> ## Documentation Index
> Fetch the complete documentation index at: https://docs.legalancer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-Factor Authentication

> Turn on a second sign-in step, and know what to do when your phone isn't there.

Two-factor authentication puts a 6-digit code from your phone in front of your account, so a stolen password on its own gets nobody in.

<Warning>
  Once it's on, you'll be asked for a code on every single sign-in. There is no "trust this device" and no "remember this browser" — the code screen appears every time, on every device.
</Warning>

An authenticator app is the only supported second factor. There is no SMS option, no emailed code and no security key.

***

## Turning it on

Open your profile from your picture in the top-right corner, then go to the Security tab.

<Steps>
  <Step title="Click Enable 2FA">
    A window opens with a QR code and a Secret Key underneath it.
  </Step>

  <Step title="Add it to your authenticator">
    Scan the QR code with 1Password, Google Authenticator, Authy or any other TOTP app. If you can't scan — you're on the same phone, say — use the copy button beside the Secret Key and paste it into the app instead.
  </Step>

  <Step title="Save the secret key somewhere safe">
    Copy it into your password manager, or use an authenticator that syncs across your devices. This is the only time it's shown.
  </Step>

  <Step title="Enter a code and click Save">
    Type the 6 digits your app is showing. Nothing is switched on until this code checks out.
  </Step>
</Steps>

<Warning>
  There are no backup codes or recovery codes. Legalancer never issues any. The secret key from step 3 is your only self-service way back in if you lose the phone, so back it up before you close that window.
</Warning>

***

## Signing in from then on

Enter your email and password as usual, then a code screen appears. Type the 6 digits and you're in.

That code screen expires 5 minutes after your password is accepted. If you go looking for your phone and take longer than that, the screen stops working — go back to the login page and start from your password again.

Codes are accepted for the current 30-second window and one window either side, so a phone clock that's a few seconds out is fine. A phone that's minutes out is not: turn on automatic time in your phone's settings before you assume the code is wrong.

Wrong codes count as failed sign-ins. More than five failures on your email address inside 15 minutes blocks sign-in altogether, and the block clears 15 minutes after your last try — so stop guessing and check your phone's clock instead.

***

## Switching to a new phone or a new app

You can't point a second authenticator at your account while the first one is still active — the app refuses the setup outright. Disable two-factor first, then enable it again and scan the new QR code.

Do that while you still have the old authenticator in front of you: disabling asks for a current code from it.

***

## Turning it off

On the Security tab, click Disable and enter a current code from your authenticator. Your account drops back to password-only immediately.

***

## Locked out

If the authenticator is gone and you didn't keep the secret key, there is nothing you can do from the login page. Recovery is staff-initiated only.

Contact the agency and ask an admin or a manager to send you a two-factor reset link. It arrives by email and takes you to a fresh QR code and secret key. The moment you confirm a code from the new authenticator, the old one stops working and you're back to signing in normally.

The link works once and expires a day after it's sent, so use it while you have your phone to hand. Staff can only send it while your account is active.
