Guide

Two Factor Authentication

Add a second step to your sign in, so your password on its own is not enough to reach your account. It is optional, you turn it on yourself, and it works with any authenticator app.

8 min read Updated September 2026 Security

In short

Turn it on at Settings → Security. Scan one QR code with an authenticator app, type the 6 digit code it shows, and save the 10 backup codes you are given.

After that, signing in asks for your password and then a code. Nothing else about your account changes.

Overview

What it is

A password is one factor: something you know. Anyone who learns it can sign in as you. Two factor authentication adds a second factor, something you have, in the form of a phone running an authenticator app. Someone who steals your password still cannot get in, because they do not have your phone.

The app shows a 6 digit code that changes every 30 seconds. When you sign in, TimelyDo asks for that code after your password. The code is generated on your device from a secret shared once at setup, so it works even with no signal and no internet connection.

It is entirely optional. Two factor authentication is off until you switch it on, and you can switch it off again at any time. Nobody is forced into it.

What you need

Any authenticator app that supports standard TOTP codes. TimelyDo does not tie you to one vendor. Popular choices:

Google Authenticator Authy 1Password Microsoft Authenticator Bitwarden Apple Passwords Any other TOTP app
If you use a password manager that stores codes for you, such as 1Password or Bitwarden, it can hold your TimelyDo code alongside your password and fill both in. Just make sure that manager itself is well protected, since it then holds both factors.
Setup

Turning it on

The whole thing takes about a minute.

1
Open your security settings
Go to Settings → Security. The two factor card sits below the change password form and shows a status of Off.
2
Select Turn on two factor authentication
A QR code appears, along with a setup key in text form.
3
Add TimelyDo to your authenticator app
Open your app, choose to add an account, and scan the QR code. If the device you are reading this on has no camera, or your app cannot scan, select the setup key to copy it and type it into the app by hand instead. Both routes produce exactly the same result.
4
Enter the 6 digit code
Your app now lists TimelyDo with a code that changes every 30 seconds. Type the code it is showing right now and select Verify and turn on. This step proves the app really did scan correctly, which is why nothing is switched on until it passes.
5
Save your backup codes
Ten backup codes appear. Copy or download them before you leave the page. See the next section for why this matters.
If the code is rejected at step 4, nothing has been switched on and your account is still reachable with your password alone. Check the troubleshooting section below, or start the setup again to get a fresh QR code.

Your backup codes

When you turn two factor authentication on, you are given 10 backup codes. Each one works exactly once, and any of them can be used in place of a code from your app.

They exist for one situation: you no longer have the phone with your authenticator app on it. A lost, stolen, broken or wiped phone takes your codes with it, and without a backup code there is no way back into your account.

How to store them

Anywhere that is not the phone running your authenticator app
Important
Good places
  • Your password manager, as a secure note
  • Printed and kept somewhere physically safe
  • An encrypted file on a different device
Poor places
  • A note on the same phone as the app
  • An email to yourself
  • A plain text file on a shared drive
Copy codes Download as timelydo-backup-codes.txt Each code works once
The codes are shown once and never again. We store only a hashed form of them, so we genuinely cannot show them to you later, and neither could anyone who stole a copy of our database. If you lose them, generate a new set while you are still signed in.
Everyday use

Signing in

Sign in with your email and password as usual. Instead of landing in the app, you get a short page asking for your code.

Email and password code prompt signed in

Open your authenticator app, read the 6 digit code next to TimelyDo, and type it in. The form submits on its own as soon as you have entered six digits, so there is usually nothing to click.

Lost your phone? Type one of your backup codes into the same box instead. There is no separate mode to switch to, the box accepts either. That code is then used up and will not work a second time.

Until you enter a correct code you are not signed in at all. Closing the tab at the prompt leaves your account exactly as it was, and the prompt itself expires after 10 minutes.

How often you are asked

Not every time you open the app. The Remember me box on the sign in form keeps you signed in on that browser for two weeks, and it is ticked by default. So in practice you enter a code roughly once a fortnight per browser, plus any time you sign in somewhere new.

If you would rather be asked more often, untick Remember me when you sign in. Signing out ends the remembered session everywhere, so the next sign in asks for a code again.

