Cobber Help

Two-factor authentication

An extra code at login, so a stolen password isn't enough.

Admin & data

Quick answers

6 questions · click to open
How do I turn on two-factor authentication?

Open your own user under Users & Permissions, then Manage two-factor authentication. Scan the QR code with an authenticator app and type in the 6-digit code it shows.

Which authenticator apps work?

Anything that scans a QR code for login codes. The setup screen mentions Google Authenticator, Authy and 1Password.

Do I have to turn it on?

No. It's optional. Still worth doing on accounts that can send campaigns or export people — those are the ones that hurt if a password leaks.

What happens at login after I enable it?

After your password, Cobber asks for the 6-digit code from your authenticator app. You have five minutes to enter it.

Are there backup codes if I lose my phone?

No, and another admin can't reset it for you. Add the same account to a second app you control while you still have access.

How do I turn 2FA off?

On the Two-Factor Authentication page, enter your password and choose Disable 2FA. You have to already be logged in.

A password on its own is a weak lock for a dashboard that holds members, donations and the send button. Two-factor authentication adds a 6-digit code from an authenticator app after you sign in — so someone who has the password still can’t get in without the phone or password manager that holds the app.

Turn it on

You can only do this for yourself. Another admin’s user record won’t show the controls.

  1. Open your own user

    Under Users & Permissions, open your own record — it's the one with the Your Account badge. The Two-Factor Authentication card sits further down that page.

  2. Scan the QR code

    Manage two-factor authentication, then Set up two-factor authentication. Scan the QR code with Google Authenticator, Authy, 1Password, or whatever you already use. Can't scan? Expand the manual key and type it into the app instead. The entry is labelled Cobber plus your organisation name, with your email as the account.

  3. Enter the code to switch it on

    Type the 6-digit code from the app and choose Verify and enable. If the code is rejected, wait for the next one — phone clocks that are set by hand are the usual culprit.

Signing in afterwards

Email and password as usual, then the 6-digit code. Every login asks for a fresh one. If you wander off for more than five minutes on that screen, you’ll be sent back to log in again.

Turning it off

Same page: enter your password and choose Disable 2FA. You have to already be in. Another admin can’t do it for you, which is the point.

If you lose the phone

There are no backup codes. If the only copy of the authenticator is on a device you no longer have, a password login won’t complete.

Add the same QR code — or the manual key — to a second app you control while you’re setting it up. A password manager counts. Doing that after the phone is gone doesn’t.

Fault finding
SymptomCause and fix
Invalid code when enabling The phone's clock is out. Set it automatically, then wait for the next code.
Sent back to login on the code screen More than five minutes after the password. Log in again and enter the code straight away.
No two-factor card on the user You're looking at someone else's record. Open your own — the one with the Your Account badge.
Can't disable 2FA Wrong password. A mismatch leaves it on.