Two-factor authentication (2FA) adds an extra layer of security to your account. In addition to your password, you will need a temporary verification code from an authentication app when logging in. This means that a stolen or leaked password alone is not enough to access your account.
Why is two-factor authentication important?
An invoicing account may contain company, customer and financial data. A strong and unique password remains essential, but passwords can be compromised through phishing, password reuse or a data breach involving another service. Two-factor authentication therefore adds a second verification step:
- Step 1 – your password: something only you should know.
- Step 2 – your verification code: a temporary code generated by an authentication app on your device.
Even if someone knows your password, they cannot log in without the temporary verification code.
Important: two-factor authentication is one part of a broader security strategy. It does not replace a strong password, careful user management, secure devices or a separate backup procedure.
Activating two-factor authentication
1. Open the user settings
Log in and navigate to the user settings via the menu in the top-right corner.

2. Start the setup
Click Activate two-factor authentication.

3. Connect an authentication app
Install an authentication app, such as Google Authenticator, Microsoft Authenticator, Authy or a similar app. Then scan the QR code displayed on the screen.

4. Confirm the verification code
Enter the temporary code from your authentication app and confirm the activation. The next time you log in, you will be asked to enter a verification code after entering your password.
Recommended practices for organisations
Is access security important to your management, internal control team, auditor or a government authority? Include at least the following measures in your organisation’s security procedure:
- Activate two-factor authentication for every user who has access to the account.
- Use a separate account for each employee.
- Do not share passwords, QR codes, verification codes, activation links, password reset links or similar confidential information.
- Use a strong and unique password, preferably stored in a trusted password manager.
- Regularly review which users have access.
- Remove access as soon as a user no longer requires it.
- Secure the email account and the device used to log in.
- Define internally who is responsible for user management and for reporting potential security incidents.
Disabling two-factor authentication
You can disable two-factor authentication from the user page. Only do this when necessary and reactivate the security feature as soon as possible.
No longer have access to your authentication app? Please contact our support team.