Skip to main content
UTMKit signs you in with a link sent to your mailbox, or a password — so whoever controls the mailbox is you. Two-factor authentication adds a step that lives on your phone instead: after the link or the password, the sign-in asks for the six-digit code from an authenticator app before the session opens.

Turning it on

Open account settings and find Two-factor authentication. Because this changes how you sign in, the page asks you to have signed in recently; if it has been a while, sign in again first.
1

Scan the code

Press Turn on two-factor. Scan the QR code with any authenticator app, or type the secret shown beside it into the app by hand.
2

Confirm with a code

Type the six-digit code the app shows. Nothing is active until a correct code confirms it, so an abandoned setup leaves your sign-in unchanged.
3

Keep your recovery codes

You are then shown a set of single-use recovery codes, once. Copy them or download them as a text file and store them somewhere safe — a password manager, a printed page in a drawer. They are never shown again.
From now on every sign-in has two steps; the second asks for the six-digit code or a recovery code. Too many wrong codes in a row pause further attempts for a while, and the page says when to try again. A half-finished sign-in expires, and you start over.

Recovery codes

A recovery code opens the session when your phone is not at hand. Each one works exactly once, and after using one you are told how many remain. The settings page shows the count as well, and warns when none are left. Regenerate recovery codes issues a fresh set and kills the old ones; it asks for a current code from your app first.
If you lose both the phone and the codes there is no self-service way back in. An owner or administrator of a workspace you belong to can reset your second factor from its Members page (see below); nobody can reset their own.

What requires it

  • A workspace that requires it. An owner can switch on Require two-factor authentication on the workspace’s Members page. From then on, anyone in that workspace who has no second factor is sent to set one up before any page of that workspace opens; their other workspaces are unaffected, and new invitations say the requirement up front. Turning it off releases everyone; people who set it up keep it.
  • Minting an API token in such a workspace. A token is a credential that skips the sign-in, so someone without a second factor cannot create one there; the refusal names the workspace. See Authentication.
  • Single sign-on counts. A session opened through the organization’s identity provider has passed that provider’s own multi-factor policy, so it satisfies the requirement. See Single sign-on.

Turning it off

In account settings, under the same section, Turn off two-factor asks for a current code from your app and, again, for a recent sign-in. Afterwards signing in is one step and your recovery codes stop working.

Resetting someone else’s

On Members, an owner or administrator sees Reset 2FA on the row of anyone at their level or below who has a second factor. Pressing it turns that person’s second factor off, invalidates their recovery codes, and emails them so that nobody’s account is weakened in silence. The button never appears on your own row.