neo-pays

Security

Business

How this account proves it is you.

Signing in always requires a second factor. The only question is which: a code we send you by email, or a code your authenticator app generates offline.

Why move to an app

The email code depends on your mailbox being available. An app generates it on your phone, with no network, and comes with ten recovery codes for the day the phone is no longer there.

Setting it up

Scan the QR with any app (Google Authenticator, Authy, 1Password), then enter the six-digit code to finish. If scanning is impossible, the key can be typed by hand.

A setup started and not finished has to be restarted from the beginning. Starting again issues a new key — delete the old entry in your app, or it will produce codes that no longer work.

The recovery codes

They are shown once. Each one signs you in once. Without them, losing your phone is losing the account.

Generating a new set immediately invalidates the old one — do it if you think the printout has been seen. The screen warns you when only a few are left.

Turning it off

Turning the app off destroys your recovery codes and signs out all your other devices. Sign-in returns to the email code.

If the account owner has made the app mandatory for the company — see Team — turning it off is not offered.

/dashboard/security