# Two-step verification

> Add a six-digit code from an authenticator app to your sign-in, keep recovery codes, and see how an owner can require it for everyone.

Two-step verification asks for a six-digit code from an authenticator app after your email link or your Google or Apple sign-in. Someone who gets into your inbox still cannot get into your workspace. It is off until you turn it on, and an owner can [require it of everyone](#require-it-for-the-whole-workspace).

Any app that reads a QR code and makes time-based codes works, including Google Authenticator, Microsoft Authenticator and 1Password.

## Turn it on

:::steps
1. **Start the setup.** Go to **Settings · Security**, find **Two-step sign-in**, press **Set up**, then **Set up an authenticator app**.
2. **Add sanda to your app.** Scan the QR code. If you cannot scan, choose "enter a setup key" in your app and type the key shown, as a time-based code. A password manager can take the setup link instead.
3. **Enter the code.** Type the six-digit code your app now shows for sanda and press **Turn on two-step sign-in**.
4. **Keep your recovery codes.** sanda shows 10 recovery codes, once. Press **Copy codes** or **Download as text**, store them somewhere other than your phone, tick **I have saved my recovery codes**, and press **Done**.
:::

Nothing switches on until the code in step 3 matches, so a setup you abandon halfway changes nothing. If the code does not match, check that the app is showing sanda and that your phone's clock is set automatically.

## Signing in with it

After you use your email link or press **Continue with Google** or **Continue with Apple**, sanda shows "Enter the code from your app." Type the six digits and press **Continue to sanda**.

- A code works once. Wait for the next one if you have just used it.
- A code is accepted for up to thirty seconds either side of the moment it was made, so a phone whose clock is slightly out still works.
- You have 10 minutes from the first step to finish, and five tries. After five wrong codes that sign-in is stopped and you start again from the beginning. sanda also limits how many codes one person can try in an hour, whichever sign-in they are on.

## Recovery codes

If you lose your phone, press **Lost your phone? Use a recovery code** on the code page and enter one of your 10 codes. Each works once, in place of an app code. After you sign in this way sanda takes you to **Settings · Security**, where the **Two-step sign-in** row shows how many recovery codes you have left.

sanda keeps only a scrambled copy of each code and cannot show it to you again. When you are nearly out, the panel tells you. To get a fresh set of 10, turn two-step off and set it up again.

## Change phones or turn it off

Turn it off first, then set it up on the new phone. **Turn off** asks for a current code from your app or one unused recovery code. A session left open on a shared computer is not enough. Codes tried here count toward the same hourly limit as codes tried at sign-in. After too many, sanda says "Too many codes tried. Wait an hour, then try again." While two-step is on, you cannot start a second setup, so nobody can swap your authenticator without a code.

:::steps
1. **Turn it off.** In **Settings · Security**, press **Turn off** on the **Two-step sign-in** row.
2. **Enter a code.** Use your app's current code or an unused recovery code, then press **Turn off two-step sign-in**.
3. **Set it up again.** Press **Set up** and follow the steps above with your new phone.
:::

## If you lose the phone and the recovery codes

You cannot reset it yourself, because a reset would let anyone with your inbox switch it off. Write to sanda support at hello@sanda-os.com.au. sanda will need to confirm it is really you before it restores your access.

## Require it for the whole workspace

An owner can require two-step sign-in for every person in the workspace. Admins cannot.

:::steps
1. **Turn it on for yourself first.** The switch is not available until the owner has two-step on.
2. **Open the row.** In **Settings · Security**, find **Require two-step sign-in for everyone** and press **Require**.
:::

The row then reads **required**. Press **Make optional** to lift the rule.

What happens to people who have not set it up yet:

- They can still sign in with their email link or Google or Apple. They are not locked out, because that is how they reach the setup.
- The console then shows "Set up two-step sign-in." in place of every page, and refuses everything else until they finish. They can still send a support message and answer the privacy policy.
- The same rule holds for the reports portal, for the MCP endpoint and for the screen where someone approves a connected app. Someone without two-step cannot use a side door around it.
- Integration tokens and connected apps that already exist are machine credentials, so sanda does not ask them for a code.

If a person turns two-step off in a workspace that requires it, they are asked to set it up again straight away.

sanda records in your workspace's audit trail when two-step is turned on or off, when a recovery code is used, and when the requirement changes.

:::links
- [Sign in](https://docs.sanda-os.com.au/workspace/sign-in): The email link and Google or Apple.
- [Members and roles](https://docs.sanda-os.com.au/workspace/members-and-roles): Who can require it.
- [Security](https://docs.sanda-os.com.au/workspace/security): How sanda protects sign-in.
:::
