Skip to content

Two-factor authentication

Tidehawk requires every member to hold a second factor. You can use a passkey or an authenticator app.

The first time you sign in without one, Tidehawk shows the Secure your account page. It says “Multi-factor authentication is required to continue” and offers two choices: Set up a passkey, which is the recommended option, or Use an authenticator app instead. There is no skip. Until you complete one of them, every page and every API call is redirected back to this screen. The only other option on the page is to sign out.

Once you finish, Tidehawk shows your recovery codes and then lets you into the app.

  1. Open Settings and go to the Security section.
  2. Select Set up 2FA.
  3. Scan the QR code with Google Authenticator, Authy, 1Password or a similar app. If you cannot scan, open Can’t scan? Enter code manually and type the secret in.
  4. Enter the 6-digit code and select Enable 2FA.

The Security section then reads “Two-factor authentication is enabled”. Your Team page entry shows 2FA ✓.

Your authenticator secret is encrypted before it is stored, and it is never included in a data export.

Recovery codes let you sign in if you lose your passkey or authenticator.

  • Tidehawk generates 10 codes. Each works once.
  • They are shown once, at the moment they are generated. Save them somewhere safe.
  • Settings → Security → Recovery codes shows how many you have left.
  • Regenerate codes issues a new set and invalidates every previous code.

To use one, start signing in with your email and password, then choose Lost your passkey? Use a recovery code and enter it.

Select Disable in the Security section and confirm with your password. You will be asked to add a second factor again on your next sign-in, because a second factor is mandatory.

Require two-factor authentication workspace-wide

Section titled “Require two-factor authentication workspace-wide”

Owners can enforce enrolment across the whole workspace.

  1. Open Settings → Security → Workspace 2FA.
  2. Select Turn on next to Require 2FA for everyone in this workspace.
  3. Confirm in the Require 2FA for everyone? dialog.

Admins and technicians see the same panel but cannot change it. It is marked Owner-only.

The panel records who turned it on and when. The member roster below it shows Member enrolment (X of Y enrolled) and lists each person as ✓ enrolled or not enrolled.

Current sessions are not interrupted. A member without an authenticator app is walked through enrolment the next time they sign in with a password, and no session is issued until they finish. A registered passkey does not satisfy this particular check, so passkey holders should sign in with Sign in with passkey rather than the password form.

Turning the setting off relaxes the policy immediately and needs no confirmation.