How-to
Two-factor authentication and passkeys
Turn on an authenticator app with recovery codes, add Touch ID, Face ID or security-key passkeys, and regain access if you lose your device.
Emailit always asks for a second factor when you sign in with a password. By default that’s a code sent to your email. This page shows how to replace it with an authenticator app, how to add passkeys, and what to do if you lose a device.
Before you begin
- You’re signed in to the dashboard.
- For an authenticator app: an app such as 1Password, Google Authenticator, Microsoft Authenticator or Authy.
- For passkeys: a browser and device that support passkeys (WebAuthn), such as Touch ID, Face ID, Windows Hello or a hardware security key. The Add passkey button only appears in browsers that support them.
Turn on an authenticator app
-
Open your account. In the account menu at the bottom of the sidebar, select Account. Find Two-Factor Authentication, which shows Two-factor authentication is disabled.
-
Start setup. Select Enable. The Set up Two-Factor Authentication dialog shows a QR code and a Secret key.
-
Add Emailit to your app. Scan the QR code, or copy the Secret key into your app if you can’t scan.
-
Confirm. Enter the 6-digit code from your app under Verification Code and select Enable.
-
Save your recovery codes. Emailit shows 8 recovery codes once. Store them in a password manager or print them, then select Done.
From now on, sign-in asks for a code from your app instead of an emailed code. Emailit stops sending sign-in codes by email while the authenticator app is on.
Recovery codes
Each recovery code works once. At the sign-in prompt, select Use recovery code and enter one of them.
The dashboard shows your recovery codes only right after you enable two-factor authentication. To get a fresh set, turn two-factor authentication off and on again. That also creates a new secret, so remove the old Emailit entry from your authenticator app and scan the new QR code.
Turn off the authenticator app
Under Two-Factor Authentication, select Disable, enter your password and select Disable. Sign-in goes back to a 6-digit code emailed to you. Your secret and recovery codes are deleted.
Add a passkey
A passkey lets you sign in without a password or code. It’s tied to your device or security key, which makes it resistant to phishing.
-
Open Passkeys. On the Account page, find Passkeys and select Add passkey.
-
Name it. Enter a Device name you’ll recognize later, such as
MacBook ProorYubiKey 5C, and select Continue. -
Follow your browser’s prompt. Confirm with Touch ID, Face ID, your device PIN or by touching your security key.
The passkey appears in the list with when it was created and last used. You can add several, for example one per laptop plus a hardware key as a backup.
To sign in with it, select Sign in with a passkey on the sign-in page, or choose the passkey from your browser’s autofill in the email field.
Delete a passkey
Select the trash icon next to the passkey and confirm. It can no longer be used to sign in. This can’t be undone, but you can add the same device again.
Two-factor status of your teammates
The member list under WorkspaceSettingsMembers has a 2FA column. Enabled means the member signs in with an authenticator app, and Disabled means they use emailed codes. Pending invitations show Pending, and Unknown means the status couldn’t be loaded. Emailit can’t require two-factor authentication for a workspace, so ask your team to turn it on.
If you lose your device
-
Use a recovery code. On the authenticator prompt, select Use recovery code and enter one of your saved codes.
-
Use another method. If you added a passkey on another device or a security key, sign in with Sign in with a passkey instead.
-
Reset two-factor authentication. Once you’re in, disable two-factor authentication under Account, then enable it again with your new device. You get a new QR code and new recovery codes.
-
Contact support. If you have no recovery codes and no passkey, email support@emailit.com from your account address and explain what happened. Support needs to confirm you own the account before removing two-factor authentication.