Secure Your Account with Two-Factor
What you will end up with
Sign-in that needs your password and a six-digit code from your phone, so a leaked password alone cannot reach your customers' conversations.
Before you start
- An authenticator app — Google Authenticator, Microsoft Authenticator, 1Password, Authy, or any other TOTP app.
Steps
1. Enrol

- Open Profile from the bottom of the sidebar.
- Find the two-factor authentication section and start setup.
- Scan the QR code with your authenticator app.
- Type the six-digit code it shows to confirm.
Your account appears in the app as Orqestra:<workspace>:<your email>.
If you belong to more than one Orqestra organization, each is a separate entry with its own
code — enrolling in one does not enrol you in the others.
2. Save your recovery codes
Setup gives you a set of one-time recovery codes. Each works once.
Save these somewhere other than your phone.
They are the only way back into your account if you lose the device. A password manager or a printed copy in a safe place both work. A screenshot in your phone gallery does not — that is the thing you just lost.
3. Require it for the whole team (owners only)
Under the organization security settings you can require two-factor for every member. With it on, anyone without an enrolment is walked through setup on their next sign-in before they get access — nobody is locked out, but nobody skips it either.
How to check it worked
Sign out and back in. After your password you should be asked for a code. Enter one from the app.
When it does not work
- “Invalid code” every time. Almost always clock drift — TOTP codes depend on the time. Turn on automatic date and time on your phone.
- A code was rejected right after it worked. Each code is single use. Wait for the next one rather than retyping the same digits.
- Lost the phone and the recovery codes. Someone with user-management permission can clear your enrolment, after which you set it up again. Nobody — including them — can read your existing secret.