Settings & Admin

Two-factor Authentication

Two-factor authentication adds a 6-digit code from an authenticator app to every sign-in, with 10 backup codes. It works in the agency console, the client dashboard and the client portal.

Talk to us Browse all guides

Last checked against the product:

Overview

Every console, the same steps.

Agency console, client dashboard and client portal: Account menu > Two-factor authentication. The account menu is under your name at the top right.

Before you start

  • Any user of the agency console, the client dashboard or the client portal, for their own account.
  • An authenticator app on your phone, for example Google Authenticator, Microsoft Authenticator, 1Password, Authy or Bitwarden.
  • To make it compulsory: a super admin in the agency console. To reset someone else: see Reset a User below for who can do it in each console.

Set It Up

About two minutes.

Open the page

Open Account menu > Two-factor authentication.

Scan the QR code

In step 1 on the page, scan the QR code with your authenticator app. If the QR code does not load, type the secret shown under it into the app instead.

Confirm a code

In step 2, type the 6-digit code the app now shows and click Verify and enable 2FA.

Save the backup codes

The page shows 10 single-use backup codes once. Use Print or Copy to clipboard and keep them somewhere safe. You will not see them again.

Signing In

Password first, then the code.

After your password, enter the 6-digit code from the app.
Tick Trust this device for 30 days (skip 2FA next time) on a computer only you use.
No phone? Click Lost your phone? Use a backup code and type one of your codes. Each works once.
Five wrong codes in 15 minutes lock the second step for 15 minutes.

Backup Codes

When you run low.

On the same page, open Regenerate backup codes and click Generate new codes. You get 10 new codes and the old set stops working straight away. Disable 2FA asks for your password. If two-factor is compulsory for your console, you are asked to set it up again at your next sign-in.

Making It Compulsory

Per console, from a date.

Agency console: Setup > Security & 2FA. Super admin only.

Set the date

Set the 2FA enforcement deadline and click Save deadline. Until that date, users who have not set it up see a banner counting down the days.

Set each console

Under Enforcement per console, choose for the agency console, the client dashboard and the Client portal: the same date, its own date, or Off. Click Save per-console settings.

Tell people

Under Notify everyone, click the Send setup email to button. It emails each active user who has not set up two-factor, with the steps. It only works once a deadline is saved.

Important

After the date, a user without two-factor is taken straight to the set-up page when they sign in and cannot open anything else. On a new TempClock system the date is set to 14 days after set-up.

Reset a User

For a lost phone and lost backup codes.

Who is locked out Where to reset Who can do it
An agency console user Agency console: Setup > Users, then Reset 2FA on their row A super admin
A client dashboard user Client dashboard: Setup > Users, then Reset 2FA. Agency console: Setup > Dashboard users, then Reset 2FA A tenant admin, or the agency
A client portal user Agency console: Clients > Portal users, Edit, then Reset this user's 2FA. Client dashboard: Setup > Portal users, then Reset 2FA An agency Admin, or a tenant admin

A reset clears the user's authenticator and backup codes, signs them out everywhere and forgets their trusted devices. They set it up again at their next sign-in. Every reset is written to the audit log.

Troubleshooting

Common questions.

Problem Check
The code is always wrong The phone's clock must be right. Turn on automatic date and time on the phone.
Locked after wrong codes Wait 15 minutes, or use a backup code. A super admin can reset you.
New phone Sign in with your old phone or a backup code, open Disable 2FA, enter your password, then set it up again on the new phone. With no phone and no backup codes, ask for a reset (see Reset a User).

Related guides

Know who turned up, and pay every hour right.

Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.

Hosted in the EU · Your largest site live first, with us alongside · No app needed to clock in