What is Two-Factor Authentication?
Two-factor authentication (2FA) adds an extra layer of security to your account. In addition to your password, you will enter a one-time code from an app on your phone when logging in.
How to Enable 2FA
Go to Settings → My Account
In the Two-Factor Authentication section, click Enable 2FA
Scan the QR code using an authenticator app (e.g., Google Authenticator, Authy, Microsoft Authenticator)
Enter the 6-digit code from the app to confirm
Save your backup codes in a safe place
Backup Codes
After enabling 2FA, you will receive 10 backup codes. Each code can only be used once instead of a code from the app – for example, when you do not have access to your phone.
Important: Save your backup codes in a safe place. You will not see them again after closing the window. If you run out, you can generate new ones in your account settings.
Logging in with 2FA
Enter your email and password as usual
Open your authenticator app and enter the current 6-digit code
If you do not have access to the app, use one of your backup codes
Disabling 2FA
You can disable 2FA in Settings → My Account. You will need to enter a code from the app to confirm.
Note: If your company requires 2FA, the disable button will not be available.
Enforcing 2FA for the Entire Company
Administrators can require all users in the company to have 2FA enabled.
How to Enable 2FA Enforcement
Go to Settings → Security
Select the Grace Period – the time users have to set up 2FA
Click Enable Requirement
Grace Period
After enabling the requirement, users have a set time (e.g., 7 or 14 days) to activate 2FA. During this period:
Users will see a notification on the dashboard with the activation deadline
They can work normally in the application
After the Grace Period Expires
Users without active 2FA will be redirected to the 2FA setup page after logging in. They cannot continue to the application without activation.
Disabling the Requirement
You can disable the 2FA requirement at any time in Settings → Security. Users who already have 2FA enabled can keep it or disable it.
RECOMMENDATION
In Retino, you don't pay per user, so feel free to create a separate login for each team member under their own email — it won't cost you anything extra.
Why do we recommend this? If you enable two-factor authentication, each account gets its own unique access code. When multiple people share a single email login, they'd have to pass this code around to each other, which is impractical and less secure.
Tip: Set up an individual account for every team member. You'll have a better overview of who's doing what in Retino, and 2FA will work smoothly.
