Two-factor authentication
Two-factor authentication (2FA) asks for a 6-digit code from an authenticator app when you sign in, as well as your password. It’s optional for every role, but we strongly recommend it, especially for Business Admins.
You’ll need an authenticator app such as Google Authenticator, Authy or 1Password.
Turn on two-factor authentication
- Go to Settings. In the Security card, find Two-Factor Authentication.
- Click Enable Two-Factor Authentication.
- Scan the QR code with your authenticator app. If you can’t scan it, type the key shown under Can’t scan the QR code? Enter this key manually.
- Enter the 6-digit code from your app in Enter verification code.
- Click Enable MFA.
Your authenticator now appears under Active authenticators with an Active badge.
If you haven’t set up 2FA, Scrya may show a Secure Your Account prompt after you sign in. Click Enable Two-Factor Authentication to start, or Skip for now. Skipping hides the prompt in that browser only.
Signing in
After your email and password, you’ll see the Two-Factor Authentication screen. Enter the current code from your app in Verification code and click Verify. If the wrong account is shown, click Not you? Sign out.
How often you’re asked
Business Admins choose how often people with 2FA turned on must enter a code. The setting is MFA challenge frequency, under Settings > Organization > Edit:
- Every log-in (the default)
- Every 1 hour, 4 hours, 8 hours, 24 hours or 48 hours
With a timed option, you’re asked again once that time has passed, even if you’re still signed in. The setting also applies to your customers who use 2FA. If a customer belongs to several organisations, the strictest setting applies.
Change or remove your authenticator
You can have one authenticator at a time. To move to a new phone:
- In Two-Factor Authentication, click the bin icon next to your authenticator.
- Click Disable MFA to confirm.
- Click Enable Two-Factor Authentication and set up the new device.
Do this while you still have your old device.
If you lose your device
If you can’t get a code, contact support@scrya.io from the email address on your account. Your Business Admin can’t reset it for you.
Tip: During setup, you can save the same QR code or key in a second authenticator, such as a password manager, as a backup.
Troubleshooting
- “That code isn’t correct”. Make sure your phone sets its time automatically, then use a fresh code. Codes change every 30 seconds.
- “Two-factor authentication is already on”. Remove your existing authenticator before you set up a new one.
- Other errors. Quote the ERR reference to support. See Error references.
