Security and 2FA
Set up two-factor authentication and manage your account sessions and devices
Two-factor authentication (2FA)
Two-factor authentication adds an extra layer of security: in addition to your password, you need a temporary code to sign in. You can configure it at Settings → Security (2FA).
Enable 2FA
- Go to Settings → Security (2FA) and click Enable TOTP (Google Authenticator).
- Scan the QR code with Google Authenticator (or any TOTP app). If you can't scan it, use the manual key shown below the QR.
- Enter the 6-digit code shown in the app and click Confirm and enable.
- Save the backup codes that appear — they are shown only once and you'll need them if you lose access to your device.
Backup codes are only shown once when enabling 2FA. Store them somewhere safe. If you lose them, you can regenerate them from Settings → Security.
Verification methods
| Method | When to use it |
|---|---|
| Google Authenticator (TOTP) | Primary method — 6-digit code that changes every 30 seconds |
| Code by email | If your device is not available — the system sends a code to your email |
| Backup code | If you lost access to your app and email — each code can only be used once |
Signing in with 2FA enabled
After entering your email and password, the system redirects you to a verification screen where you enter the code using your chosen method. You can switch methods at any time from that screen.
Verification on critical actions
Some sensitive actions require additional 2FA verification, regardless of when you signed in:
- Refunding a reservation
- Creating or editing system users
When attempting these actions, a verification modal opens where you must enter your code. Once verified, you have 15 minutes before verification is required again.
If you haven't set up 2FA yet, the system will guide you through the setup before you can perform these actions.
Suspicious access detection
If the system detects an unusual sign-in (VPN, network change, or unknown device), it blocks access and sends a verification code to your email. You must enter it to continue.
Active sessions and devices
From Settings → Security you can view and manage:
- Active sessions — all devices where you have an open session. You can close individual sessions or all others except the current one.
- Trusted devices — devices the system has recognized. You can mark them as trusted or remove them.
Disable 2FA
In Settings → Security, click Disable TOTP, enter a current code from your app to confirm, and you're done.