Skip to main content

Two-factor authentication

Turn on two-factor in User Settings and Spiich emails a six-digit code after your password every time you log in. Admins can require it for everyone. Google sign-in is never asked for a code.

Two-factor authentication in Spiich is an emailed six-digit code asked for after your password. Each member can turn it on for themselves, and an admin can require it across the whole workspace.

There is no authenticator app, no SMS and no recovery codes. The code goes to the email address you sign in with, so make sure you can reach that mailbox before you turn it on.

Turn it on for yourself

  1. Open User Settings

    Click Settings in the sidebar, then User Settings.

  2. Find the security section

    Scroll to Two-factor authentication.

  3. Turn on the switch

    Switch on Require a code at login. The caption confirms what happens: Spiich emails you a six-digit code after your password.

Nothing changes until your next sign-in. From then on, after the password step you land on a screen headed One more step and Check your email, with a Verification code box, a Verify button, a Send a new code link and Back to log in.

Require it for everyone

Open Settings > User Management, find the Two-factor authentication card above the Members list, and switch on Require for all members. You should see Two-factor authentication is now required. Everyone is asked for an emailed code the next time they log in with a password.

The policy is a floor, not an override. While it is on, members cannot turn the switch off for themselves and their card explains that the workspace admin requires it. Turning the policy back off leaves each member's own opt-in exactly as they set it, so the people who chose it keep it.

What the code screen does

  • The code is six digits and expires ten minutes after it is sent.
  • You can get it wrong at most five times. After that the sign-in attempt is dead and you start again from Back to log in.
  • You can request at most three fresh codes per sign-in attempt, with a thirty-second wait between sends.
  • An account can start at most five code-requiring sign-in attempts in an hour.

Why Google sign-in is not asked for a code

If you sign in with Continue with Google, Spiich never asks you for a code, even when the workspace requires two-factor. This is deliberate. The code would be delivered to the same mailbox Google has already verified, so it would add a step without adding a factor.

If you want a second step on a Google account, use your Google account's own two-factor settings. Those apply at the Google consent stage, before Spiich sees you at all. Alternatively, sign in with email and password so the Spiich code applies.

Limits

  • Email is the only delivery channel. There is no authenticator app, no SMS and no set of one-time recovery codes.
  • The second factor applies to password sign-in only.
  • A workspace admin can require it, but nobody can require it for one individual: the policy is workspace-wide or nothing.
  • Turning the workspace policy off does not turn anybody's personal setting off.
  • Your Spiich password itself must be 10 to 128 characters and contain at least one uppercase and one lowercase letter. Change it in Settings > User Settings, covered in Your profile and preferences.

If something goes wrong

  • The switch is on and greyed out. An admin has turned on Require for all members, which nobody can opt out of individually. The card says so. If it genuinely needs to change, an admin turns the policy off in Settings > User Management.
  • The code never arrives. Check spam. Wait for the thirty-second cooldown and click Send a new code. If the attempt is exhausted, click Back to log in and start the sign-in again.
  • The code is rejected. Either it expired after ten minutes or it was mistyped. Use the code from the most recent email.
  • You are locked out of the mailbox itself. The code cannot be sent anywhere else. Contact Spiich, or see Login problems.

Frequently asked questions

Not today. The second factor is a six-digit code emailed to the address you sign in with. There are no TOTP authenticator apps, no SMS codes and no downloadable recovery codes, so keep access to that mailbox.