Set Up Two-Factor Authentication (2FA)

Overview

Two-factor authentication (2FA) is turned on at the agency level, then each member enrols their own account. A Principal (any user with Principal permissions, including the agency owner) clicks Agency in the sidebar → opens the User Management card → turns on Enable 2-Factor Authentication on the Security card. Every member then enrols: Download Authy → scan the QR code or Add to authenticator → save your backup codes → Confirm, then log in again with a 6-digit code.

Turn on 2FA for your agency
1
Open User Management
From the left sidebar, click Agency, then open the User Management card. (You'll need Principal permissions to turn 2FA on — the agency owner always has them, and other senior staff may too.)
2
Find the Security card
On the User Management page, find the Security card, headed 2-Factor Authentication.
3
Turn on the toggle
Switch on Enable 2-Factor Authentication. A confirmation window, Enable 2FA for your agency?, opens.
4
Confirm
Click Yes, enable 2FA. A green You have enabled 2-Factor Authentication for your agency! banner confirms it's on.

Note: Only a Principal (any user with Principal permissions, which always includes the agency owner) can turn this on, and once it's on every member must enrol before they can keep using Keyhook. Let your team know before you enable it, and pick a quiet time so no one is locked out mid-task.

Download an authenticator app
1
Open the enrolment screen
Once 2FA is on for your agency, you're taken to the 2-Factor Authentication enrolment screen the next time you use Keyhook. Work through its numbered steps.
2
Install an authenticator app
On your phone, install an authenticator app. Keyhook recommends Authy — tap Download Authy to open its download page. Any standard authenticator app (for example Google Authenticator or 1Password) works too.
Add Keyhook to your authenticator app
1
Scan the QR code
Under Option 1, open your authenticator app and scan the QR code shown on the enrolment screen.
2
Or add it by link
If you can't scan, use Option 2 instead: click Add to authenticator to open the setup link directly in your app.
3
Check the code appears
Your authenticator app now shows a 6-digit code for Keyhook that changes every few seconds. That's the code you'll enter when you log in.
Save your backup codes
1
Copy or download the codes
The screen lists your backup codes. Click Copy to copy them, or Download to save them as a file (keyhook-backup-codes.txt).
2
Store them somewhere safe
Keep the codes somewhere secure and private — a password manager is ideal.

Note: Backup codes are shown only once and each code works only once. They're the way back into your account if you lose your authenticator app, so save them before you continue and don't share them with anyone.

Confirm and log back in
1
Confirm you're set up
When you've added Keyhook to your app and saved your backup codes, click Confirm at the bottom of the enrolment screen.
2
Log in again
Keyhook logs you out to finish enrolment. Log back in with your email and password, then enter the current 6-digit code from your authenticator app in the Authenticator code field.
If you lose access to your authenticator app
1
Try a backup code
At login, click Enter a backup code and enter one of the backup codes you saved instead of a 6-digit code. Remember each backup code only works once.
2
Re-enrol via support
If you've run out of backup codes or want to move to a new phone, go to My Account, find the 2-Factor Authentication card and click Manage 2-factor authentication to open the 2-Factor Authentication page. Use the Replace 2-factor authentication card there to reach Keyhook support by Live chat or Email and request re-enrolment.

Note: Re-enrolling invalidates the codes in your old authenticator app and every previously generated backup code, so only do it when you've actually lost access.

Frequently asked questions

Do I have to set up 2FA?

If your agency owner has turned on 2FA for the agency, yes — you'll be sent to the enrolment screen and can't keep using Keyhook until you've enrolled your account.

Which authenticator app should I use?

Keyhook recommends Authy, but any standard authenticator app that generates 6-digit time-based codes (such as Google Authenticator or 1Password) will work.

Who can turn 2FA on or off for the agency?

Any Principal — a user with Principal permissions, which always includes the agency owner — can enable or disable 2FA for everyone from the Security card on the User Management page.

What happens right after I click Confirm?

Keyhook logs you out to complete enrolment. Log back in with your email and password, then enter the current 6-digit code from your authenticator app.

I lost my phone — how do I get back in?

Log in with one of your saved backup codes (each works once). If they're used up or lost, open the 2-Factor Authentication page and use the Replace 2-factor authentication card to contact Keyhook support and re-enrol.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us