Skip to content
sandadocs

Two-step verification

Add a six-digit code from an authenticator app to your sign-in, keep recovery codes, and see how an owner can require it for everyone.

Two-step verification asks for a six-digit code from an authenticator app after your email link or your Google or Apple sign-in. Someone who gets into your inbox still cannot get into your workspace. It is off until you turn it on, and an owner can require it of everyone.

Any app that reads a QR code and makes time-based codes works, including Google Authenticator, Microsoft Authenticator and 1Password.

Turn it on

  1. Start the setup. Go to Settings · Security, find Two-step sign-in, press Set up, then Set up an authenticator app.
  2. Add sanda to your app. Scan the QR code. If you cannot scan, choose "enter a setup key" in your app and type the key shown, as a time-based code. A password manager can take the setup link instead.
  3. Enter the code. Type the six-digit code your app now shows for sanda and press Turn on two-step sign-in.
  4. Keep your recovery codes. sanda shows 10 recovery codes, once. Press Copy codes or Download as text, store them somewhere other than your phone, tick I have saved my recovery codes, and press Done.

Nothing switches on until the code in step 3 matches, so a setup you abandon halfway changes nothing. If the code does not match, check that the app is showing sanda and that your phone's clock is set automatically.

Signing in with it

After you use your email link or press Continue with Google or Continue with Apple, sanda shows "Enter the code from your app." Type the six digits and press Continue to sanda.

  • A code works once. Wait for the next one if you have just used it.
  • A code is accepted for up to thirty seconds either side of the moment it was made, so a phone whose clock is slightly out still works.
  • You have 10 minutes from the first step to finish, and five tries. After five wrong codes that sign-in is stopped and you start again from the beginning. sanda also limits how many codes one person can try in an hour, whichever sign-in they are on.

Recovery codes

If you lose your phone, press Lost your phone? Use a recovery code on the code page and enter one of your 10 codes. Each works once, in place of an app code. After you sign in this way sanda takes you to Settings · Security, where the Two-step sign-in row shows how many recovery codes you have left.

sanda keeps only a scrambled copy of each code and cannot show it to you again. When you are nearly out, the panel tells you. To get a fresh set of 10, turn two-step off and set it up again.

Change phones or turn it off

Turn it off first, then set it up on the new phone. Turn off asks for a current code from your app or one unused recovery code. A session left open on a shared computer is not enough. Codes tried here count toward the same hourly limit as codes tried at sign-in. After too many, sanda says "Too many codes tried. Wait an hour, then try again." While two-step is on, you cannot start a second setup, so nobody can swap your authenticator without a code.

  1. Turn it off. In Settings · Security, press Turn off on the Two-step sign-in row.
  2. Enter a code. Use your app's current code or an unused recovery code, then press Turn off two-step sign-in.
  3. Set it up again. Press Set up and follow the steps above with your new phone.

If you lose the phone and the recovery codes

You cannot reset it yourself, because a reset would let anyone with your inbox switch it off. Write to sanda support at hello@sanda-os.com.au. sanda will need to confirm it is really you before it restores your access.

Require it for the whole workspace

An owner can require two-step sign-in for every person in the workspace. Admins cannot.

  1. Turn it on for yourself first. The switch is not available until the owner has two-step on.
  2. Open the row. In Settings · Security, find Require two-step sign-in for everyone and press Require.

The row then reads required. Press Make optional to lift the rule.

What happens to people who have not set it up yet:

  • They can still sign in with their email link or Google or Apple. They are not locked out, because that is how they reach the setup.
  • The console then shows "Set up two-step sign-in." in place of every page, and refuses everything else until they finish. They can still send a support message and answer the privacy policy.
  • The same rule holds for the reports portal, for the MCP endpoint and for the screen where someone approves a connected app. Someone without two-step cannot use a side door around it.
  • Integration tokens and connected apps that already exist are machine credentials, so sanda does not ask them for a code.

If a person turns two-step off in a workspace that requires it, they are asked to set it up again straight away.

sanda records in your workspace's audit trail when two-step is turned on or off, when a recovery code is used, and when the requirement changes.

Something unclear or out of date? Tell us, and we will fix the page.