fusialDocs

How does two-factor authentication (2FA) work?

Fusial supports 2FA with either an authenticator app (TOTP) or a one-time code sent to email. Any user can enable 2FA on their own account, and organization owners can require it for every member and choose which methods are allowed. This page covers personal setup, the owner-level requirement, trusted devices, and recovery.

Fusial supports two-factor authentication two ways:

  • Authenticator app (TOTP). A six-digit code from an app like 1Password, Google Authenticator, or Authy. Recommended.
  • Email one-time code (OTP). A six-digit code emailed to you at sign-in.

There are two ways 2FA gets turned on:

  • Personal opt-in. Any user — including organization members and outside collaborators — can enable 2FA on their own account at any time.
  • Organization-wide requirement. An owner can require 2FA for every member of the organization. When that's on, anyone without 2FA already enabled is forced to set it up the next time they sign in.

Which authenticator apps work

Any standard TOTP app. When you scan the QR code, the app saves the entry as Fusial. Common choices:

  • 1Password — stores the TOTP alongside your Fusial password.
  • Bitwarden — same idea, free tier supported.
  • Google Authenticator
  • Authy
  • Microsoft Authenticator
  • Duo Mobile

Avoid SMS-based 2FA — Fusial doesn't support it, and it's significantly less secure than TOTP.

Enabling 2FA on your own account

You can turn on 2FA for your personal account whether or not your organization requires it.

  1. Sign in to Fusial.
  2. Go to Settings → Security.
  3. Turn on Two-factor authentication.
  4. Choose Authenticator app or Email.
    • Authenticator app: scan the QR code, or paste the secret manually if you can't scan. Enter the six-digit code from the app to confirm.
    • Email: Fusial sends a one-time code to your account email. Enter it to confirm.

From your next sign-in onward, you'll be asked for a code after entering your password (or completing Google sign-in).

Backup codes

When you enable 2FA, Fusial issues a set of one-time backup codes. Each code works once and lets you sign in if you can't use your normal 2FA method.

  • Save them immediately. Store them in your password manager, alongside your Fusial password. Don't leave them in the same place as your authenticator device.
  • Each code is one-time use. After you use one, cross it off.
  • You can regenerate the full set from Settings → Security at any time. Regenerating invalidates the previous set.

Backup codes are the only in-product recovery path if you lose access to your authenticator app. Fusial cannot reset another user's 2FA — not your teammates, not an admin, not the owner — so if you don't save your backup codes and your organization is configured for Authenticator app only, you can lock yourself out permanently. See Losing your authenticator device below.

Requiring 2FA for your organization (owner)

The owner can require 2FA for every member of the organization.

  1. Sign in as the owner.
  2. Go to Settings → Security.
  3. Turn on Require two-factor authentication.
  4. Choose which methods members are allowed to use:
    • Authenticator app and email (default) — members can pick either.
    • Authenticator app only — email OTP is disabled for this organization. Use this for stricter compliance regimes.
  5. Save.

Once required:

  • Members who already have personal 2FA enabled are unaffected — their existing setup keeps working (as long as the method they chose is still allowed).
  • Members without 2FA are sent to Settings → Security the next time they sign in and can't proceed until they finish enrolling.
  • New invitees go through enrollment as part of their first sign-in.

Trusted devices

After a successful 2FA challenge, you can mark the device as trusted. Trusted devices skip the 2FA prompt at sign-in for 30 days. After 30 days, you'll be challenged again and can re-trust the device.

Use this on devices that are physically secure and only used by you. Don't trust shared or kiosk machines.

You can revoke trusted devices from Settings → Security at any time. Revoking immediately forces a 2FA challenge on the next sign-in from that device.

If you sign in with Google

Google OAuth and Fusial's 2FA are independent. Even if your Google account already has its own 2FA, Fusial still asks for a Fusial 2FA code when you've enabled it on your account or when your organization requires it.

Losing your authenticator device

Fusial does not let owners or admins reset another user's 2FA — there is no "Reset 2FA" action on the Members page or anywhere else. Recovery is self-service only, in this order:

  1. Use a backup code. At the 2FA prompt, choose to enter a backup code instead. Each code works once. After you sign in, generate a fresh set from Settings → Security.
  2. Switch to email OTP. If your organization allows email codes (the default, Authenticator app and email) and you set up the email method, select Email at the sign-in prompt and Fusial sends a one-time code to your account email.
  3. Contact Fusial support. If you have no backup codes and your organization is configured for Authenticator app only, contact support. We can verify your identity and act on the account, but we cannot reset your 2FA — even Fusial staff don't have a 2FA-reset action. The realistic outcomes are limited.

To protect against this scenario:

  • Save your backup codes when you enable 2FA.
  • Enable both authenticator app and email OTP if your organization allows it.
  • Keep at least two owners or administrators on the organization wherever possible so a single lockout doesn't strand the whole team.

Disabling 2FA

  • On your own account. Turn 2FA off from Settings → Security. You'll be asked to re-enter your password to confirm. If your organization requires 2FA, the personal toggle is locked on and you can't disable it.
  • For the organization. The owner can turn off the organization-wide requirement from the same settings page where they enabled it. Members who turned on 2FA personally keep their personal setup; only the enforced requirement is lifted.

Disabling your own 2FA is recorded in your organization's audit log.

We recommend keeping 2FA on. It's the single most effective control against credential-based account takeover.