Two-step sign-in (2FA)

Sign in with your normal login, then a 6-digit code from an app on your phone. Your org or company can require it for everyone.

Two-step sign-in (2FA) adds a second step after your normal login (Google or email): a 6-digit code from an authenticator app on your phone. Someone who steals your password still cannot get in without your phone.

Turn it on for yourself

  1. Open Settings at the bottom of the left menu, then the Security tab.
  2. Click Set up 2FA.
  3. Open an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, Authy…) and scan the QR code. Can't scan it? Click Type a key instead.
  4. Type the 6-digit code the app shows, and click Turn on 2FA.
  5. Save your 10 backup codes. They are shown only once. Copy or download them, and keep them somewhere safe, like a password manager.

From now on, every sign-in asks for a code after your normal login. 2FA belongs to you, not to an org: the same app works for every org you are in.

Make it required for everyone

An org Admin opens the org's Settings → Security and sets Everyone must use 2FA to Yes, everyone. A company Admin can do the same in Settings → Company → Security: then it applies to every org in the company, and an org cannot turn it off.

Next to the switch, Admins and Managers see how many people already use 2FA, and who does not.

Turning it on never signs anyone out or blocks a sign-in. People without 2FA are asked to set it up right after their next click or sign-in, before anything else opens.

Workspaces and teams do not have their own switch. Their settings show whether the org or the company requires 2FA.

Signing in

After your normal login, SeamTrail asks for the 6-digit code from your app.

  • Use a backup code instead: each backup code works once. When only two are left, SeamTrail reminds you to make new ones.
  • Five wrong codes in a row lock code entry for 15 minutes.
  • If SeamTrail cannot check codes for a moment, try again, or use a backup code.

New phone, new backup codes, turning it off

In Settings → Security:

  • Move to a new phone: scan a new QR code. The old phone stops working.
  • New backup codes: makes 10 new ones; the old ones stop working. Needs a code from your app.
  • Turn off: needs a code from your app. Not possible while your org or company requires 2FA.

Lost your phone and your backup codes?

On the code screen, click Lost your phone and your backup codes? SeamTrail shows the Admins of your org and company, with their emails. Ask one of them to reset your 2FA. If no one else can reset it, write to SeamTrail support from the email you sign in with.

Resetting someone's 2FA (Admins)

An org Admin opens the org's Settings → People and clicks Reset 2FA next to the person. Company Admins can do it in every org of the company.

  • Do it only when you are sure it is really them asking, for example on a call.
  • The person signs in with their normal login and sets 2FA up again. They see who reset it, and when.
  • A reset never lets the Admin sign in as them.
  • Every reset is written in the audit log.

Who has 2FA

Every people list (org, workspace, team, feature and company) shows a 2FA or No 2FA tag next to each person, for that place's Admins and Managers.

AI assistants

AI assistants (Claude, Cursor, ChatGPT…) sign in with their own link and cannot type a code. Links made before keep working. Making a new link needs a sign-in that passed 2FA: if you have not entered your code yet, SeamTrail asks for it first, then brings you back to the assistant's page. You can remove an assistant's link at any time in Settings → AI assistants.

What is kept

The authenticator secret is made and checked by WorkOS, SeamTrail's sign-in provider. SeamTrail keeps only a reference to it, and the backup codes as a one-way hash, never the codes themselves.

On this page