Two-Factor Authentication
Two-factor authentication (2FA) adds a second step to your login. After your password, Hostim asks for a six-digit code from an authenticator app on your phone. A stolen password alone is then not enough to reach your projects.
Hostim uses TOTP, the standard supported by most authenticator apps: Google Authenticator, Microsoft Authenticator, Aegis, 2FAS, 1Password, Bitwarden, and others.
Turning it on
- Open your Security settings.
- Click Enable two-factor authentication.
- Enter your account password.
- Scan the QR code with your authenticator app. If you cannot scan it, copy the key shown under the code and enter it in the app by hand.
- Type the six-digit code the app shows and click Verify.
Hostim then shows your recovery codes. Save them before you close the window.
Recovery codes
You get ten recovery codes. Each one works once. They are your way back in when you lose access to the authenticator app.
The codes are shown only once, right after you turn 2FA on. Hostim stores
them hashed and cannot show them to you again. You can download them as a .txt
file from the same window.
Keep the codes somewhere other than the phone that holds your authenticator app. If you lose the phone, both would be gone at the same time.
To replace them, click Regenerate recovery codes in your Security settings. This asks for your password and a current authentication code. All ten old codes stop working immediately.
Logging in with 2FA
- Enter your email and password as usual.
- On the next screen, enter the six-digit code from your authenticator app.
If you do not have the app with you, click Use a recovery code instead and enter one of your recovery codes. That code is then used up.
You have to finish the second step within five minutes. After that, start the login again.
When your password or codes are asked for
| Action | Password | Authentication code |
|---|---|---|
| Turn 2FA on | Yes | Yes |
| Turn 2FA off | Yes | Yes |
| Regenerate recovery codes | Yes | Yes |
| Change your password | Yes (the old one) | Yes |
A recovery code is accepted at login only. Turning 2FA off, changing your password, and regenerating codes all need a current code from the authenticator app.
If you signed up with GitHub or Google and never set a password, the password step is skipped.
Too many wrong codes
After five wrong codes in a row, the second step is locked for 15 minutes. Wait, then try again with a fresh code. Hostim also sends an email to your account address when this happens, so you notice if someone else is trying.
Codes change every 30 seconds. If your codes are always rejected, check that the clock on your phone is set automatically — a phone clock that runs a few minutes off produces codes Hostim will not accept.
Lost the authenticator and the recovery codes
Contact support at support@hostim.dev from the email address on the account. We have to confirm who you are before we can remove the second factor, so expect questions about your account, and expect this to take longer than a password reset. This is why the recovery codes are worth saving.