ResytechResytech Docs
Team Management

Enable Two-Factor Authentication

How to set up two-factor authentication on your Resytech account with an authenticator app or SMS, save your recovery codes, and start using trusted devices.

Two-factor authentication (2FA) protects your account by requiring a verification code from your phone in addition to your password whenever you sign in. Because Resytech accounts can move real money, we strongly recommend enabling 2FA for every team member -- and especially for administrators.

This guide walks you through the full enrollment for either method, what to expect on your next sign-in, and how to manage your trusted devices afterward.

Before you begin

  • Decide how you want to get codes:
    • Authenticator app (recommended). Install one on your phone if you have not already: Google Authenticator, Microsoft Authenticator, Authy, or the one built into 1Password or Bitwarden all work. No cell service needed.
    • Text message (SMS). You need a US mobile phone that can receive SMS messages.
  • You need your current Resytech password handy -- the wizard asks for it as proof of identity.
  • Have a safe place ready to store your recovery codes (a password manager is ideal).

Steps

1. Open the Security tab

  1. Click your name in the top navigation, or go to Dashboard > Profile.
  2. In the left sidebar, click Security.
  3. Find the Two-Factor Authentication card. If 2FA is not enabled yet, it shows an amber warning banner and a green Enable 2FA button.
  4. Click Enable 2FA. The enrollment wizard opens and asks which method you want.

2a. Authenticator app

  1. Click Authenticator app.
  2. Enter your current Resytech password and click Continue. Resytech generates a setup key and shows it as a QR code.
  3. Open your authenticator app and choose Add account, Scan QR code or the + button.
  4. Point the phone at the QR code on screen. The app adds an entry named Resytech: your-email and starts showing a 6-digit code that changes every 30 seconds.
    • Cannot scan? Click Can't scan it? Enter the key manually, then in your app choose Enter a setup key and type the key shown (letters and digits, spaces do not matter). Choose time based if the app asks.
  5. Type the 6-digit code the app is currently showing into Code from your app and click Verify and enable.

The QR code is valid for 10 minutes. If it expires, click Back and start step 2a again -- a new key is generated, so make sure the entry in your app is the one you just scanned. Skip to step 3.

2b. Text message (SMS)

  1. Click Text message (SMS).
  2. In the Mobile phone number field, enter the number you want verification codes sent to. You can include spaces, dashes, or parentheses -- the format (415) 555-1234 works just as well as +14155551234.
  3. In the Confirm your password field, enter your current Resytech password.
  4. Click Send verification code. Resytech sends a 6-digit SMS code to the number you typed in. You should receive it within a few seconds.
  5. Open your phone and check the SMS. The message looks like: "Your Resytech verification code is 123456. It expires in 10 minutes. Never share this code with anyone."
  6. Type the 6-digit code into the verification input. On iPhone and modern Android browsers, the code may auto-fill from the SMS notification.
  7. Click Verify and enable.

Tip: Standard messaging rates apply. The code is sent from the main Resytech number, not from your business's connected Twilio account (if you have one).

If you typed the wrong code, you have up to 5 attempts before the code is permanently burned and you have to request a new one. If your code expired, click Back and start again.

3. Save your recovery codes

After successful verification, Resytech generates ten one-time recovery codes and displays them on screen. They look like abcd-efgh.

This is the only time you will ever see these codes. If you lose them, you have no way to retrieve them -- you can only generate a new batch (which invalidates this one). Save them now:

  1. Click Copy all to copy them to your clipboard, then paste into your password manager.
  2. Or click Download .txt to save them to a text file. Move the file somewhere safe (encrypted disk, locked cloud folder, printed and filed away).
  3. Tick the "I have saved these recovery codes somewhere safe" checkbox at the bottom. The Done button stays disabled until you do.
  4. Click Done.

Why recovery codes matter: If you ever lose your phone, break it, wipe your authenticator app, switch carriers, or travel somewhere without service, recovery codes are how you get back into your account. Each code works exactly once, so guard them carefully.

What happens next

  • The Two-Factor Authentication card now shows a green "Enabled" badge, your method (authenticator app, or your masked phone number like +1 ••• ••• 1234) and the date you enrolled.
  • Your next sign-in will require a verification code. Sign out and back in to test it -- you should see a new "Verify your identity" screen between password and dashboard.
  • A new Trusted Devices card appears below the 2FA card. It is empty until you check the "Trust this device for 30 days" box during a sign-in.

Signing in with 2FA enabled

The next time you sign in, the flow looks like this:

  1. Enter your email and password as usual, click Sign in.
  2. The screen changes to "Verify your identity".
  3. Authenticator app: open the app and read the current 6-digit code for Resytech. SMS: Resytech texts you a 6-digit code.
  4. Enter the code. Optionally check Trust this device for 30 days if you are signing in from your own computer.
  5. Click Verify and sign in.

Once you check the trusted-device box on a browser, you will skip the verification step entirely for the next 30 days when signing in from that same browser. You can manage this list any time from Profile > Security > Trusted Devices.

Tips

  • Trust devices you control, not shared computers. If you sign in from a friend's laptop or a hotel business center, leave the trusted-device box unchecked.
  • Keep your recovery codes synced with your password manager. If you save your password in 1Password or Bitwarden, save your recovery codes there too -- the password and recovery codes belong together.
  • Authenticator codes are time-based. If a code is refused, wait for the app to show the next one and try again. If codes are refused repeatedly, check that your phone's clock is set automatically -- a clock more than a minute off will produce codes Resytech does not accept.
  • A used authenticator code cannot be entered twice. If you sign in and something else asks for a code within the same 30 seconds, wait for the next one.
  • You can resend an SMS code. If your text does not arrive within a minute, click Didn't get a code? Resend on the verification screen. There is a 60-second cooldown between resends.
  • Daily SMS limit is 10. Across all 2FA flows -- sign-in, enrollment, recovery -- Resytech only sends 10 codes per user per 24 hours. If you hit this limit, use one of your recovery codes instead.
  • SMS codes expire fast. Each is only valid for 10 minutes. If yours expires, request a new one.
  • Lost your phone? Use a recovery code. See Recover Account Access.

Regenerating recovery codes

If you have used some of your codes (or you suspect they may have been exposed), you can generate a fresh batch:

  1. Go to Profile > Security.
  2. In the Two-Factor Authentication card, click Regenerate recovery codes.
  3. Confirm your password and click Continue (authenticator app) or Send verification code (SMS).
  4. Enter the code from your app, or the SMS code you receive.
  5. Save the new batch of ten codes -- the old codes are now invalid.

Disabling 2FA

If you ever need to turn off 2FA (for example, to switch methods, change your phone number, or move your authenticator to a new phone):

  1. Go to Profile > Security > Disable 2FA.
  2. Choose I have my authenticator app / I have my phone, or Use a recovery code.
  3. Confirm your password.
  4. Enter the verification code or recovery code.
  5. Click Disable 2FA.

After disabling, your authenticator secret or verified phone, your recovery codes, and all your trusted devices are removed. You can re-enable 2FA at any time with either method -- this is the supported way to change your method, phone number or authenticator device.

For more on the security model and limits, see Two-Factor Authentication.

On this page