Two-factor authentication
Add a second factor to your sign-in — an authenticator app, or codes by email — and let your workspace decide who must have one. Workflows can even ask approvers to confirm each decision with a code.
What 2FA is in Hubtoll
Two-factor authentication adds a one-time code to your password at sign-in, so a stolen password alone can't open your account. You hold one factor — it's yours, not per-workspace — and it protects you in every Hubtoll workspace you belong to.
Two methods are supported:
| Method | How it works | Availability |
|---|---|---|
| Authenticator app | Scan a QR code once with Google Authenticator, Microsoft Authenticator, 1Password or any TOTP app; it then shows a fresh 6-digit code every 30 seconds — no network needed. | Free for everyone. Recommended. |
| Email codes | A 6-digit code is emailed to you each time one is needed. | Included with paid plans. |
Every code is single-use, and repeated wrong codes temporarily lock the factor — changing network or device doesn't shed the lock.
Setting yours up
- Open your avatar (top right) → Security (or go to /user-profile/security).
- Choose Authenticator app, scan the QR code (or type the manual key), and enter the app's current 6-digit code to confirm. If your workspace's plan includes email codes, you can pick Email instead.
- From then on, sign-in asks for your code after your password.
If your workspace requires 2FA of you (see below), Hubtoll takes you to this screen at sign-in and the rest of the workspace stays locked until you've finished — that's by design, not a bug.
What a workspace can require
Each workspace decides independently what it demands, under Corporate management → Security (profile editors and super admins):
- Super admins — the workspace can insist its super admins are enrolled before they can do anything else.
- Staff — off, optional, or required for everyone.
Because your factor is yours, enrolling once satisfies every workspace that requires one.
Codes on approvals
A workflow can ask its approvers to confirm each decision with a one-time code — approve, reject or send-back. The switch lives on the workflow itself, where the workflow is designed, so it applies to that process only.
When it's on, deciding first shows your normal confirmation, then asks for a code from your own factor. Nothing is recorded until the code checks out — cancelling leaves the record exactly as it was. This works on the web console and in the Hubtoll mobile app.
An approver with no factor isn't waved through: they're challenged by email where the plan includes it, or told to set up an authenticator first.
Resetting or turning it off
On the same Security page you can replace your factor (e.g. a new phone — re-scan a fresh QR) or turn 2FA off, where your workspace doesn't require it. Either way you must first prove the current factor: authenticator users enter their app's code; email users are sent one.
Lost your factor?
If you can't produce a code (lost phone, deleted app), use “Lost your authenticator?” on the sign-in page. It raises a request to the Hubtoll team, who verify it's really you before clearing the factor so you can enrol again — there are deliberately no recovery codes to store or lose.
Your workspace's admins can't see or reset your factor themselves; the reset is done by Hubtoll, and every reset is recorded.
Continue reading
Reach the Hubtoll team on WhatsApp or email cloud@digitalvortextech.org. We usually reply within a few hours (Mon–Fri, 8:00–19:00 GMT).