Two-Factor Authentication

Add TOTP-based 2FA to your account using Google Authenticator, 1Password, Authy, or any RFC 6238 app.

Why 2FA matters

Signalog accounts have access to monitor configuration, alert routing, billing, and team membership. Anyone who compromises an account can disable monitors, redirect alerts, or worse. Two-factor authentication adds a second layer that a stolen password alone can’t bypass.

We support standard TOTP (Time-based One-Time Password, RFC 6238). Any authenticator app works:

  • Google Authenticator
  • 1Password
  • Bitwarden
  • Authy
  • Microsoft Authenticator

2FA is available on every plan. Not a paid feature.

Setup

Step 1: Open Profile → Security

From the user menu (top right), click Profile, then the Security tab.

Step 2: Generate a TOTP secret

Click Enable 2FA: signalog generates a TOTP secret and displays:

  • QR code: scan with your authenticator app
  • Manual code: type-able backup if you can’t scan

Most apps will scan the QR code; tap the + in your app and scan.

Step 3: Verify with a code

Your app now shows a 6-digit code that rotates every 30 seconds. Enter the current code in Signalog and click Verify and enable.

If the code is wrong, your device clock might be out of sync with the server (TOTP relies on time agreement). Sync your device clock and try again.

Step 4: Save your recovery codes

After successful verification, Signalog generates 8 recovery codes. Save these now: you can’t view them again.

Print them, store them in a password manager, or save them in a secure note. Each code is a one-time-use bypass for 2FA. Useful when you’ve lost your phone or your authenticator app is broken.

Signing in with 2FA

After 2FA is enabled, the login flow has an extra step:

  1. Enter email + password as usual
  2. Signalog sends back a temp token (not a full session)
  3. The login UI prompts for your 6-digit code
  4. Enter the code (or use a recovery code) → full session is issued

Recovery codes are accepted in the same input. Signalog detects the format and handles them differently. Each recovery code can only be used once; after use, it’s revoked.

Disabling 2FA

If you need to remove 2FA (changing devices, troubleshooting):

  1. Profile → Security
  2. Click Disable 2FA
  3. Enter your current 6-digit code or a recovery code to confirm

Disabling 2FA invalidates all your existing recovery codes. If you re-enable later, you’ll get a fresh set.

Lost your phone? Use a recovery code

  1. On the login page, enter email + password as usual
  2. At the 2FA prompt, click Use recovery code
  3. Enter one of the 8 codes you saved during setup
  4. After login, immediately disable + re-enable 2FA on your new device, and save the new recovery codes

Lost your phone AND your recovery codes?

You’re in account-recovery territory:

  1. Contact a team owner. They can remove you from the team and re-invite you with a fresh password
  2. If you’re the only owner, contact Signalog support. We’ll require identity verification before disabling 2FA on your account

We deliberately don’t have a “self-serve, just send me an email” recovery flow because that’s exactly what attackers exploit.

2FA + SSO

If you sign in via SSO (Business plan), the IdP handles 2FA. Signalog doesn’t add a second layer. Configure 2FA enforcement in your IdP (Okta, Google Workspace, Azure AD all support this).

If you’re on a team that allows both password and SSO login, 2FA on the password path is independent. Turning it on only affects email/password sign-ins.

What 2FA protects

  • Email + password login
  • Magic link login (the magic link itself is single-use, but 2FA still applies)
  • Disabling 2FA itself (you need a code to disable it)

What 2FA doesn’t protect

  • SSO logins (handled by the IdP)
  • API key authentication (use IP-restricted keys for that protection layer)
  • Active sessions you’re already logged into (2FA only applies at login)

Per-team 2FA enforcement (roadmap)

We don’t yet have a “require all members of this team to have 2FA” enforcement toggle. It’s on the roadmap. For now, encourage your team to enable 2FA. The audit log shows which users have it on so you can audit periodically.

Compliance note

For SOC2 or similar frameworks that require 2FA for production access, our 2FA implementation:

  • Uses RFC 6238 TOTP (industry standard)
  • Stores secrets encrypted at rest
  • Provides recovery codes (one-time use, hashed at rest)
  • Logs all 2FA events to the audit log (user.2fa.enabled, user.2fa.disabled, user.2fa.recovery_used)

This generally satisfies framework requirements; check with your auditor for specifics.

Next steps