MagicWP Docs
Account & Team

Two-factor authentication

When MagicWP requires two-factor authentication, and what to expect

Two-factor authentication (2FA) protects your account with a 6-digit code from an authenticator app, in addition to your password. Turn it on in Settings → Security.

When 2FA is required

  • Working in someone else's workspace. Every member needs 2FA turned on and must have entered a code when signing in. This protects the workspace Owner's sites from a member's leaked password.
  • Managing members. The Owner needs 2FA to invite people, resend invitations and change roles.
  • Creating API tokens. Anyone creating a token needs 2FA.

Turning 2FA off later stops all of your API tokens from working, and closes your access to other people's workspaces until you turn it back on.

"Confirm with your authenticator"

If you signed in before turning 2FA on, or your session didn't go through a code, the dashboard asks for a current 6-digit code the first time you need it. Enter it and what you were doing carries on: an invitation you were sending is sent, and you don't have to fill anything in again.

If 2FA isn't set up yet, the dialog sends you to Settings → Security to turn it on first.

On this page