v2.8.0feature
Two-Factor Authentication (2FA)
LetRetro now supports two-factor authentication (2FA) for everyone — an optional extra layer of security that keeps your account safe even if your password is ever compromised.
How it works
- Authenticator app support — Set up 2FA with any TOTP authenticator app you already use: Google Authenticator, Authy, 1Password, and others
- Works alongside password sign-in — Sign in with your email and password as usual, then confirm with a 6-digit code from your authenticator app
- Optional, per user — Each user chooses whether to enable 2FA on their own account. No workspace-wide configuration required
- Server-side enforcement — Workspaces that require it can enforce 2FA at the workspace level, with new members prompted to enroll before they get in
How to enable it
Enabling 2FA takes less than a minute:
- Go to your Settings and open the Security section
- Click Set up authenticator app
- Scan the QR code with your authenticator app and enter the 6-digit code to confirm
- Done — you'll be asked for a code on your next sign-in
If you ever lose access to your authenticator app, you can remove 2FA from a verified session and re-enroll.
What's next
We're adding backup codes and SMS-based two-factor options for teams that prefer not to rely on an authenticator app.