← Back to Kept

Short reads on how Kept works, from setup to safety.

Setting up two-factor authentication
Two-factor authentication (TOTP, the six-digit code from an authenticator app) adds a second check beyond your password when signing in, so…

Two-factor authentication (TOTP, the six-digit code from an authenticator app) adds a second check beyond your password when signing in, so a leaked password alone isn't enough to get into your account.

Setting it up

From Account -> Security, start setup to get a QR code (or a manual entry key) to add to an authenticator app. Google Authenticator, Authy, 1Password, or anything else that generates standard TOTP codes works. Enter the six-digit code the app shows you to confirm the setup before it's turned on; this catches a mistyped secret before it can lock you out.

Using it

Once enabled, signing in asks for your password as normal, then a code from your authenticator app. Each code works once. Reusing a code you've already entered, even within its normal validity window, doesn't work a second time.

Signing in without your phone

There is currently no self-service recovery code or backup method if you lose access to your authenticator app. If this happens, use the feedback form (see "How do I contact support?") rather than trying repeated codes; a locked-out account needs a person to sort out.

Turning two-factor off later requires your password again, to confirm the change is being made by you and not by someone who is already inside your session.