# Two-factor authentication

Two-factor authentication (2FA, also called MFA) adds a second step to signing in: after your password, or after Google or GitHub, EvoHub asks for a 6-digit code from an authenticator app on your phone. This page explains how to turn it on, how an organization can require it, and how to manage your signed-in devices.

## What you need

An authenticator app that supports time-based one-time passwords (TOTP), such as Google Authenticator, Authy, 1Password or Microsoft Authenticator. EvoHub does not send codes by SMS or email.

## Turn on two-factor authentication

:::steps
### Open Authentication
Open the avatar menu, choose **My Account**, then **Authentication**. Next to **Two-factor authentication**, select **Enable**.

### Show the QR code
The QR code is hidden so that nobody nearby can scan it. Select **Show QR code** when you are ready.

### Scan it
Scan the QR code with your authenticator app. If you cannot scan, type the key shown under **Can't scan? Enter this key manually** into the app instead. Then select **I've scanned it**.

### Confirm with a code
Enter the 6-digit code your app now shows and select **Enable MFA**.
:::

From now on, every sign-in to your account asks for a code.

> [!WARNING]
> EvoHub does not currently provide backup codes. Before you finish setup, keep a copy of the setup key somewhere safe, such as your password manager, or add the account to a second device. With the key you can restore the codes on a new phone.

## Sign in with a code

1. Sign in with your email and password, or with Google or GitHub.
2. On the **Two-factor authentication** screen, enter the current 6-digit code from your app.

The code screen is valid for 5 minutes. If it expires, start the sign-in again. Codes change every 30 seconds; if one is rejected, wait for the next one and check that your phone's clock is set automatically.

## Turn off two-factor authentication

Go to **My Account → Authentication**, select **Disable** next to **Two-factor authentication**, enter a current code from your authenticator app and select **Disable MFA**. A current code is required, so someone who only knows your password cannot turn it off.

If your organization requires two-factor authentication, you will be asked to set it up again the next time you sign in.

## If you lose your device

- If you saved the setup key, add it to the authenticator app on your new device and sign in as usual. Then turn 2FA off and on again to get a fresh key.
- Turning 2FA off also needs a code, so being signed in elsewhere does not help on its own; restore the key first.
- If you have neither the key nor a second device, contact support at info@evosync.io from the email address on your account.

## Require two-factor authentication for an organization

Administrators can make 2FA mandatory for everyone in an organization.

:::steps
### Open Login Policies
Go to **Organization → Login Policies**.

### Turn on Require MFA
Switch on **Require MFA** ("All members must enable two-factor authentication") and select **Save Policies**.
:::

What happens next:

- Members who already use 2FA notice nothing.
- A member without 2FA is taken through setup the next time they sign in, whether with a password or with Google or GitHub, and enters the organization only after it is done.
- Someone switching into the organization from another one is asked to set up 2FA first.

## Review your sessions

**My Account → Active Sessions** lists every device signed in to your account: browser and operating system, IP address, when it was last seen and when it signed in. Your current device is marked **Current session**, and the mobile app is marked **MOBILE**.

To sign a device out, select **Revoke** and confirm with **Revoke Session**. Do this for any device you do not recognize, and then change your password.

Sessions also end on their own after a period of inactivity, 7 days by default. Administrators can change this under **Organization → Login Policies → Session Timeout**.

## Related

- [Security at EvoHub](https://docs-dev.evohub.io/security.md)
- [Create your account](https://docs-dev.evohub.io/create-your-account.md)
- [Privacy and your data](https://docs-dev.evohub.io/privacy-and-data.md)
