Two-factor authentication
Add a second factor to your sign-in — a passkey, an authenticator app, or codes by email — and let your workspace decide who must have one. Workflows can even ask approvers to confirm each decision with a code.
What 2FA is in Hubtoll
Two-factor authentication means a stolen password alone can't open your account — either by adding a one-time code to your sign-in, or by replacing the password altogether with a passkey. What you set up is yours, not per-workspace, and it protects you in every Hubtoll workspace you belong to.
Three methods are supported:
| Method | How it works | Availability |
|---|---|---|
| Passkey | Your device's own fingerprint, face or PIN signs you in — there's nothing to type and nothing to copy across. A passkey replaces your password at sign-in rather than adding a step to it. More below. | Free for everyone, on the web console. |
| Authenticator app | Scan a QR code once with Google Authenticator, Microsoft Authenticator, 1Password or any TOTP app; it then shows a fresh 6-digit code every 30 seconds — no network needed. | Free for everyone. Recommended. |
| Email codes | A 6-digit code is emailed to you each time one is needed. | Available on every plan. |
Every code is single-use, and repeated wrong codes temporarily lock the factor — changing network or device doesn't shed the lock.
Setting yours up
- Open your avatar (top right) → Security (or go to /user-profile/security).
- Choose Authenticator app, confirm your account password, scan the QR code (or type the manual key), and enter the app's current 6-digit code to confirm. Or pick Email to receive codes by email instead — both methods are on every plan.
- From then on, sign-in asks for your code after your password.
Or add a passkey from the Passkeys card on the same page — see below. A passkey counts as your second factor, so you don't need both.
Why the password for an authenticator app? Setting one up decides who can sign in as you from then on, so being signed in isn't enough on its own — the password proves it's you at the keyboard, not someone using a session you left open. Email codes don't ask for it: confirming the code we send already proves the inbox is yours.
If your workspace requires 2FA of you (see below), Hubtoll takes you to this screen — at sign-in, or straight away if the requirement starts while you're already signed in (say, your administrator turns it on, or you're given the Super admin role) — and the rest of the workspace stays locked until you've finished. That's by design, not a bug.
Passkeys
A passkey signs you in with the fingerprint, face or PIN your device already uses — no password and no code to type. It's the strongest option, and it's free for everyone.
Two things make it safer than a password. The passkey never leaves your device, so there's nothing for a leak or a database breach to expose. And your browser will only use it on the real Hubtoll address — a convincing look-alike site can't persuade it otherwise, which is the one thing a careful person still can't reliably spot by eye.
To add one:
- Open your avatar (top right) → Security.
- On the Passkeys card, click Add a passkey. We'll ask for a one-time code first — from your authenticator app, or emailed to you — because a passkey is a way into your account.
- Then follow your device's prompt (Touch ID, Face ID, Windows Hello, your phone, or a hardware security key).
- Give it a name you'll recognise — "Work laptop", "My phone" — so you can tell your devices apart later. We suggest one; change it or keep it.
Next time, click Sign in with a passkey on the sign-in page. You don't type your email first: your device offers whichever passkey belongs to Hubtoll.
| Good to know | |
|---|---|
| It satisfies a 2FA requirement | Because your device checks it's you (fingerprint, face or PIN) every single time, a passkey counts as two factors on its own. If your workspace requires two-factor authentication, adding a passkey is enough — you don't also need an authenticator app. |
| Add one per device | Add a passkey on each device you sign in from. Some passkeys sync through your Apple, Google or password-manager account, and where they do we'll show them as "available on your other devices". |
| You can still use your password | Adding a passkey doesn't remove your password. If your workspace requires a second factor, signing in with your password will ask you to confirm with your passkey afterwards. |
| Rename or remove any time | Both are on the Passkeys card. Removing a passkey only affects that device. |
| Adding or removing one asks for a code | A passkey is a way into your account, so changing which ones you have is confirmed with a one-time code — from your authenticator app, or emailed to you if that's your only factor. Adding one asks before your device prompts you, so you're never left with a half-made passkey. And it's never your passkey you're asked for: you'll usually be removing one because that device is gone. |
| The last one is protected | If a passkey is the only thing satisfying your workspace's two-factor requirement, Hubtoll won't let you remove it — that would lock you out at your next sign-in. Add an authenticator app or another passkey first, then remove it. |
If your browser can't create a passkey (an older browser, or a page that isn't on a secure https address), the button simply isn't offered — you can still see and remove any passkeys you've already added.
Very rarely, Hubtoll stops accepting a particular passkey and marks it no longer accepted on that card. That's a safety check reacting to something unexpected from the device; remove it and add a fresh one.
What a workspace can require
Each workspace decides independently what it demands, under Corporate management → Security (profile editors and super admins):
- Super admins — the workspace can insist its super admins are enrolled before they can do anything else.
- Staff — off, optional, or required for everyone.
Because your factor is yours, setting one up once — a passkey, an authenticator app or email codes — satisfies every workspace that requires one.
Codes on approvals
A workflow can ask its approvers to confirm each decision with a one-time code — approve, reject or send-back. The switch lives on the workflow itself, where the workflow is designed, so it applies to that process only.
When it's on, deciding first shows your normal confirmation, then asks for a code from your own factor. Nothing is recorded until the code checks out — cancelling leaves the record exactly as it was. This works on the web console and in the Hubtoll mobile app.
An approver with no factor isn't waved through: they're challenged by email, or can set up an authenticator first.
One thing to know if you sign in with a passkey: this particular step asks for a code, not your passkey, so you'll be sent one by email. Setting up an authenticator app alongside your passkey avoids the email round-trip on workflows that use this.
Resetting or turning it off
On the same Security page you can replace your factor (e.g. a new phone — re-scan a fresh QR) or turn 2FA off, where your workspace doesn't require it. Either way you must first prove the current factor: authenticator users enter their app's code; email users are sent one.
We email you when a way to sign in is added
Whenever a passkey is added to your account, or an authenticator app or email codes are set up — including when you move to a new phone — Hubtoll emails you straight away. The email says what was added, when (in your workspace's time), roughly where from and on which device, and in which workspace.
If it was you, there's nothing to do. If it wasn't, someone else may have access to your account, and the email says what to do next: remove the passkey from your Security page, change your password, or ask us to reset two-factor authentication if you can't sign in any more. A passkey works without your password, so changing the password alone won't stop one somebody else added — remove it first. Setting up email codes needs a code sent to your inbox, so if you didn't set them up, secure your email account too.
These emails can't be switched off: they're how you'd find out if someone else did it.
Lost your factor?
If you can't produce a code or reach your passkey — a lost or replaced phone, a deleted app, a laptop you no longer have — use the “Lost access…?” link at the bottom of the sign-in step that's asking you to confirm. It raises a request to the Hubtoll team, who verify it's really you before clearing it so you can set one up again. There are deliberately no recovery codes to store or lose.
A reset clears everything: your authenticator or email factor and every passkey on your account. That's on purpose — the usual reason for this request is a device you no longer control, and a passkey left behind on it would still work.
If you still have another device with a working passkey, you don't need us: sign in with that one and add a replacement from the Passkeys card. Removing the one on the lost device takes seconds.
Your workspace's admins can't see or reset your factor themselves; the reset is done by Hubtoll, and every reset is recorded.
Continue reading
Reach the Hubtoll team on WhatsApp or email cloud@digitalvortextech.org. We usually reply within a few hours (Mon–Fri, 8:00–19:00 GMT).