Skip to main content
Everyone·Getting Started

Two-Factor Authentication

Set up 2FA on your account to add a second layer of protection beyond your password

Two-factor authentication adds a second verification step when you log in: a time-based code from an authenticator app. Even if your password is compromised, your account stays protected. For password changes and other account settings, see Your Profile & Account.

Setting up 2FA

Security settings with the Set up two-factor authentication button
Security settings with the Set up two-factor authentication button
2FA setup: scan the QR code with an authenticator app, then enter the 6-digit code to verify and enable
2FA setup: scan the QR code with an authenticator app, then enter the 6-digit code to verify and enable
  1. Go to Settings → Security → Two-factor authentication
  2. Click Enable 2FA
  3. Open an authenticator app on your phone (Google Authenticator, Authy, 1Password, or any TOTP-compatible app)
  4. Scan the QR code shown in MentorStack
  5. Enter the 6-digit code from your authenticator app to confirm setup
  6. Save your backup codes in a safe place: you'll need them if you lose access to your device

Once enabled, you'll be prompted for a code each time you log in.

Backup codes

During setup, MentorStack generates 8 one-time backup codes. Each code can only be used once. Store them somewhere secure (a password manager, printed sheet, or encrypted notes file).

If you lose your authenticator device and don't have backup codes, contact your admin or MentorStack support to verify your identity and reset 2FA.

Generating new backup codes

If you've used most of your backup codes or suspect they've been exposed:

  1. Go to Settings → Security → Two-factor authentication
  2. Click Regenerate backup codes

The old codes are immediately invalidated.

Disabling 2FA

  1. Go to Settings → Security → Two-factor authentication
  2. Click Disable 2FA
  3. Confirm with your current authenticator code

Note

If your organization has enforced 2FA for all members, you cannot disable it yourself. Contact your admin if you need an exception.

Organization-enforced 2FA (admins)

Admins can require 2FA for all members in their organization:

  1. Go to Settings → Security
  2. Toggle Require 2FA for all members

Members who haven't set up 2FA will be prompted to do so on their next login. They won't be able to access the platform until 2FA is configured. For broader sign-in controls, admins can also configure Single Sign-On (SSO).