Two-factor authentication (2FA) adds an extra layer of security to your account. In addition to your password, you will need a temporary verification code from an authentication app when logging in. This means that a stolen or leaked password alone is not enough to access your account.

Why is two-factor authentication important?

An invoicing account may contain company, customer and financial data. A strong and unique password remains essential, but passwords can be compromised through phishing, password reuse or a data breach involving another service. Two-factor authentication therefore adds a second verification step:

  • Step 1 – your password: something only you should know.
  • Step 2 – your verification code: a temporary code generated by an authentication app on your device.

Even if someone knows your password, they cannot log in without the temporary verification code.

Important: two-factor authentication is one part of a broader security strategy. It does not replace a strong password, careful user management, secure devices or a separate backup procedure.


Activating two-factor authentication

1. Open the user settings

Log in and navigate to the user settings via the menu in the top-right corner.

Opening the user menu via the email address

2. Start the setup

Click Activate two-factor authentication.

The button for activating two-factor authentication

3. Connect an authentication app

Install an authentication app, such as Google Authenticator, Microsoft Authenticator, Authy or a similar app. Then scan the QR code displayed on the screen.

Scanning a QR code with an authentication app

4. Confirm the verification code

Enter the temporary code from your authentication app and confirm the activation. The next time you log in, you will be asked to enter a verification code after entering your password.


Recommended practices for organisations

Is access security important to your management, internal control team, auditor or a government authority? Include at least the following measures in your organisation’s security procedure:

  • Activate two-factor authentication for every user who has access to the account.
  • Use a separate account for each employee.
  • Do not share passwords, QR codes, verification codes, activation links, password reset links or similar confidential information.
  • Use a strong and unique password, preferably stored in a trusted password manager.
  • Regularly review which users have access.
  • Remove access as soon as a user no longer requires it.
  • Secure the email account and the device used to log in.
  • Define internally who is responsible for user management and for reporting potential security incidents.

Disabling two-factor authentication

You can disable two-factor authentication from the user page. Only do this when necessary and reactivate the security feature as soon as possible.

No longer have access to your authentication app? Please contact our support team.

Need more information? Read the useful articles below