Secure Your Account with Two-Factor

By Orqestra · Published September 2, 2026

What you will end up with

Sign-in that needs your password and a six-digit code from your phone, so a leaked password alone cannot reach your customers' conversations.

Before you start

  • An authenticator app — Google Authenticator, Microsoft Authenticator, 1Password, Authy, or any other TOTP app.

Steps

1. Enrol

The Profile screen, where two-factor authentication is enrolled
Profile. Two-factor enrolment and recovery codes live here.
  1. Open Profile from the bottom of the sidebar.
  2. Find the two-factor authentication section and start setup.
  3. Scan the QR code with your authenticator app.
  4. Type the six-digit code it shows to confirm.

Your account appears in the app as Orqestra:<workspace>:<your email>. If you belong to more than one Orqestra organization, each is a separate entry with its own code — enrolling in one does not enrol you in the others.

2. Save your recovery codes

Setup gives you a set of one-time recovery codes. Each works once.

Save these somewhere other than your phone.
They are the only way back into your account if you lose the device. A password manager or a printed copy in a safe place both work. A screenshot in your phone gallery does not — that is the thing you just lost.

3. Require it for the whole team (owners only)

Under the organization security settings you can require two-factor for every member. With it on, anyone without an enrolment is walked through setup on their next sign-in before they get access — nobody is locked out, but nobody skips it either.

How to check it worked

Sign out and back in. After your password you should be asked for a code. Enter one from the app.

When it does not work

  • “Invalid code” every time. Almost always clock drift — TOTP codes depend on the time. Turn on automatic date and time on your phone.
  • A code was rejected right after it worked. Each code is single use. Wait for the next one rather than retyping the same digits.
  • Lost the phone and the recovery codes. Someone with user-management permission can clear your enrolment, after which you set it up again. Nobody — including them — can read your existing secret.