What is 2FA
Two-factor authentication (2FA) is an additional layer of account protection. When signing in, after entering your password you'll be asked to enter a one-time 6-digit code from the authenticator app on your phone.
tikento uses the TOTP (RFC 6238) standard — the same one used in Google Authenticator, Yandex Key, Authy, and most enterprise authenticators.
Who needs 2FA
2FA is mandatory for users with the following roles:
- Owner of the organization
- Admin of the organization
On their first sign-in with these roles, tikento will prompt them to set up 2FA before they can continue. Without 2FA configured, access to administrative functions will be restricted.
Setting up 2FA
Step 1. Install an authenticator
Any TOTP app will work:
- Google Authenticator (Android, iOS)
- Yandex Key (Android, iOS) — recommended for Russian-speaking users
- Authy (Android, iOS, Desktop) — supports cloud backup
- Microsoft Authenticator
- Any other app that supports TOTP RFC 6238
Step 2. Open the settings
In tikento: Profile settings > Security > Two-factor authentication > "Enable".
Step 3. Scan the QR code
In the authenticator app:
- Tap "+" or "Add account".
- Select "Scan QR code".
- Point the camera at the QR code on the tikento screen.
If scanning is unavailable, enter the secret key manually (click "Enter key manually" below the QR code).
Step 4. Enter the confirmation code
The authenticator app will generate a 6-digit code. Enter it in tikento and click "Confirm". The code refreshes every 30 seconds — enter it before it changes.
Step 5. Save recovery codes
After a successful link, tikento will display 8 recovery codes. Each code is single-use. Use them if you lose access to your phone.
Store the codes:
- In a password manager
- In an encrypted file
- On paper in a secure location
Signing in with 2FA
After setup, every sign-in requires:
- Enter your email and password.
- A field for the 6-digit code will appear.
- Open the authenticator app and enter the current code.
- Click "Confirm".
Disabling 2FA
For Owner and Admin roles, 2FA cannot be disabled. For other roles: go to Settings > Security > "Disable 2FA", then enter your current TOTP code to confirm.
What to do if you lose your phone
- On the sign-in page, click "Use recovery code".
- Enter one of your saved recovery codes.
- After signing in, immediately re-link 2FA to a new device.
If you don't have recovery codes either, contact tikento support with proof of identity.