Skip to content

Two-step verification and recovery codes

Turning on a second step, where to keep the ten recovery codes, exactly what happens when you spend one, and the day-long wait that follows.

Updated 11 September 20264 minApplies to: Back office, Help centre

It is your account, not the business's

Login & security is a personal page, and every role can open it — a waiter's account is theirs to protect as much as an owner's. Business settings live elsewhere.

The page holds five things: how you sign in, two-step verification, passkeys, where you are signed in, and what has happened on your account recently.

Turning on the second step

Use an authenticator app. Scan the square code with it, or type the key it shows you if the camera will not cooperate, then type back the six digits the app produces. That is the whole enrolment.

If your phone number is verified on the account and your deployment has a message channel configured, your phone can be a second factor as well. When no channel is configured the option is simply not offered — the product does not show a button it cannot honour.

Passkeys are separate, still in beta, and appear only where they have been switched on and your browser supports them.

The ten recovery codes

At the end of enrolment you are shown ten codes. They are shown once and never again. Each is ten characters, printed with a dash in the middle, and the alphabet deliberately leaves out the characters people confuse — no zero against O, no one against I or L — so a code read off a printout at a counter can be typed correctly.

Put them somewhere that is not the till and not the phone with the authenticator on it. A printout in the safe is a better answer than a screenshot in a chat, and the reason is in the next section.

The security page tells you how many are still unused, and you can generate a fresh batch at any time. Doing so stops the old batch working, so re-print immediately.

Signing in from then on

After your password you land on the second-step screen. It offers each factor it can actually challenge, and a link to use a recovery code instead.

This applies on the till too. A till is a money surface and is not exempt. Once that session is verified it stays verified for the life of the session — shift changes are the staff PIN's job, so nobody types a six-digit code between customers.

What spending a recovery code actually does

This is the part worth reading before you need it. Redeeming one code:

  1. removes every second factor from your account, not just the one you lost,
  2. spends that code and cancels the other nine,
  3. signs out every other session you had, and
  4. emails you to say it happened.

So you are back in, with two-step verification switched off, no codes left, and every other device signed out. Set it up again straight away and take a new batch.

There is one more consequence, and it is deliberate: for a day after a recovery code is used, actions that move money are refused. A recovery code is the one credential that clears every factor at once, so if it were stolen — a photo of a printout, a screenshot — the thief would be inside immediately. The day's wait is what stops "inside the account" becoming "the week's takings, tonight", and the email gives you time to react. Ordinary trading is untouched; it is the money actions that wait.

When something asks you to verify again while you are already signed in

Some actions want proof that was given recently, not merely at some point today — turning a module on or off, removing sample data, and the money actions. A session verified at nine in the morning is still verified at six in the evening on a laptop anybody walked past, which is not what a second factor is for.

The window is short. Verify once and you can work through a run of them without re-typing anything.

An account with no second factor is never walled out of these — it gets a prompt to set one up and carries on.

If you have lost both

There is no self-serve way past a lost factor with no code. That is the point of a second factor.

Write to us from the Support screen with your business name and the email on the account. Recovery with our help is deliberately slow: it needs identity checks against what is already on your account, it is delayed with notice to every contact on file, and every step of it is recorded. Do not expect it inside an hour, and be suspicious of anyone who offers to do it faster.

While you are on that page

Two things are worth a look even when nothing is wrong.

Where you are signed in lists your sessions with the browser, the system and roughly where they were last seen. Signing one out takes effect on that device's very next request. There is a button to sign out everything except the device you are on.

Recent activity is an append-only list of what has happened on the account — sign-ins, failures, password and email changes, factors added or removed, sessions revoked. If something on it is not you, change the password, sign out the other sessions, and tell us.

Still stuck?

Beta