Two-factor sign-in

Ask for a code from an authenticator app as well as the password, and what to do if you lose your phone.

Two-factor means your password alone is not enough. You also type a six-digit code from an authenticator app on your phone. The code changes every 30 seconds and exists only on that phone.

It stops the most common way accounts are taken over: someone has your password, because it was reused somewhere else, guessed or phished. Without your phone they get nowhere.

Two-factor is part of Pro. Once you have turned it on you keep it, even if Pro ends.

Turning it on

  1. Install an authenticator app on your phone. Google Authenticator and Microsoft Authenticator are the most common, and password managers like 1Password and Bitwarden can do the job too.
  2. Go to Account → Profile → Two-factor and choose Turn on two-factor.
  3. Open the app, tap +, choose Scan a QR code, and scan the code on screen. Scan with the authenticator app, not with your phone's camera: the camera cannot open the code and only shows a blank page.
  4. Enter the six digits the app shows.
  5. Keep the recovery codes you are given. They are shown this once.

If you cannot scan, choose Enter a setup key in the app and type the key printed beside the QR code.

The recovery codes

You get ten recovery codes when you turn two-factor on. Each works once, and they are the only way in if the phone goes missing.

Put them somewhere you can find them without the phone: in your password manager, in the notes field of the entry for wegotfiles.com, or on paper in a drawer. Not only on the phone — that is the thing you need the codes for if you lose it.

If you have used them up, or lost them, make new ones under Account → Profile → Two-factor → Make new recovery codes. The old ones then stop working.

Remember this device

When you enter the code you can tick a box to have the browser remembered for 30 days, 3 months, 6 months or 1 year. Your password alone then signs you in on that machine, while every other machine still asks for a code.

Only do it on a machine that is your own. On a borrowed or shared PC, leave it alone.

To undo it, choose Forget all remembered devices under Account → Profile → Two-factor. The next sign-in asks for a code everywhere. The same happens by itself when you change your password.

More than one device

You can register up to three authenticator apps. With both a phone and a tablet, one lost phone is no longer a problem. Choose Add another device and scan a new code.

If you lose your phone

  1. Sign in with your password, and choose Lost your phone? Use a recovery code when the code is asked for.
  2. Enter one of the recovery codes. Two-factor is then turned off, so a phone you no longer have cannot lock you out.
  3. Set it up again straight away, on the new phone.

If you have neither the phone nor the recovery codes, write to support@wegotfiles.com. We can reset two-factor on your account, but only once we have confirmed that it really is you asking. You get an email when it happens.

For companies: require it of everyone

If you own a workspace, you can require two-factor of everyone in it. The switch is under Account → Identity.

  • You need two-factor on your own account first.
  • We show how many in the workspace already have it before you turn it on.
  • Those without it are asked to set it up at their next sign-in and get no further until they have.
  • They cannot turn it off while the requirement stands.

Requiring two-factor of others

If you have a shared folder, you can require two-factor of the people who open its share link. In the folder options, Access → Who can open the link, you choose between anyone with the link, must be signed in, and must be signed in with two-factor. You need two-factor yourself for the last one. Whoever opens the link then needs Pro as well.

The same can be required of everyone in a workspace; see the section above.

Signing in with Google or Microsoft

Two-factor applies there too. You are asked for the code afterwards, exactly as with a password.

What we do on our side

  • No half-finished sign-in: your session is created only once the code is accepted. Until then you are not signed in anywhere in the service.
  • Five wrong codes, and the password has to be typed again.
  • You get an email when two-factor is turned on, turned off, when a recovery code is used, and if we reset it for you.
  • Changing your password, or asking for a new one after "forgot password", forgets every remembered device.