Skip to content

Two-factor authentication

Two-factor authentication (2FA) makes your account harder to take over. Once turned on, signing in requires both your password and a 6-digit code generated by an authenticator app on your phone. PostRoll uses standard TOTP — the same protocol your bank and most other apps use — so any authenticator works: Authy, 1Password, Google Authenticator, Microsoft Authenticator, etc.

  1. Open Settings → Security. Click your avatar in the bottom of the app sidebar, choose Settings, then pick Security from the settings sidebar. (Cmd/Ctrl-K → “Security settings” jumps straight there, or visit /app/settings/security directly.)
  2. Click Add authenticator.
  3. Scan the QR code with your authenticator app, or copy the secret in below it if your app can’t scan.
  4. Enter the 6-digit code your authenticator shows you. PostRoll will verify the link is working before continuing.
  5. Save your recovery codes. PostRoll shows ten one-time codes that you can use to sign in if you ever lose access to your phone. We can’t show them again — copy them to your password manager or print them somewhere safe.
  6. Tick I’ve saved these somewhere safe, then click Done.

After you turn 2FA on, the sign-in flow has one extra step:

  1. Enter your email and password as usual.
  2. PostRoll shows the Two-factor verification screen. Open your authenticator app, find the PostRoll entry, and type in the current 6-digit code.
  3. You’re in.

Codes rotate every 30 seconds. If a code is rejected, wait for the next one and try again.

On the verification screen, click Use a recovery code instead and paste in any one of the codes you saved during enrolment. Each code works once — once you use one, it’s gone.

Using a recovery code automatically turns 2FA off on your account. After signing in, head back to Settings → Security and re-enrol. Doing this generates a fresh set of ten recovery codes; save them again.

If you run out of recovery codes AND no longer have your authenticator, contact support — we can clear the second factor from your account after verifying your identity another way.

There’s no built-in “remove authenticator” button today. To go back to password-only sign-in:

  1. Use a recovery code on the verification screen — this clears the factor automatically.
  2. Don’t re-enrol.