Two-factor authentication

Generate a security key or use biometric options to reduce the risk of account compromise.

Two-factor authentication (2FA) is a security method that requires an additional step of identification to protect your Dashboard account from unauthorized access.

You can perform either of the following to complete two-factor authentication:

Authenticator

You can choose any Authenticator app, as they all have a similar interface and operate in the same way. The first time you log in to the Dashboard, you need to configure two-factor authentication using your preferred app.

📘

Note

This requirement now also applies to Sandbox and self-service accounts. Users on these accounts who never configured 2FA are sent to authenticator-app (QR code) setup at their next Dashboard login and must complete it before signing in. Single sign-on (SSO) users are not affected.

The following algorithm describes the 2FA configuration, using Google Authenticator as an example:

  1. On the Dashboard login screen, enter your email (or username) and password.
  2. Open the Google Authenticator app on your device, tap the + icon and choose Scan a QR code.
  3. Scan the QR code displayed on the Dashboard login screen.
  4. Enter the app-generated authentication code, following the on-screen instructions.

Once you configure 2FA in the Google Authenticator app, you will be required to enter the code each time you log in to the Dashboard. The app generates a new code automatically every 30 seconds.

Security key

A security key is a secondary (and optional) method for two-factor authentication. This is a reliable and convenient form of authentication that uses public-key cryptography to keep your login credentials secure.

The security key allows you to use the following methods for two-factor authentication:

  • Fingerprint sensor or face recognition on your laptop.
  • Yubikey or any other hardware key.
  • Mobile devices.

To enable the security key as a two-factor authentication:

  1. In the Dashboard, go to the Profile settings page.
  2. Click Change next to the Two-factor authentication section.
  3. Click Add security key in the Security key section and follow the on-screen instructions to configure one or more options suggested by the system. You can add as many keys as you need.

Once the security key is added, you can access the Dashboard as follows:

  1. On the Dashboard login screen, enter your email (or username) and password.
  2. A pop-up window will request you to authenticate.
  3. Use the preferred security key that you have previously configured.

The system stores the last two-factor authentication method you used and offers this option the next time you log in. If you want to revert to Google Authenticator, in the pop-up window, click Cancel.

Confirm sensitive actions

Some Dashboard sections require you to re-confirm your identity before you can perform sensitive actions. When you open one of these sections, you are asked to enter your two-factor authentication code again, even though you are already signed in.

  • After you enter the code, the section stays unlocked for about 10 minutes. During this window, you can move between protected sections, switch browser tabs, and reload the page without being asked for the code again.
  • When the window expires, the next sensitive action prompts you for the code once more.
📘

Note

You are asked for the code only once per unlock — protected sections share the same confirmation, so entering it in one section unlocks the others for the rest of the window.

Manage 2FA authentication

You can always reset your Authenticator code or delete an existing security key.

To reset the Authenticator code:

  1. In the Dashboard, go to the Profile settings page.
  2. Click Change next to the Two-factor authentication section.
  3. Click Reset code for Authenticator.
  4. Open the Authenticator app on your device and scan the QR code displayed on the Dashboard login screen.
  5. Enter the app-generated authentication code, following the on-screen instructions.

To delete a security key:

  1. In the Dashboard, go to the Profile settings page.
  2. Click Change next to the Two-factor authentication section.
  3. Click the trash bin icon next to the security key you want to remove.

After deleting a security key, you will see a Restore button next to it, allowing you to restore the key if needed.

📘

Tip

To resolve 2FA and login issues, follow the steps in the SumsubCare guide (requires a Sumsub Dashboard login).


Did this page help you?