Setting up two-factor authentication (2FA)

Updated 11 July 2026 4 min read

Setting up two-factor authentication (2FA)

Two-factor authentication (2FA) adds a second step to signing in, so a stolen password alone isn't enough to get into your Accupe account. This article covers turning 2FA on, verifying it with an authenticator app, and generating recovery codes as a backup.

Before you start

  • Security settings are admin-only. If you're not an admin, opening Settings > Security shows an "Access Restricted" message ("Only administrators can manage security settings.") instead of the controls below. Ask your firm's admin to set this up, or to grant you admin access first.
  • Have an authenticator app ready on your phone, such as Google Authenticator or Authy.

Turn on 2FA

  1. Go to Settings > Security.
  2. In the Authentication card, find "Two-Factor Authentication (2FA)".
  3. Select the toggle to switch it on. The "Setup Two-Factor Authentication" window opens.
  4. Wait while Accupe generates your token ("Generating secure token...").
  5. Scan the QR code that appears with your authenticator app. The screen also notes "If you can't scan it, you can enter the setup key manually in your app", but Accupe doesn't actually display that key as text anywhere on this screen, only the QR code itself, so if your device can't scan a QR code, use your authenticator app's own manual "add account" option instead.
  6. Select "Next Step".
  7. Enter the current 6-digit code your authenticator app shows for Accupe.
  8. Select "Verify & Enable" (this stays disabled until you've typed exactly 6 digits).

If the code is rejected, you'll see "Invalid code. Please try again." Codes refresh every 30 seconds, so check your app for the latest one and try again. Select "Back" if you need to return to the QR code screen.

Once verified, an "Active" badge appears next to "Two-Factor Authentication (2FA)", and you'll be asked for a code from your app every time you sign in from then on.

Note: Closing the setup window at any point before you complete Step 2 does not turn on 2FA, there's no separate cancel step needed. Just reopen it from the toggle and start again.

Generate recovery codes

Recovery codes let you sign in once each if you lose access to your authenticator app, for example if your phone is lost or the app is uninstalled. You can only generate them once 2FA is switched on.

  1. In the Authentication card, select "View Recovery Codes" (greyed out until 2FA is active).
  2. The "Recovery codes" window opens showing your current status: how many codes are unused, how many have already been used, and when they were last generated.
  3. Select "Regenerate codes".
  4. On the "Regenerate recovery codes?" confirmation, select "Regenerate codes" again to proceed. This immediately invalidates every code from any previous batch, including ones you haven't used yet.
  5. Your 10 new codes appear in a two-column list, with a banner reminding you they won't be shown again.
  6. Select "Download as .txt" to save a copy (the file is named accupe-recovery-codes-YYYY-MM-DD.txt, using that day's date), and select "I've saved them" once you've stored them somewhere safe.

Each code works once only. After you use one to sign in, it's marked as used and won't work again.

Tip: Keep your recovery codes somewhere separate from the phone running your authenticator app, such as a password manager or a printed copy in a locked drawer. If both live on the same device and you lose it, the codes won't help you.

Turn off 2FA

  1. Go to Settings > Security.
  2. Select the "Two-Factor Authentication (2FA)" toggle while it's switched on.
  3. On the "Disable Two-Factor Authentication?" prompt, select "Disable 2FA" to confirm.

This removes every authenticator you've enrolled, not just one. After this, sign-in relies on your password alone until you turn 2FA back on by repeating the steps above.

Status meanings in the Recovery codes window

You'll seeWhat it means
X unused code(s) remainingCodes still available to use if you lose access to your authenticator app
X already usedCodes that have already been redeemed and will no longer work
Last generated [date]When the current batch of codes was created
Note: Regenerating your codes is permanent. It invalidates the entire previous batch, even codes you haven't used yet, so only regenerate when you genuinely need a fresh set or think your existing codes may have been seen by someone else.