Skip to content

Matches page titles and page text. Forty pages, indexed at build time.

Multi-factor authentication

A six-digit code from an authenticator app. Optional and strongly encouraged for customers, mandatory for staff, and how an owner requires it for a whole organisation.

Two-factor authentication adds a six-digit code from an authenticator application to your password. It is the single highest-value control on an account that can delete a database.

It is optional for customer accounts and strongly encouraged. It is mandatory for Balta staff accounts, without exception.

Enrol

  1. Open Security in the sidebar, or take the offer during signup.
  2. Press Enrol now.
  3. The screen shows a Setup key and an Authenticator link. Both carry the same secret; use either one.
  4. Add it to your authenticator application.
  5. Type the current code into Code from your authenticator and submit.

Two-factor authentication is on once that code is accepted, and not before.

Open the enrolment screen only when you mean to finish it. Opening it issues a new secret at once and replaces the one your authenticator holds, even if you are already enrolled. If you leave without confirming a code, the codes your authenticator shows stop working the next time you sign in.

Enrol a second device at the same time

There are no recovery codes. The protection you have is a second copy of the secret.

While the Setup key is on screen, add it to a second authenticator on a different device, and keep that device somewhere other than the first. Do this during enrolment: the key is not shown again.

A copy in the same password manager as your password is a second factor with one factor.

Require it for an organisation

  1. Open Security → Organisation policy.
  2. Turn on Require two-factor authentication.
  3. Save. You are asked for your password again.

Only owners and administrators see this control. The change is recorded in the audit log.

The requirement is checked on every request, not only at sign-in. A member who has not enrolled is sent to enrolment on their next request, and until they finish, enrolment and signing out are the only things available. Sessions that already exist get no exemption. There is no grace period and no dismiss.

The requirement follows the person. If any organisation you belong to requires it, it applies to your whole session, whichever organisation you have open. That includes someone who has just accepted an invitation to that organisation.

How the codes work

Codes follow RFC 6238: six digits, and a new one every 30 seconds. The code from the step either side of the current one is also accepted, so a phone clock a few seconds out still works.

Each code works once. Entering a code that has already been accepted is refused, even inside its 30 seconds.

The authenticator code is the only second factor supported. Passkeys are not, and no code is sent by email or text message.

For staff

Mandatory, without exception. The rule is in the database as well as in the code: a staff session without a verified second factor fails a constraint, and a staff route that tried to skip the check would stop the control plane from starting. Staff sessions last eight hours and cannot be extended.

What you will see

After enrolment, signing in takes your password and then the current code, on a screen headed "One more step." The field is Authentication code.

A wrong code gets the same answer as a wrong password.

Troubleshooting

Your codes stopped working. You probably opened the enrolment screen and left without confirming. Opening it issues a new secret immediately. Enrol again, using the key now on screen.

The code is rejected and the clock looks right. Each code works once. If you have already used this one, wait for the next.

You lost the device. There are no recovery codes, so the route is support. We verify that you are the account holder before the second factor is removed. A person does that check, so it is deliberately not instant.

Contact support any time by email or from your dashboard. Every service is monitored around the clock.

You want to turn it off. There is no self-service reset. No screen and no endpoint turns two-factor authentication off, for you or for an administrator in your organisation.

A colleague is stuck on the enrolment screen. The organisation requires it. Enrolment and signing out are the only things available until they finish, and that is the design.