How do I set up two-factor authentication?

Protect your account with an authenticator-app code at sign-in, plus recovery codes for when you lose your phone.

You switch on two-factor authentication (2FA) from your account's Sign-in & security page — after that, signing in needs your password plus a 6-digit code from an authenticator app.

Any dashboard user with an email-and-password account can do this. Staff who sign in with a PIN on the portal don't use 2FA — it protects password sign-ins. Your email address must be verified first.

Signing in with 2FA on. After your password (or Google sign-in), you're asked for the 6-digit code. No phone to hand? Click Use a recovery code instead and enter one of your saved codes — remember each works only once.

Managing it later. On the same row you can Disable 2FA, and a Recovery codes row lets you Regenerate a fresh set (you'll confirm your sign-in; old codes stop working immediately). Regenerate as soon as you've used a few or suspect they've been seen.

Locked out completely? If you've lost both the app and your recovery codes, contact support from the sign-in screen's recovery prompt to regain access — nobody at your restaurant can bypass 2FA for you.

One heads-up: some actions elsewhere in ResoFlow ask you to re-confirm your identity; with 2FA on, those prompts include your authenticator code too.

Related: How do I see and end active sessions? · Can't sign in — password resets and account recovery