Two-factor authentication
An extra code at login, so a stolen password isn't enough.
Quick answers
8 questions · click to openHow do I turn on two-factor authentication?
Open your own user under Users & Permissions, then Manage two-factor authentication. Scan the QR code with an authenticator app and type in the 6-digit code it shows.
Which authenticator apps work?
Anything that scans a QR code for login codes. The setup screen mentions Google Authenticator, Authy and 1Password.
Do I have to turn it on?
Only if your organisation requires it. Under Settings → Security, a national admin can turn on Require two-factor authentication. When that's on, every admin is sent to set-up before they can use the dashboard. Otherwise it's optional — still worth doing on accounts that can send campaigns or export people.
How do we require 2FA for every admin?
Under Settings → Security, tick Require two-factor authentication and save. Admins who haven't enrolled yet are asked to set it up on their next login, and nobody can turn their own 2FA off while the requirement is on.
What happens at login after I enable it?
After your password, Cobber asks for the 6-digit code from your authenticator app. You have five minutes to enter it.
Are there backup codes if I lose my phone?
No. While you still have access, add the same account to a second app you control. If you're locked out, another admin with user-management access can reset 2FA from your record under Users & Permissions.
How do I turn 2FA off?
On the Two-Factor Authentication page, enter your password and choose Disable 2FA — unless your organisation requires it, in which case that option is hidden. You have to already be logged in.
Can another admin reset my 2FA?
Yes. Under Users & Permissions, open your user record. If 2FA is enabled, they'll see Reset two-factor authentication. After a reset you must enrol again before signing in fully (and immediately if the organisation requires 2FA).
A password on its own is a weak lock for a dashboard that holds members, donations and the send button. Two-factor authentication adds a 6-digit code from an authenticator app after you sign in — so someone who has the password still can’t get in without the phone or password manager that holds the app.
Require it for everyone
National admins can make 2FA compulsory under Settings → Security. Tick Require two-factor authentication and save.
When that’s on:
- Admins who haven’t enrolled yet are sent to set-up before they can use the dashboard.
- Nobody can disable their own 2FA while the requirement stays on.
- Another admin can still reset someone’s 2FA from that person’s record under Users & Permissions if they lose their device.
Turn it on for yourself
You can only enrol yourself. Another admin’s user record won’t show the set-up controls — only status and, when needed, a reset.
-
Open your own user
Under Users & Permissions, open your own record — it's the one with the Your Account badge. The Two-Factor Authentication card sits further down that page.
-
Scan the QR code
Manage two-factor authentication, then Set up two-factor authentication. Scan the QR code with Google Authenticator, Authy, 1Password, or whatever you already use. Can't scan? Expand the manual key and type it into the app instead. The entry is labelled Cobber plus your organisation name, with your email as the account.
-
Enter the code to switch it on
Type the 6-digit code from the app and choose Verify and enable. If the code is rejected, wait for the next one — phone clocks that are set by hand are the usual culprit.
Turning it off
Same page: enter your password and choose Disable 2FA — unless your organisation requires two-factor authentication, in which case that option isn’t shown. You have to already be in.
If you lose the phone
There are no backup codes. If the only copy of the authenticator is on a device you no longer have, a password login won’t complete.
Add the same QR code — or the manual key — to a second app you control while you’re setting it up. A password manager counts. Doing that after the phone is gone doesn’t.
If you’re locked out, ask another admin with access to Users & Permissions to open your user record and choose Reset two-factor authentication. You’ll enrol a new authenticator on next login.
| Symptom | Cause and fix |
|---|---|
| Invalid code when enabling | The phone's clock is out. Set it automatically, then wait for the next code. |
| Sent back to login on the code screen | More than five minutes after the password. Log in again and enter the code straight away. |
| No two-factor card on the user | You're looking at someone else's record and they don't have 2FA on (and the organisation doesn't require it). Open your own — the one with the Your Account badge — to manage yours. |
| Can't disable 2FA | Wrong password, or your organisation requires it under Settings → Security. Ask another admin to reset it if you've lost the device. |
| Sent straight to 2FA set-up after login | Your organisation requires two-factor authentication and you haven't enrolled yet. Finish set-up to reach the dashboard. |