2. We email you a code to confirm it is you. Enter it in Email authentication code and select Verify email.
  3. Under Scan the QR code, open your authenticator app and scan the code on screen. If your app cannot scan it, select Show next to Manual entry key and type the key into your app, or use Copy.
  4. Enter the code your app now shows in Authenticator code and select Enable authenticator.
  5. Save the Recovery codes that appear, then select Done.

Finish these steps within 10 minutes of verifying your email. If you take longer, select Cancel and start again.

When the authenticator app is enabled, you see "Authenticator app enabled." For your security, any other places where you are signed in are signed out, and we email you to confirm the change.

Recovery codes

When you enable an authenticator app you get 8 recovery codes. Use them if you lose access to your authenticator app.

  • Store them somewhere safe, such as a password manager. They are shown only once: "Save these recovery codes before leaving this page. They will not be shown here again."
  • To use one, enter it in the Authentication code box when you sign in, instead of a code from your app.
  • Each recovery code works once. After you use it, it cannot be used again.

Recovery codes only apply to authenticator apps. If you use email codes, you do not have recovery codes.

The Portal does not have a separate button to create new recovery codes. If you have used most of yours, or lost them while you still have your authenticator app, switch to email codes and then back to an authenticator app (both sections in this article). Setting up the authenticator app again gives you a fresh set of 8 codes and replaces the old ones.

Switch back to email codes

  1. In the Two-factor authentication panel, select Switch to email code.
  2. Under Verify both methods, enter the code we email you in Email authentication code.
  3. Enter a current code from your authenticator app in Current authenticator code.
  4. Select Verify email.

You see "Email code authentication enabled." Asking for both codes stops someone who only has access to your email from weakening your account's security. Your old recovery codes stop working.

Troubleshooting

  • The authentication code is invalid. Make sure you enter the newest code. If you use an authenticator app, check the time on your device is set automatically, as codes depend on the correct time.
  • Too many authentication attempts. After several wrong codes you must wait before trying again. The message tells you how long to wait.
  • You did not get an email code. Check your spam or junk folder, then select Resend code after a minute has passed.
  • You have lost your authenticator app. You can still sign in with one of your recovery codes, or with a passkey if you have added one. Switching to email codes needs a current code from your authenticator app, so if you can no longer get codes from it, contact support to have your two-factor method reset.
  • You are changing phone. While you still have your old phone, select Switch to email code and complete the steps, then select Switch to authenticator app and scan the new QR code with the app on your new phone.
  • Resetting your password. If you use an authenticator app, you are asked for an authenticator code (or a recovery code) when you choose a new password. See Resetting your password.