Skip to main content

Two Factor Authentication

How to set up 2FA, what to do if you're locked out, and how admins can reset it for their team.

Written by Rich Nicolson
Updated over a week ago

What is two-factor authentication?

Two-factor authentication (2FA) adds a second layer of security to your Socket login. As well as your password, you'll need to enter a code from an authenticator app each time you sign in. This protects your account even if your password is compromised.

2FA is required for all Socket accounts. You can use any authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy. SMS-based 2FA is not supported due to the security risks associated with SMS verification.

Setting up 2FA

When you first log in to Socket, you'll be prompted to set up 2FA automatically. The setup takes about a minute.

Click Get Started on the setup screen, then open your authenticator app and scan the QR code shown on screen.

Enter the six-digit code from your app to confirm it's working.

Save your recovery codes somewhere safe. These are displayed on the final screen and are the only way to regain access if you ever lose your authenticator app.

Once complete, your profile will show a green tick next to 2FA confirming it's active.

Staying logged in: the "Remember me" option

After setting up 2FA, you'll see a "Remember me for 30 days" option on the login screen. Ticking this means you won't be asked for a 2FA code on that device for 30 days, even if your session expires.

If you log in from a different device or location, you'll need to complete 2FA again.

If you're locked out

If you can't access your authenticator app, you have two options depending on your situation.

You have your recovery codes: enter one of them on the login screen in place of your authenticator code. Each recovery code can only be used once. After use, a new replacement code will be issued.

You don't have your recovery codes: contact the Socket team via the chat icon in the app or by emailing [email protected]. We'll verify your identity and reset your 2FA so you can set it up again from scratch. This is the most common reason people contact us about 2FA, so don't worry, it's a quick fix.

Note: if you've switched to a new phone and haven't transferred your authenticator app across, this counts as not having access to your app. Contact us and we'll reset it for you.

Common questions

Can I use 2FA without an authenticator app? No. Socket requires an authenticator app and does not support SMS-based 2FA. If you don't already have one, Google Authenticator, Microsoft Authenticator, and Authy are all free and quick to set up.

I've got a new phone.

How do I move my 2FA across? The easiest approach is to transfer your authenticator app to your new phone before you lose access to the old one. Most authenticator apps have a built-in transfer or export option. If you've already switched phones without doing this, contact us and we'll reset your 2FA.

Can I turn 2FA off? No, 2FA is required for all Socket accounts and cannot be disabled.
​

Did this answer your question?