-
Notifications
You must be signed in to change notification settings - Fork 0
Two Factor Login
Groundskeeper can ask for a second step when you sign in: a six-digit code from an authenticator app on your phone (Microsoft Authenticator, Google Authenticator, Authy, 1Password and the like all work). It uses the same standard those apps use for every other site, so nothing extra is installed anywhere. It is per person and optional.
- Sign in, open Settings -> Users, and find the Two-factor sign-in card.
- Click Set up two-factor sign-in. A QR code appears. Scan it with your authenticator app, or type the secret shown beside it into the app by hand.
- Enter the six-digit code the app now shows and click Turn on.
- Save the eight recovery codes shown next. They appear once. Any one of them signs you in if you lose your phone, and each works only once.
From then on, signing in asks for your password, then for the current code from the app (or one of your recovery codes).
On the same card, open Turn off two-factor sign-in and enter your password and a current code. Both are needed on purpose, so a sign-in left open on a desk cannot remove it.
Use one of your recovery codes to sign in, then turn two-factor off and set it up again on the new phone. If you have no recovery codes left, an administrator can clear your two-factor from Settings -> Users with the Reset 2FA button beside your name; you then sign in with your password alone and set it up again.
- Two-factor needs named user accounts. An install still on the original shared admin password is asked to migrate to named accounts first (also under Settings -> Users).
- Codes depend on the phone's clock being roughly right (within a minute). If codes are refused, check the phone's time is set automatically.
- The QR code is generated on your Groundskeeper server; the secret never leaves it except to your phone.
Last updated: 2026-09-03 (v0.127.0)