Skip to content

Two-factor authentication

With two-factor turned on, signing in takes two things instead of one: your password, and a six-digit code that changes every thirty seconds. Someone who learns your password still cannot get in without the device that generates the code.

It is off unless you turn it on.

Tovari’s second factor is an authenticator app — the kind that shows rotating six-digit codes, such as the one built into your phone or password manager. Setting it up means scanning a QR code once.

There is no text-message or email option. If you are looking for one, it is not that it is hidden — Tovari does not offer it.

Two-factor is for accounts that sign in with an email and password. If your account signs in with Google or Apple, Tovari does not offer it, and says so rather than letting you start.

The reason is worth stating plainly: Tovari has no backup codes. For an account that signs in through Google or Apple, a second factor would become a step you could not satisfy if you lost your authenticator — so that combination is refused rather than offered and regretted.

For the same reason, keep your authenticator app somewhere you will still have it — a password manager that syncs between your devices is safer than a single phone.

Scanning the QR code is not enough on its own. Two-factor becomes active only once you enter a code from your authenticator to prove the pairing worked. If you close the setup before that, nothing changes and your next sign-in is unaffected.

Open Settings, then Security. The two-factor card shows whether it is on and offers to set it up.

Setting up walks you through it: Tovari shows a QR code, you scan it with your authenticator app, then you type the six-digit code it shows you. Once that code is accepted, two-factor is on.

If the card tells you your account is not eligible, that is the Google or Apple case described above.

After your password is accepted, Tovari asks for the current six-digit code from your authenticator before finishing the sign-in.

Turning it off asks for both your password and a current code. That is deliberate: it is the same proof as signing in fresh, so that someone at an unlocked screen cannot quietly remove your second factor. If either is wrong, two-factor stays on.

Both setting up and turning off work in the phone-browser layout, in a sheet rather than a dialog. The QR code is awkward to scan from the same phone that would display it — if you can, set it up on a computer, or use an authenticator that lets you type the key by hand.