Skip to main content
Two-factor authentication (2FA) adds a second verification step to the login process. After entering your email and password, you must provide a time-based one-time password (TOTP) from an authenticator app.

Compatible apps

  • Google Authenticator (iOS, Android)
  • Authy (iOS, Android, desktop)
  • 1Password (built-in TOTP)
  • Bitwarden (built-in TOTP)
OwnPay uses standard TOTP (RFC 6238). Any authenticator app that supports this standard will work.

Enable 2FA

1
Go to My Account (click your avatar in the top-right corner).
2
Click Enable 2FA in the Security section.
3
A QR code appears. Scan it with your authenticator app.
4
The app displays a 6-digit code. Enter it in the Verification Code field.
5
Save your backup codes. OwnPay generates a set of single-use recovery codes. Store them in a secure location.
6
Click Confirm. 2FA is now active on your account.
Backup codes are shown only once. If you lose your authenticator device and do not have backup codes, you will need the super-admin to manually disable 2FA on your account.

Using 2FA at login

After entering your email and password, a second screen appears asking for your 6-digit verification code. Open your authenticator app and enter the current code. Codes rotate every 30 seconds.

Lost device recovery

If you lose access to your authenticator app:
  1. On the 2FA login screen, click Use backup code
  2. Enter one of your saved backup codes
  3. Each backup code can only be used once
  4. After logging in, disable 2FA and re-enable it with a new authenticator

2FA enforcement per role

Super-admins can enforce 2FA for specific roles. When enforced, staff in those roles cannot disable 2FA and must set it up before accessing the dashboard. Configure this in Settings > Security > Enforce 2FA for roles.
Last modified on August 25, 2026