Two-Factor Authentication
Two-factor authentication (2FA) adds an extra security layer to your tagd-ai account. Even if someone learns your password, they can't access your account without the second factor.
How 2FA Works
With 2FA enabled:
- Enter your email and password
- You're prompted for a verification code
- Get the code from your authenticator app
- Enter the code to complete login
Setting Up 2FA
Requirements
- A smartphone with an authenticator app:
- Google Authenticator
- Authy
- Microsoft Authenticator
- 1Password
- Any TOTP-compatible app
Enable 2FA
- Go to Account → Security
- Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app
- Enter the verification code shown in the app
- Save your backup codes
- 2FA is now active
Step-by-Step with Google Authenticator
- Install Google Authenticator on your phone
- In tagd-ai, go to Account → Security
- Click Enable Two-Factor Authentication
- Open Google Authenticator
- Tap + → Scan QR code
- Point camera at the QR code in tagd-ai
- Authenticator shows a 6-digit code
- Enter this code in tagd-ai
- Click Verify and Enable
Backup Codes
What Are Backup Codes?
Single-use codes for when you can't use your authenticator:
- Phone lost or broken
- App deleted
- Can't access device
Saving Backup Codes
When you enable 2FA:
- tagd-ai displays 10 backup codes
- Download or print them immediately
- Store securely (not on your phone)
- Each code can only be used once
Using a Backup Code
- At 2FA prompt, click Use backup code
- Enter one of your backup codes
- Code is consumed (can't be reused)
- You're logged in
Regenerating Backup Codes
If you've used or lost codes:
- Go to Account → Security
- Click Regenerate Backup Codes
- Enter your 2FA code to confirm
- New codes are generated
- Old codes are invalidated
Logging In with 2FA
Normal Login
- Enter email and password
- Click Sign In
- 2FA prompt appears
- Open authenticator app
- Enter the 6-digit code
- Click Verify
Code Timing
- Codes refresh every 30 seconds
- Enter before the timer expires
- If it expires, wait for the next code
Remember This Device
Optionally skip 2FA on trusted devices:
- Check Remember this device for 30 days
- 2FA won't be required on this device
- Other devices still require 2FA
Disabling 2FA
To turn off two-factor authentication:
- Go to Account → Security
- Click Disable Two-Factor Authentication
- Enter your password
- Enter a 2FA code (or backup code)
- Confirm disabling
warning
Disabling 2FA reduces your account security. Only disable if necessary.
Changing 2FA Method
To switch authenticator apps:
- Disable 2FA (above)
- Re-enable 2FA
- Scan with new authenticator app
Troubleshooting
Code Not Working
-
Check time sync - Your phone's clock must be accurate
- Enable automatic time on your phone
- Try syncing time in authenticator settings
-
Wait for new code - Use a fresh code, not expired one
-
Check correct account - Ensure you're using tagd-ai's entry
Lost Phone
- Use a backup code to log in
- Go to Account → Security
- Disable 2FA
- Re-enable with new device
Authenticator App Deleted
- Use a backup code
- Disable and re-enable 2FA
- Set up with fresh QR code
No Backup Codes
If you can't access authenticator AND have no backup codes:
- Contact support@tagd-ai.com
- Verify your identity
- Support can disable 2FA after verification
- This may take 1-3 business days
Best Practices
Setup
- Use a reputable authenticator app
- Enable cloud backup in authenticator (Authy)
- Store backup codes securely offline
- Consider multiple 2FA methods
Maintenance
- Check backup codes periodically
- Update 2FA when changing phones
- Keep authenticator app updated
- Remove old devices from trusted list
Recovery
- Keep backup codes in safe place
- Don't store with your password
- Consider giving trusted person emergency access
- Test a backup code to ensure they work
2FA and Teams
Organization Policies
Organizations can:
- Require 2FA for all members
- Enforce 2FA for admin accounts
- Set policies for trusted devices
Admin Settings
Organization admins:
- Go to Organization → Security
- Toggle Require 2FA
- Set grace period for enabling
- Monitor compliance
Security Benefits
What 2FA Protects Against
- Password theft/leaks
- Phishing attacks
- Brute force attempts
- Shared password compromises
What 2FA Doesn't Protect
- If your device is stolen and unlocked
- Targeted attacks on your authenticator
- Social engineering on backup codes