Two-factor authentication
[object Object]
Two-factor authentication (2FA) adds a second layer of protection to your account. Once enabled, in addition to your password we'll ask you for a one-time code from an app or a tap of your security key when you sign in.
You enable the feature under Settings, Security.
Fibly supports two methods, which you can enable separately or at the same time. The second method then serves as a backup way to sign in.
Method 1: authenticator app (TOTP)
The most common form of 2FA. It generates six-digit codes in an app on your phone.
Apps that work
- Google Authenticator (iOS, Android)
- Microsoft Authenticator (iOS, Android)
- Authy (iOS, Android, desktop)
- 1Password or Bitwarden (if you use them as a password manager)
How to enable it
- Under Settings, Security, click Enable authenticator app.
- Open your chosen app on your phone and select "Add account".
- Scan the QR code shown in the Fibly dashboard (or enter the text code manually if your camera isn't working).
- Enter the six-digit code from the app in the dashboard to confirm everything works.
- Click Confirm.
From now on, every time you sign in, the dashboard will ask you for the current code from the app after you enter your password.
Method 2: security key (WebAuthn)
The strongest protection. It requires a physical USB key or a key built into your device (e.g. Touch ID on a MacBook, Windows Hello).
Keys that work
- YubiKey (5 NFC, 5C, 5C NFC, and newer)
- Google Titan
- Apple, Microsoft, and Google keys built into the device (Touch ID, Face ID, Windows Hello)
How to enable it
- Under Settings, Security, click Add security key.
- Follow your browser's instructions (insert the USB key and tap it, or use biometrics if the key is built in).
- Give the key a name, e.g. "Office YubiKey", so you can recognize it when you have several.
Backup codes
After you enable any 2FA method, Fibly will generate backup codes: ten one-time codes you can use instead of the app or key if you lose access to your device (e.g. you lose your phone).
- Download them and store them in a safe place (a password manager, an encrypted file, or a paper copy kept at home).
- Each code works only once.
- Once you've used most of the codes, generate new ones (the previous ones will be invalidated).
Don't skip this step. If you lose your phone and don't have backup codes or a security key, the only way to recover your account is to contact our support, which requires additional verification and takes time.
Disabling 2FA
Under Settings, Security you can disable each method separately. The operation requires your current password.
What's next
2FA is the last layer of account security. If you manage an entire team, encourage your colleagues to enable 2FA on their own accounts. In Team members you can see who has an active account.