Changelog/Two-Factor Authentication (2FA)
v2.8.0feature

Two-Factor Authentication (2FA)

LetRetro now supports two-factor authentication (2FA) for everyone — an optional extra layer of security that keeps your account safe even if your password is ever compromised.

How it works

  • Authenticator app support — Set up 2FA with any TOTP authenticator app you already use: Google Authenticator, Authy, 1Password, and others
  • Works alongside password sign-in — Sign in with your email and password as usual, then confirm with a 6-digit code from your authenticator app
  • Optional, per user — Each user chooses whether to enable 2FA on their own account. No workspace-wide configuration required
  • Server-side enforcement — Workspaces that require it can enforce 2FA at the workspace level, with new members prompted to enroll before they get in

How to enable it

Enabling 2FA takes less than a minute:

  1. Go to your Settings and open the Security section
  2. Click Set up authenticator app
  3. Scan the QR code with your authenticator app and enter the 6-digit code to confirm
  4. Done — you'll be asked for a code on your next sign-in

If you ever lose access to your authenticator app, you can remove 2FA from a verified session and re-enroll.

What's next

We're adding backup codes and SMS-based two-factor options for teams that prefer not to rely on an authenticator app.