Overview
Two-factor authentication (2FA) adds an extra layer of security to your Vault account. When enabled, you’ll need your master password AND a verification code from your phone to log in.
Why Enable 2FA
Even if someone discovers your master password, they can’t access your vault without also having your phone. This protects against:
- Phishing attacks
- Password theft
- Compromised devices
Supported 2FA Methods
Vault supports these authentication methods:
| Method | Security Level | Recommended For |
|---|---|---|
| Authenticator app | High | Everyone |
| Medium | Basic protection | |
| Hardware key (FIDO2) | Highest | High-security users |
Setting Up Authenticator App
- Download an authenticator app:
- Google Authenticator
- Authy
- Microsoft Authenticator
- 1Password
- In Vault, go to Settings > Security > Two-step Login
- Click Manage next to Authenticator App
- Scan the QR code with your app
- Enter the 6-digit code to verify
- Save your recovery code - store it securely offline
Setting Up Hardware Key
- Go to Settings > Security > Two-step Login
- Click Manage next to FIDO2 WebAuthn
- Insert your hardware key (YubiKey, etc.)
- Follow the prompts to register the key
- Name your key for easy identification
Recovery Codes
When you enable 2FA, you receive a recovery code. This is essential:
- Write it down on paper (not digitally)
- Store it securely - safe, lockbox
- It’s your only backup if you lose your phone
To view your recovery code:
- Go to Settings > Security > Two-step Login
- Click View Recovery Code
- Enter your master password
Logging In with 2FA
- Enter your email and master password
- When prompted, open your authenticator app
- Enter the current 6-digit code
- (Optional) Check “Remember this device” on trusted computers
Lost Your Phone?
If you lose access to your authenticator:
- Use your recovery code to log in
- Go to Settings > Security > Two-step Login
- Disable the old authenticator
- Set up 2FA again with your new device
No recovery code? Contact support@heimlane.com with account verification.
Tips
- Set up 2FA on a new device BEFORE wiping your old phone
- Use an authenticator app that supports cloud backup (like Authy)
- Consider registering a backup hardware key
- Never share your 2FA codes with anyone
