Two-factor authentication
Add an authenticator app to your account, and keep your recovery codes somewhere you can reach them.
Last updated
Two-factor authentication adds a six-digit code from an authenticator app to your sign-in. It is optional, but your account holds valuations and contract terms for your own book, so it is worth the two minutes.
Everything here lives under Settings → Security, reached from the circular button with your initials at the bottom of the sidebar.
What you need
An authenticator app on your phone or laptop — any TOTP app works. If you do not already use one, your organisation may have a preference; ask before installing something.
Turning it on
The enrolment wizard has four steps and cannot be part-completed: if you close it before the end, nothing is enrolled and you start again.
- Verify Your Identity. Re-enter your account password. This is the standard guard against someone enrolling a factor on a session you left open.
- Set Up Authenticator App. Scan the QR code with your authenticator app. If you cannot scan — a desktop app, or a phone camera that will not focus — the same screen shows the secret key as text to type in instead.
- Verify Code. Type the six-digit code your app is showing. This proves the app and the portal agree before the portal starts relying on it.
- Save Recovery Codes. The portal generates eight recovery codes and shows them once. Save them now — see below.
Once complete, the status card on the Security page reads Your account is protected with two-factor authentication. and shows an Active badge.
Recovery codes
The eight recovery codes are shown once, at the end of enrolment. They are the only way back into your account if you lose access to your authenticator app. Save them before you close that screen.
Keep them somewhere you can reach without your phone — a password manager, or your organisation’s credential store. Not a note on the phone that holds the authenticator.
Each code works once and is consumed when used. Signing in with one does not turn two-factor authentication off; your authenticator stays enrolled.
Keeping track of them
The Security page shows a Recovery Codes card reading {n} of {total} codes remaining, with a bar that runs green, then amber, then red as you use them. At two or fewer remaining it warns: You’re running low on recovery codes. Consider generating new ones.
If you have never generated any, the card reads No recovery codes have been generated. Generate codes to ensure you can access your account if you lose your authenticator device or don’t have it with you.
Generating a new set
Use the generate option on the Recovery Codes card. The portal asks you to confirm first, because generating a new set invalidates every code from the previous one — including any you have written down. Save the new set the same way.
Signing in with two-factor on
After your email and password, the portal asks for the current six-digit code. If you cannot reach your authenticator, use the Lost your authenticator? Use a recovery code link. Both paths are covered in Signing in.
Turning it off
Remove the enrolled factor from the same Security page. You will be asked to confirm your identity first — your password, and a current six-digit code. If you signed in or confirmed something within the last fifteen minutes, the portal skips that prompt.
If you did not enable it
When a second factor is added to an account, Barkr emails the account holder. If that email reaches you and it was not you who enrolled, the message contains a link that removes the enrolment. Use it, change your password, and let Barkr know — see Contacting support.