Two-Factor Authentication
Add an authenticator app to your sign-in, keep backup codes, and require 2FA for everyone on your account.
What two-factor authentication does
Two-factor authentication (2FA) adds a second step to signing in: a six-digit code from an authenticator app on your phone, such as 1Password, Google Authenticator, or Authy. Someone who learns your password, or gets into your Google or Apple account, still can't get into Thicket without that code.
It applies however you sign in. If you sign in with Google or Apple, Thicket asks for the code after Google or Apple signs you in.
Turning it on
- Open My settings from your avatar, then Security
- Under Two-factor authentication, click Enable
- If you sign in with a password, confirm it. If you sign in with Google or Apple, there's no password to confirm and setup starts right away
- Scan the QR code with your authenticator app (or type the setup key in by hand), then enter the six-digit code the app shows
- Save your backup codes somewhere safe
That's it. From now on, sign-in asks for a code. Leave Remember this device for 30 days checked on a device you use every day, or turn it off on a shared or public device.
Backup codes
Each backup code signs you in once if you don't have your authenticator app to hand. They're shown once at setup. If you lose them, go to Security and click Backup codes to get a fresh set; the old ones stop working the moment new ones exist.
Google and Apple sign-in
Accounts that sign in with Google or Apple don't have a Thicket password, and don't need one for 2FA. You can add one from Security if you'd also like to sign in with your email address and a password. Once you have a password, Thicket asks for it before changing your 2FA settings.
Requiring 2FA for everyone
Account owners can require two-factor authentication for the whole account under Admin → Security. Set up your own 2FA first; Thicket will not let an owner turn on the requirement before they are ready. When it's on, everyone except clients is walked through setup the next time they visit, and can't get into the account until they finish. That includes people who sign in with Google or Apple on the web or mobile app. People covered by the requirement cannot turn off their own 2FA until an account owner turns off the account-wide requirement.
Locked out?
If you've lost your authenticator app, use one of your backup codes to sign in, then set 2FA up again from Security.
If you're locked out entirely, an owner or admin on your account can reset your 2FA from your entry on the People page. The reset also revokes remembered devices. You'll sign in with your usual method without a code and can set it up again. If you're not sure who to ask, contact support from the email address on your account.