Skip to main content
security

Two-Factor Authentication (2FA)

Learn how to set up and use two-factor authentication to secure your Ottili ONE account.

Two-factor authentication adds an extra layer of security to your Ottili ONE account by requiring a second form of verification in addition to your password.

Why Use 2FA?

Even strong passwords can be compromised through data breaches, phishing, or malware. 2FA ensures that even if someone obtains your password, they cannot access your account without your second factor.

Types of 2FA Available

Ottili ONE supports two types of two-factor authentication:

1. Authenticator App (TOTP)* - Use an app like Google Authenticator, Authy, or 1Password to generate time-based codes

2. SMS Verification* - Receive codes via text message (where configured)

We recommend using an authenticator app for better security and reliability.

Setting Up Authenticator App (TOTP)

Step 1: Navigate to Security Settings

1. Sign in to your Ottili ONE account

2. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

3. Click "Set up" under "Authenticator app"

Step 2: Scan QR Code

1. Open your authenticator app (Google Authenticator, Authy, 1Password, etc.)

2. Choose "Add account" or "Scan QR code"

3. Scan the QR code displayed on screen

4. Your app will now show a 6-digit code that refreshes every 30 seconds

Can't scan the QR code?* Click "Show setup key" to display a manual entry key. Enter this key in your authenticator app instead.

Step 3: Verify Setup

1. Enter the current 6-digit code from your authenticator app

2. Click "Verify"

3. Save your recovery codes (see below)

Step 4: Save Recovery Codes

After enabling 2FA, you'll receive 8 recovery codes. Save these codes in a secure location* (password manager, printed copy in a safe, etc.).

Recovery codes allow you to access your account if you lose your authenticator device. Each code can only be used once.

Using 2FA at Login

When you sign in with 2FA enabled:

1. Enter your email and password

2. You'll be prompted for a two-factor code

3. Open your authenticator app and enter the current 6-digit code

4. Click "Sign in"

Lost your device?* Click "Use a recovery code" and enter one of your 8-character recovery codes instead.

Setting Up SMS Verification

SMS verification sends a code to your phone number via text message.

Step 1: Add Phone Number

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Under "SMS verification", click "Add phone number"

3. Enter your phone number in international format (e.g., +1-555-123-4567)

4. Click "Send code"

Step 2: Verify Phone Number

1. Check your phone for a text message from Ottili ONE

2. Enter the 6-digit code

3. Click "Verify"

Step 3: Enable SMS 2FA

1. Toggle "Use SMS for two-factor authentication"

2. Confirm your choice

Note:* SMS delivery may be delayed or unavailable in some regions. Authenticator apps are more reliable.

Managing Your 2FA Settings

Disable 2FA

To disable 2FA:

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Click "Disable" under the 2FA method you want to remove

3. Enter your password to confirm

4. Click "Disable"

Warning:* Disabling 2FA makes your account less secure. We recommend keeping 2FA enabled at all times.

Regenerate Recovery Codes

If you've used some recovery codes or lost them:

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Click "Generate new codes" under "Recovery codes"

3. Enter your password to confirm

4. Save the new codes securely

5. Old codes will be invalidated

Change Phone Number

To change your SMS verification number:

1. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

2. Click "Change number" under "SMS verification"

3. Enter your new phone number

4. Verify with a code sent to the new number

Troubleshooting

"Invalid code" Error

  • Check the time*: Authenticator codes are time-based. Ensure your device's clock is accurate.
  • Wait for refresh*: Codes change every 30 seconds. Wait for a new code if the current one doesn't work.
  • Try a recovery code*: If your authenticator is out of sync, use a recovery code and then re-setup 2FA.

Lost Authenticator Device

1. Use one of your 8 recovery codes to sign in

2. Go to [auth.ottili.one/mfa](https://auth.ottili.one/mfa)

3. Disable 2FA

4. Set up 2FA again with your new device

5. Generate new recovery codes

Not Receiving SMS Codes

  • Check signal*: Ensure your phone has cellular service
  • Wait 60 seconds*: SMS delivery can be delayed
  • Try again*: Click "Resend code" after 60 seconds
  • Use authenticator app*: SMS is less reliable; consider switching to an authenticator app

Locked Out of Account

If you've lost your authenticator device AND recovery codes:

1. Contact Ottili ONE support at support@ottili.one

2. Provide proof of identity (government ID, account details)

3. Support will verify your identity and help you regain access

Note:* Account recovery may take 3-5 business days for security reasons.

Best Practices

1. Use an authenticator app* instead of SMS for better security and reliability

2. Save recovery codes* in multiple secure locations (password manager, printed copy)

3. Keep your phone number up to date* if using SMS verification

4. Never share your 2FA codes* with anyone, including Ottili ONE staff

5. Re-setup 2FA* if you get a new phone or lose your authenticator device

6. Test your recovery codes* periodically to ensure they work

Security Considerations

  • Authenticator apps* are more secure than SMS because codes are generated locally and cannot be intercepted
  • SMS codes* can be intercepted through SIM swapping or SS7 attacks
  • Recovery codes* are your last line of defense; treat them like passwords
  • 2FA is not foolproof*: Sophisticated attackers may still compromise accounts through social engineering or malware

Frequently Asked Questions

Can I use multiple 2FA methods?

Yes, you can enable both authenticator app and SMS verification. You'll be able to choose which method to use at login.

What happens if I disable 2FA?

Your account will only require a password to sign in. This makes your account less secure. We recommend keeping 2FA enabled.

Do I need to enter a 2FA code every time I sign in?

No. If you're signing in from a trusted device and location, you may not be prompted for 2FA. However, you'll always need 2FA when signing in from a new device or location.

Can I use hardware security keys (YubiKey, etc.)?

Yes! Ottili ONE supports passkeys (WebAuthn), which work with hardware security keys. See [Passkeys](/docs/auth-passkeys) for more information.

Will 2FA work without internet?

Authenticator apps generate codes offline, so they work without internet. SMS verification requires cellular service.

Related Articles

  • [Passkeys](/docs/auth-passkeys) - Passwordless authentication with biometrics or security keys
  • [Recovery Codes](/docs/auth-recovery-codes) - Account recovery when you lose your 2FA device
  • [Active Sessions](/docs/auth-sessions) - Manage your login sessions across all devices
  • [Change Password](https://auth.ottili.one/change-password) - Update your account password

Need Help?

If you're having trouble with 2FA:

  • Check our [troubleshooting guide](#troubleshooting) above
  • Visit our [Help Center](https://help.ottili.one)
  • Contact support at support@ottili.one

Was this article helpful?