Two-factor authentication
Two-factor authentication is an additional layer of protection that dramatically increases the security of your account. It is designed to ensure that only you can access it even if somebody else knows your password.
It requires a smartphone with Google Authenticator (or similar app) installed. To log in, you will have to enter a one-time 6-digit code provided by your mobile app, in addition to your password.
Why enable two-factor authentication?
Passwords alone are a fragile barrier: they can be stolen by phishing, leaked in data breaches on other websites, or guessed when they are too simple. Many people also reuse the same password across different services, which means a single leak can expose several accounts. Two-factor authentication combines something you know (your password) with something you physically have (your smartphone): even if somebody else obtains your password, they still cannot log in without the one-time code generated on your phone.
How does it work?
Once two-factor authentication is enabled, logging in requires two steps: your password, followed by the current 6-digit code from your authenticator app. The code is generated on your phone or computer app, changes every 30 seconds, and can only be used once, which makes an intercepted code useless.
Enabling two-factor authentication
You can enable or disable two-factor authentication from Avatar / Change my password / Manage two-factor authentication.
External plugins and applications relying on our API (other than those provided by PhotoDeck) might not work with two-factor authentication.
Please save carefully the secret key as instructed when you set up two-factor authentication, as it will allow you to easily and securely recover your account if you lose your device.
Recovering access to your account
When you enabled two-factor authentication, you were instructed to save the text key displayed under the QR code securely and separately from your phone, for example in a password manager. This secret key is your first and most secure recovery mechanism: if you lose your authentication app or its configuration, you can configure a new authenticator app with the same key, and your one-time codes will start working again without having to contact us.
If you no longer have that secret key either, contact support with your account information: to verify your identity, we will ask you for a proof of identity matching the account’s name (for example your passport) and the date and invoice number of your last payment. We will then disable two-factor authentication so that you can log in again.
FAQ
I don’t received any code to log in
Two-factor authentication works with the smartphone or desktop authenticator app you have used when setting it up. This is where you will find the code to log in, no code is sent via SMS or email.
I lost my two-factor authentication app and can’t log in anymore
Contact support with your account information: to verify your identity, we will ask you for a proof of identity (for example your passport) and the date of your last payment. We will then disable two-factor authentication so that you can log in again.
I get asked for a verification code but I never set up two-factor authentication
The 6-digit code is generated by the authenticator app (for example Google Authenticator) that was used when two-factor authentication was enabled on your account. If you no longer have access to that app, contact support so that we can verify your identity and reset it for you.