Two-factor Authentication
Two-factor authentication adds a 6-digit code from an authenticator app to every sign-in, with 10 backup codes. It works in the agency console, the client dashboard and the client portal.
Last checked against the product:
Overview
Every console, the same steps.
Agency console, client dashboard and client portal: Account menu > Two-factor authentication. The account menu is under your name at the top right.
Before you start
- Any user of the agency console, the client dashboard or the client portal, for their own account.
- An authenticator app on your phone, for example Google Authenticator, Microsoft Authenticator, 1Password, Authy or Bitwarden.
- To make it compulsory: a super admin in the agency console. To reset someone else: see Reset a User below for who can do it in each console.
Set It Up
About two minutes.
Open the page
Open Account menu > Two-factor authentication.
Scan the QR code
In step 1 on the page, scan the QR code with your authenticator app. If the QR code does not load, type the secret shown under it into the app instead.
Confirm a code
In step 2, type the 6-digit code the app now shows and click Verify and enable 2FA.
Save the backup codes
The page shows 10 single-use backup codes once. Use Print or Copy to clipboard and keep them somewhere safe. You will not see them again.
Signing In
Password first, then the code.
Backup Codes
When you run low.
On the same page, open Regenerate backup codes and click Generate new codes. You get 10 new codes and the old set stops working straight away. Disable 2FA asks for your password. If two-factor is compulsory for your console, you are asked to set it up again at your next sign-in.
Making It Compulsory
Per console, from a date.
Agency console: Setup > Security & 2FA. Super admin only.
Set the date
Set the 2FA enforcement deadline and click Save deadline. Until that date, users who have not set it up see a banner counting down the days.
Set each console
Under Enforcement per console, choose for the agency console, the client dashboard and the Client portal: the same date, its own date, or Off. Click Save per-console settings.
Tell people
Under Notify everyone, click the Send setup email to button. It emails each active user who has not set up two-factor, with the steps. It only works once a deadline is saved.
After the date, a user without two-factor is taken straight to the set-up page when they sign in and cannot open anything else. On a new TempClock system the date is set to 14 days after set-up.
Reset a User
For a lost phone and lost backup codes.
| Who is locked out | Where to reset | Who can do it |
|---|---|---|
| An agency console user | Agency console: Setup > Users, then Reset 2FA on their row | A super admin |
| A client dashboard user | Client dashboard: Setup > Users, then Reset 2FA. Agency console: Setup > Dashboard users, then Reset 2FA | A tenant admin, or the agency |
| A client portal user | Agency console: Clients > Portal users, Edit, then Reset this user's 2FA. Client dashboard: Setup > Portal users, then Reset 2FA | An agency Admin, or a tenant admin |
A reset clears the user's authenticator and backup codes, signs them out everywhere and forgets their trusted devices. They set it up again at their next sign-in. Every reset is written to the audit log.
Troubleshooting
Common questions.
| Problem | Check |
|---|---|
| The code is always wrong | The phone's clock must be right. Turn on automatic date and time on the phone. |
| Locked after wrong codes | Wait 15 minutes, or use a backup code. A super admin can reset you. |
| New phone | Sign in with your old phone or a backup code, open Disable 2FA, enter your password, then set it up again on the new phone. With no phone and no backup codes, ask for a reset (see Reset a User). |
Related guides
Know who turned up, and pay every hour right.
Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.
Hosted in the EU · Your largest site live first, with us alongside · No app needed to clock in