Two-Factor Authentication (2FA)
Two-factor authentication (2FA) adds a second layer of security to your eventOne account. After entering your password, you'll be asked to verify with a second factor before access is granted.
Enrolling in 2FA
Go to User Settings (click your avatar in the top-right navbar → User Settings). The Two-Factor Authentication card appears at the top of the page.
Click + Add a 2FA Method to open the method picker and choose from three options:
| Method | Best for |
| Authenticator App | Best security; works offline; requires a TOTP app (Google Authenticator, Authy, 1Password, etc.) |
| Passkey | Passwordless hardware key or device biometrics (Face ID, Touch ID, Windows Hello) |
| SMS | Convenient fallback using a mobile phone number (not recommended) |
Authenticator App (TOTP)
- Click + Add a 2FA Method → select Authenticator App.
- Open your TOTP app and scan the QR code shown, or manually enter the secret key.
- Enter the 6-digit code displayed in your app and click Verify.
- Save your recovery codes — they are shown only once.
Passkey
Passkeys use your device's built-in authenticator (Face ID, Touch ID, Windows Hello, or a hardware security key). Passkeys are phishing-resistant and do not require a code.
- Click + Add a 2FA Method → select Passkey.
- Optionally enter a label (e.g. "MacBook Touch ID").
- Click Register Passkey and follow your browser's prompt to create the credential.
- Save your recovery codes — they are shown only once.
> Note: Passkeys are tied to the device and browser where they were created. Register a passkey on each device you use, or keep a backup method (TOTP or SMS) enrolled.
SMS
- Click + Add a 2FA Method → select SMS.
- Enter your mobile phone number (including country code, e.g.
+1 555 000 0000). - Click Send Code — a 6-digit code will be sent to that number.
- Enter the code and click Verify.
- Save your recovery codes — they are shown only once.
Signing In with 2FA
After you enter your email and password on the login page, you'll be redirected to the 2FA challenge screen. The challenge screen shows your default method automatically.
Authenticator App: Enter the current 6-digit code from your app and click Verify.
Passkey: Click Use Passkey and follow your browser's prompt.
SMS: A code is sent to your registered phone number. Enter it and click Verify.
Switching methods: If you have multiple methods enrolled, a Use a different method link appears below the primary challenge. Click it to choose another enrolled method.
Using a recovery code: Below the primary challenge, click Use a recovery code and enter one of your saved codes. Each code can only be used once.
Managing Your 2FA Methods
Your enrolled methods are listed in the Two-Factor Authentication card on the User Settings page (/account ).
Setting a Default Method
The default method is the one shown first on the login challenge screen. To change it:
- Find the method you want to set as default in the Enrolled Methods list.
- Click Set as default.
The Default badge moves to that method immediately.
Removing a Method
- Find the method in the Enrolled Methods list.
- Click Remove.
- Confirm the removal.
> Warning: If you remove all enrolled methods, 2FA is disabled for your account. Removing your last method also invalidates your recovery codes.
Recovery Codes
Recovery codes let you regain access to your account if you lose your 2FA device. Each code can only be used once.
When are recovery codes generated?
Recovery codes are generated when you enroll your first 2FA method. You can regenerate them at any time from the User Settings page.
Saving your recovery codes
A warning banner is displayed immediately after enrollment — this is the only time the codes are shown in full. Copy them to a password manager, a printed sheet kept in a secure place, or another safe location.
Regenerating recovery codes
- Go to User Settings → Two-Factor Authentication.
- In the Recovery Codes section, click Regenerate Recovery Codes.
- Save the new set of codes. The old codes are immediately invalidated.
Low-code warning
A warning banner appears on your User Settings page when you have fewer than 3 unused recovery codes (including when you have 0). Regenerate your codes as soon as you see this warning.
Monitoring Your Organization's 2FA Status
Organization owners and admins can see each admin's 2FA enrollment status from the Admins page:
- Navigate to your organization → Settings → Admins.
- Each admin row shows a 2FA Enabled (green) or 2FA Disabled (grey) badge.
This gives you visibility into which admins have secured their accounts with 2FA. You cannot enable or disable 2FA on behalf of another admin — each admin must enroll from their own User Settings page.
FAQ
Q: Is 2FA required to use eventOne?
Not currently — 2FA is optional but strongly recommended for all administrators. If you manage sensitive event data or financial information, enabling 2FA is best practice.
Q: What if I lose my phone and can't receive SMS codes?
Use a one-time recovery code to sign in. Once signed in, go to User Settings → Two-Factor Authentication, remove the SMS method, and add a new one with your updated phone number.
Q: What if I lose all my recovery codes and my 2FA device?
Contact your organization owner or eventOne support to regain access. Support staff can verify your identity and temporarily disable 2FA on your account.
Q: Can I enroll more than one of the same method type?
Yes — for example, you can register multiple passkeys (one per device) or multiple TOTP apps. Each appears as a separate entry in the Enrolled Methods list.
Q: Why does the passkey not work on a different device?
Passkeys are bound to the device and authenticator where they were registered. To use a passkey on another device, register a new passkey while signed in on that device.
Q: I enrolled TOTP but the code is rejected. What's wrong?
TOTP codes are time-based and valid for 30 seconds. Make sure your device's clock is accurate (enable automatic time sync). If your clock drifts significantly, codes will be rejected.