Two-factor authentication

Protect your CertWatchr account with a code from an authenticator app on top of your password, and keep recovery codes for when the phone is lost.

With two-factor authentication (2FA) on, signing in takes your password and a six-digit code from an app on your phone. Someone who learns your password still cannot get in.

It is optional, and off until you switch it on.

Turning it on

  1. Go to Account → Two-factor authentication.
  2. Choose Authenticator app.
  3. Scan the QR code with your authenticator app — Google Authenticator, 1Password, Aegis, Bitwarden or any other TOTP app. If you cannot scan, type in the key shown below the code.
  4. Enter the six-digit code the app now shows. This step is what switches 2FA on; until you confirm a code, nothing changes.

From then on every sign-in asks for a code after your password, including sign-ins through Google, GitHub or Microsoft.

Recovery codes

Losing your phone must not mean losing your account. Right after enabling 2FA, go to Account → Recovery codes and generate a set.

  • Each code works once.
  • They are shown once, when generated. Keep them somewhere that is not the phone your authenticator is on — a password manager is ideal.
  • Generating a new set invalidates the old one.

When you need one, choose Lost your device? Use a recovery code at the code prompt.

Turning it off

Account → Two-factor authentication → Disable. If you have been signed in for a while you are asked for your password first.

Locked out

No phone and no recovery codes left? Contact support. We will verify that the account is yours and reset 2FA for you.