# Two-factor authentication

> Turn on two-factor in User Settings and Spiich emails a six-digit code after your password every time you log in. Admins can require it for everyone. Google sign-in is never asked for a code.

- Source: https://spiich.ai/help/workspace/two-factor-authentication
- Section: Workspace and account
- Who can do this: Everyone
- Time: 2 minutes
- Last updated: 2026-08-24

Two-factor authentication in Spiich is an emailed six-digit code asked for after your password. Each member can turn it on for themselves, and an admin can require it across the whole workspace.

There is no authenticator app, no SMS and no recovery codes. The code goes to the email address you sign in with, so make sure you can reach that mailbox before you turn it on.

## Turn it on for yourself

1. **Open User Settings**
   Click `Settings` in the sidebar, then `User Settings`.

2. **Find the security section**
   Scroll to `Two-factor authentication`.

3. **Turn on the switch**
   Switch on `Require a code at login`. The caption confirms what happens: Spiich emails you a six-digit code after your password.

Nothing changes until your next sign-in. From then on, after the password step you land on a screen headed `One more step` and `Check your email`, with a `Verification code` box, a `Verify` button, a `Send a new code` link and `Back to log in`.

## Require it for everyone

> **Admin only:** Only workspace admins can set the policy, from [`Settings > User Management`](https://app.spiich.ai/settings/user-management).

Open `Settings > User Management`, find the `Two-factor authentication` card above the Members list, and switch on `Require for all members`. You should see `Two-factor authentication is now required`. Everyone is asked for an emailed code the next time they log in with a password.

The policy is a floor, not an override. While it is on, members cannot turn the switch off for themselves and their card explains that the workspace admin requires it. Turning the policy back off leaves each member's own opt-in exactly as they set it, so the people who chose it keep it.

## What the code screen does

- The code is six digits and expires ten minutes after it is sent.
- You can get it wrong at most five times. After that the sign-in attempt is dead and you start again from `Back to log in`.
- You can request at most three fresh codes per sign-in attempt, with a thirty-second wait between sends.
- An account can start at most five code-requiring sign-in attempts in an hour.

> **Note:** The code email is one of a small number of transactional emails Spiich sends. If it is not in your inbox within a minute, check spam before requesting another.

## Why Google sign-in is not asked for a code

If you sign in with `Continue with Google`, Spiich never asks you for a code, even when the workspace requires two-factor. This is deliberate. The code would be delivered to the same mailbox Google has already verified, so it would add a step without adding a factor.

If you want a second step on a Google account, use your Google account's own two-factor settings. Those apply at the Google consent stage, before Spiich sees you at all. Alternatively, sign in with email and password so the Spiich code applies.

## Limits

- Email is the only delivery channel. There is no authenticator app, no SMS and no set of one-time recovery codes.
- The second factor applies to password sign-in only.
- A workspace admin can require it, but nobody can require it for one individual: the policy is workspace-wide or nothing.
- Turning the workspace policy off does not turn anybody's personal setting off.
- Your Spiich password itself must be 10 to 128 characters and contain at least one uppercase and one lowercase letter. Change it in [`Settings > User Settings`](https://app.spiich.ai/settings/user), covered in [Your profile and preferences](/help/workspace/your-profile-and-preferences).

## If something goes wrong

- **The switch is on and greyed out.** An admin has turned on `Require for all members`, which nobody can opt out of individually. The card says so. If it genuinely needs to change, an admin turns the policy off in `Settings > User Management`.
- **The code never arrives.** Check spam. Wait for the thirty-second cooldown and click `Send a new code`. If the attempt is exhausted, click `Back to log in` and start the sign-in again.
- **The code is rejected.** Either it expired after ten minutes or it was mistyped. Use the code from the most recent email.
- **You are locked out of the mailbox itself.** The code cannot be sent anywhere else. Contact Spiich, or see [Login problems](/help/troubleshooting/login-problems).

## Frequently asked questions

### Does Spiich support an authenticator app or SMS codes?

Not today. The second factor is a six-digit code emailed to the address you sign in with. There are no TOTP authenticator apps, no SMS codes and no downloadable recovery codes, so keep access to that mailbox.

### If my admin requires two-factor, does that apply to Google sign-in too?

No. The workspace policy applies to password sign-in. People signing in with Google are never asked for a Spiich code, because the code would go to the mailbox Google already verified. Enforce a second factor on those accounts through your Google Workspace policy instead.

### What happens if I turn the workspace requirement back off?

Members who had turned two-factor on for themselves keep it. Only the requirement goes away, so people who never opted in stop being challenged and everyone else carries on unchanged.

### Can I be locked out permanently by wrong codes?

No. Five wrong codes ends that particular sign-in attempt, not your account. Click `Back to log in` and start again. An account is limited to five code-requiring sign-in attempts per hour, so a burst of failed attempts means waiting rather than losing the account.

## Related

- [You cannot sign in](https://spiich.ai/help/troubleshooting/login-problems)
- [Manage teammates and roles](https://spiich.ai/help/workspace/manage-your-team)
- [Your profile and preferences](https://spiich.ai/help/workspace/your-profile-and-preferences)
- [Trust and security](https://spiich.ai/trust)
