Securing your account with two-factor authentication
Enabling two-factor authentication, recovery codes, and what to do when the authenticator is lost.
Settings → Security holds two cards: Update password, and Two-Factor Authentication. The page is part of your personal settings, alongside Profile and Appearance.
Two-factor authentication is a setting on your Billow account. It applies to every workspace you are a member of, and has no effect on anyone else’s account. Each person in a shared workspace enables it separately.
Changing your password
Update password takes your current password, then the new password twice. Save applies the change.
Password confirmation
Every two-factor action on this page requires your password. One confirmation covers the actions that follow it for a limited time.
Enabling two-factor authentication
Click Enable 2FA. Billow asks for your password first: “This is a secure area of the application. Please confirm your password before continuing.” Confirm it, then click Enable 2FA again.
A dialog opens with a QR code. Scan it with an authenticator app that supports TOTP. If the app cannot scan, use the setup key listed under “or, enter the code manually”. The button beside the key copies it.
Click Continue.
Enter the six-digit code: “Enter the 6-digit code from your authenticator app”. Click Confirm.
Two-factor authentication is enabled only after that code is accepted. Closing the dialog before then discards the setup, and the card returns to Enable 2FA.
Recovery codes
A 2FA Recovery Codes section appears on the card once two-factor authentication is enabled. View Recovery Codes reveals the eight codes.
Each code can be used once and is removed after use. Store them somewhere other than the device that runs your authenticator app. Regenerate Codes issues eight new codes, and the previous eight stop working immediately.
Signing in with two-factor on
Sign in with your email and password, or with Google. Billow shows a second screen: “Enter the authentication code provided by your authenticator application.” Enter the six digits from your authenticator app.
To use a recovery code instead, click “login using a recovery code” below the field and enter one of the eight.
Disabling two-factor authentication
Disable 2FA is at the bottom of the card and asks for confirmation: “Are you sure you want to disable two-factor authentication? This will make your account less secure.” Disabling deletes the authenticator setup and the recovery codes. Enabling it again produces a new QR code, a new setup key, and eight new recovery codes.
Lost authenticator
Sign in with a recovery code.
Go to Settings → Security and click Disable 2FA.
Enable it again on your new device.
Without the authenticator app and without a recovery code, the account cannot be recovered from inside Billow. Owners and admins cannot reset another person’s two-factor authentication. Contact support.
