Skip to main content

Two-Factor Authentication (2FA)

Overview

Two-factor authentication (2FA) protects your account: every time you log in, the system requests a one-time 6-digit code from the Google Authenticator app, which refreshes every 30 seconds.

A workspace administrator can make 2FA mandatory for all members.

ℹ️ Plan requirement. 2FA is available on the PRO plan only. If you downgrade to Free or Basic, the feature is automatically disabled at the end of the billing period.


Enable mandatory 2FA (for administrators)

Once enabled, any user who logs into Darlean without 2FA configured will be blocked on their next login and redirected to the setup screen.

  1. Open Workspace Settings → Security.
  2. Find the Two-factor authentication for all users setting.
  3. Toggle it on.

Disable mandatory 2FA (for administrators)

  1. Open Workspace Settings → Security.
  2. Toggle off Two-factor authentication for all users.

⚠️ After disabling, 2FA becomes optional. Login codes will not be requested — even from users who had 2FA previously enabled.


Set up 2FA (for users)

The setup screen appears when you log into Darlean if the administrator has made 2FA mandatory and you haven't configured it yet.

  1. Install the Google Authenticator app on your phone (App Store or Google Play).
  2. Add your account to Google Authenticator using one of these methods:
    • Method 1 — QR code: scan the QR code displayed on the setup screen.
    • Method 2 — manually: click Copy key and enter it in the app manually.
  3. Enter the 6-digit code from Google Authenticator and click Confirm.
  4. Save your backup code — copy or write it down. It is shown only once.

ℹ️ The backup code is needed to disable 2FA if you lose access to your phone. It cannot be used for regular login.

  1. Done — 2FA is now active and you will be taken to your workspace automatically.

Logging in with 2FA enabled

  1. Enter your login and password.
  2. Open Google Authenticator and enter the current 6-digit code.

ℹ️ The code is valid for 30 seconds. If the code doesn't work — wait for it to refresh and try again.


Recover access if you lose your phone

If you no longer have access to your phone with Google Authenticator:

  1. On the login screen, click No access? Enter backup code.
  2. Enter your saved backup code in the window that appears.
  3. After a successful entry, the system will redirect you to the 2FA setup screen — link a new authenticator.

⚠️ If the backup code is also lost — contact your workspace administrator. It is not possible to disable 2FA on your own without a backup code.


Errors and lockouts

Invalid or expired code

If you entered an outdated code (from the previous 30-second interval), the system will show an Invalid code message. Wait for the code to refresh in Google Authenticator and try again.

Lockout after multiple failed attempts

5 consecutive incorrect code entries will block login access for 5 minutes.

⚠️ After 5 failed attempts, you will receive an email about suspicious activity. If it wasn't you — contact your workspace administrator.