Docs · Accounts & teams · Two-factor authentication

Two-factor authentication

Two-factor authentication (2FA) adds a one-time email code to your sign-in, on top of your password or magic link. It's optional and off by default — turn it on for your own account in Account settings, or ask an org admin to require it for every member.

What it is

With 2FA on, signing in takes two steps: your usual password (or magic-link click), then a 6-digit code emailed to your address. The code expires after 10 minutes and can only be used once. This protects your account even if your password is ever compromised elsewhere, since a stolen password alone isn't enough to sign in.

GTFS·X sends codes by email, and by text message (SMS) when text-message verification is enabled on your account — see Text message codes below.

Enabling email 2FA

  1. Go to Account settings and find the Two-factor authentication section.
  2. Click Enable two-factor authentication. GTFS·X emails a 6-digit code to your account's email address.
  3. Enter the code and confirm. Two-factor authentication is now on for your account.

From then on, every sign-in — password or magic link's follow-up step — asks for a fresh code.

Signing in with a code

Once 2FA is on, entering your password (or completing a Google sign-in) takes you to a code-entry screen instead of straight into the editor. GTFS·X sends a new 6-digit code each time — by email or text message, matching the method you chose — and you enter it to finish signing in. If you don't see it, use the Resend code link (available once the cooldown between sends expires) — codes can be resent a limited number of times per sign-in attempt. If a code expires or you run out of attempts, just sign in again to get a fresh one.

If you sign in with a magic link and use email 2FA, you won't be asked for a separate code — clicking the link already proves you control your email address, the same factor an email code proves. If you use text-message 2FA, a magic link still prompts for a texted code, since your phone is a separate factor from your email.

Requiring 2FA for your organization

Organization owners and admins can require two-factor authentication for every member, regardless of each member's individual setting. Open Organization settingsSecurity and check Require two-factor authentication for all members.

Members who haven't enabled 2FA on their own account are still covered: when the org requires it, they're emailed a verification code at each sign-in automatically, using their account email. Members can't turn 2FA off for their own account while their organization requires it.

Text message codes

When text-message verification is enabled on your account, you can receive codes by SMS instead of email. In Account settingsTwo-factor authentication, choose Text message, enter your phone number in international format (starting with + and your country code), and confirm the code we text you. Standard message and data rates may apply, and you can reply STOP to opt out at any time. Once your number is verified, turn on text-message codes to make SMS your second factor.

Before we text you, you check a consent box agreeing to receive SMS verification codes and account or security alerts. See the full SMS program terms for message frequency, costs, and how to get help (HELP) or opt out (STOP).

Text-message codes are an alternative to email codes, not a replacement — email 2FA keeps working exactly as described above, and you can switch back to it whenever you like. If the Text message option still shows as coming soon, it isn't enabled on your account yet; use email codes in the meantime.

Turning it off

Open Account settingsTwo-factor authentication and click Disable. GTFS·X emails a confirmation code first, the same as enabling — enter it to turn 2FA off. This option isn't available while your organization requires 2FA; ask an admin to change the org-wide setting instead.

See also