Two-factor authentication puts a 6-digit code from your phone in front of your account, so a stolen password on its own gets nobody in.
Once it’s on, you’ll be asked for a code on every single sign-in. There is no “trust this device” and no “remember this browser” — the code screen appears every time, on every device.
An authenticator app is the only supported second factor. There is no SMS option, no emailed code and no security key.
Turning it on
Open your profile from your picture in the top-right corner, then go to the Security tab.
Click Enable 2FA
A window opens with a QR code and a Secret Key underneath it.
Add it to your authenticator
Scan the QR code with 1Password, Google Authenticator, Authy or any other TOTP app. If you can’t scan — you’re on the same phone, say — use the copy button beside the Secret Key and paste it into the app instead.
Save the secret key somewhere safe
Copy it into your password manager, or use an authenticator that syncs across your devices. This is the only time it’s shown.
Enter a code and click Save
Type the 6 digits your app is showing. Nothing is switched on until this code checks out.
There are no backup codes or recovery codes. Legalancer never issues any. The secret key from step 3 is your only self-service way back in if you lose the phone, so back it up before you close that window.
Signing in from then on
Enter your email and password as usual, then a code screen appears. Type the 6 digits and you’re in.
That code screen expires 5 minutes after your password is accepted. If you go looking for your phone and take longer than that, the screen stops working — go back to the login page and start from your password again.
Codes are accepted for the current 30-second window and one window either side, so a phone clock that’s a few seconds out is fine. A phone that’s minutes out is not: turn on automatic time in your phone’s settings before you assume the code is wrong.
Wrong codes count as failed sign-ins. More than five failures on your email address inside 15 minutes blocks sign-in altogether, and the block clears 15 minutes after your last try — so stop guessing and check your phone’s clock instead.
Switching to a new phone or a new app
You can’t point a second authenticator at your account while the first one is still active — the app refuses the setup outright. Disable two-factor first, then enable it again and scan the new QR code.
Do that while you still have the old authenticator in front of you: disabling asks for a current code from it.
Turning it off
On the Security tab, click Disable and enter a current code from your authenticator. Your account drops back to password-only immediately.
Locked out
If the authenticator is gone and you didn’t keep the secret key, there is nothing you can do from the login page. Recovery is staff-initiated only.
Contact the agency and ask an admin or a manager to send you a two-factor reset link. It arrives by email and takes you to a fresh QR code and secret key. The moment you confirm a code from the new authenticator, the old one stops working and you’re back to signing in normally.
The link works once and expires a day after it’s sent, so use it while you have your phone to hand. Staff can only send it while your account is active.