What is covered

A second factor is only worth having if it covers every door into your account, so it applies to all of these:

Way inAsks for a codeNotes
Email and password Yes The normal sign in
Sign in with Google Yes Google verifying you does not replace your own second factor, otherwise it would be a way around it
Password reset link Yes The reset still works, but you land on the code prompt. Access to your mailbox alone is not enough
Email confirmation link Yes Applies when you change your email address and confirm the new one
API key No Your API key keeps working for integrations. It cannot be used to turn two factor authentication off
Existing sessions on your other devices are not signed out when you turn two factor authentication on. If you want them gone, sign out and back in.
Managing

Generating new backup codes

Go to Settings → Security and select Generate new backup codes. You are asked to confirm with your password, then a fresh set of 10 appears.

Do this when you have used several codes, when you have lost the list, or when you think someone else may have seen it. The security card shows how many unused codes you have left.

Old codes stop working immediately. Generating a new set replaces the previous one in full, so throw the old list away and save the new one.

Turning it off

Go to Settings → Security and select Turn off. You are asked to confirm with your password first.

If you signed up through Google and have never set a password, you are asked for a code from your authenticator app instead. A backup code works there too.

Turning it off deletes your backup codes and removes the pairing with your authenticator app. You can delete the leftover TimelyDo entry from the app afterwards. If you turn two factor authentication back on later, you set it up fresh with a new QR code and a new set of backup codes.

Asking for your password here is deliberate. It means someone who walks up to an unlocked laptop cannot quietly remove your second factor.

Email notices

We email you whenever two factor authentication is turned on or off, with the time the change was made shown in your own timezone. Generating new backup codes does not send an email.

These notices exist so that a change made by someone else still reaches you. If one of them arrives and it was not you, act on it. Change your password, turn two factor authentication back on, and contact us at support@timelydo.com.

Help

Troubleshooting

My code keeps being rejected

Almost always a clock problem
Codes are generated from the current time, so if your phone clock has drifted, every code it produces will be wrong. Turn on automatic date and time on your phone, then try again. We allow about 90 seconds of slack either side, so small drift is already handled.
Also worth checking
  • You are reading the code under the right account. Authenticator apps often hold many entries
  • The code has not just expired. If it is about to roll over, wait for the next one
  • You are not reusing a code you already used. Each code works once, even inside its 30 second window

I lost my phone

Use a backup code, then re-enrol
Sign in as usual and enter one of your backup codes at the prompt. Once you are in, go to Settings → Security, turn two factor authentication off and straight back on. That produces a new QR code for your replacement phone and a new set of backup codes.

I lost my phone and my backup codes

Contact support
There is no self service route out of this, by design. Email support@timelydo.com from the address on your account and we will verify who you are before removing the second factor. Expect this to take longer than a password reset, because it has to.

I was sent back to the sign in page

The prompt timed out or hit the attempt limit
The code prompt is valid for 10 minutes, and five wrong codes end it. Neither locks your account. Sign in again to get a fresh prompt.

How it works under the hood

For anyone who wants the detail:

StandardTOTP, defined in RFC 6238. The same standard every major site uses, which is why any authenticator app works
Codes6 digits, regenerated every 30 seconds, valid for about 90 seconds to allow for clock drift
ReplayOnce a code is accepted it cannot be used again, even while it is still on screen
AttemptsFive wrong codes end the sign in attempt and you start over
Your secretEncrypted in our database, not stored in readable form
Backup codesStored hashed, the same way passwords are, so they cannot be read back by anyone

Frequently asked

Q

Do I need internet on my phone to get a code?

No. Codes are calculated on the device from the secret saved at setup and the current time. Aeroplane mode is fine.
Q

Can I use the same setup on two phones?

Yes. Scan the same QR code with both apps during setup and either will produce valid codes. Some apps, such as Authy and 1Password, also sync across your own devices for you.
Q

Does this affect my attendees or my booking page?

Not at all. It protects your account only. People booking with you never see a code prompt and nothing about your public page changes.
Q

Will my integrations break?

No. Connected calendars, Zoom, Stripe, webhooks and your API key all keep working exactly as before.
Q

I signed up with Google and have no password. Can I still use this?

Yes. Turn it on the same way. When you later need to confirm turning it off or generating new codes, you are asked for a code from your app rather than a password.
Q

Can I be forced to use it by an admin?

No. It is a personal setting on your own account. There is no organisation wide requirement.

Was this article helpful?

Let us know so we can keep improving our documentation.