guide
Sections

Start here

Two-step verification

A second check at sign-in — a number your own phone works out with no signal needed, or one emailed to you if you have no smartphone — and the ten recovery codes that get you back in if you lose either.

A password is a single thing, and a single thing can be guessed, taken by a convincing email, or reused somewhere that was later broken into. Two-step verification adds a second question at sign-in that an attacker holding your password still cannot answer: a six-digit number that changes every thirty seconds and that only your own phone can work out.

The screen is at Profile → Two-step verification.

Two ways to get your number, and one of them is better

An app on your phone is the one to choose. It works the number out on its own, so it needs no signal, no data and no airtime — an officer at a gate on a bad morning can still sign in. It costs nothing every time you use it, and nobody can take it out of your inbox, because it never goes near one.

An emailed number is there for people who cannot use an app, and it is genuinely weaker in two ways worth knowing before you choose it. It depends on the network at the exact moment you are trying to get in: no data at the gate, a mail provider having a bad morning, or your school’s own filter holding it back, and you cannot sign in at all. And your email address is also where a password reset is sent, so anybody who gets into your mailbox holds both halves of your sign-in at once — the second step has stopped being a second thing.

The screen says all of this beside the two buttons, so nobody has to have read this page. Whichever you choose, the ten recovery codes below are the same, and they are the real floor under both.

Why an app, and not a text message

The number is not sent to you. Your phone calculates it from a secret it was given once, at setup, using nothing but its own clock. That has three consequences that matter in a school:

  • It works with no signal. An officer standing at a gate on a bad morning, with no data and no airtime, can still sign in. A code that has to arrive over a network is a second factor that stops working exactly where this product is used most.
  • It costs nothing. There is no per-message charge, so nobody has to weigh security against the messaging budget.
  • It cannot be taken by a SIM swap. Someone who persuades a mobile operator to move your number onto their own card gets your text messages. They do not get the secret inside your phone.

Any of the usual authenticator apps will do. The system does not care which one you use and never talks to it.

Setting it up

The screen walks through two steps on one page.

Step 1 shows a square code. Open your authenticator app, choose to add an account, and scan it. If your app cannot use the camera, the same secret is printed underneath as a Setup key you can type in by hand.

Step 2 asks for the number your app is now showing. Typing it correctly is what proves the secret actually reached your phone — until that moment the account has started setting up rather than finished, and nothing has changed about how you sign in. If you close the tab, lose the square code, or scan it into an app you then delete, simply start again; the half-finished attempt is discarded and replaced.

A little tolerance is built in, because cheap handsets drift. A number from the previous or the next thirty-second window is still accepted, so you have about ninety seconds rather than thirty. If the app keeps being refused, the usual cause is a phone whose clock is set by hand — turn on automatic time and try again.

Your ten recovery codes

The moment two-step verification is turned on, the screen shows ten recovery codes. Each one is sixteen characters, in four groups, and each works exactly once — in place of the number from your phone.

They exist for the day the phone does not: lost on a taxi, dropped in a sink, wiped and handed to a new member of staff, or simply flat. Without them, a second factor would not be a protection at all — it would be a lockout that had been moved off one thing and onto another.

Print them or write them down, and keep them away from the phone. A drawer at home, a wallet, the back of a filing cabinet — anywhere that survives losing the handset. Copying them into the same phone defeats the purpose entirely.

This is the only time they are ever shown. They are not kept anywhere they could be read back, which means nobody — not an administrator, not the people who built the system — can look yours up for you afterwards. That is deliberate: a copy somebody could fetch is a copy somebody could steal.

The screen keeps them in front of you until you confirm you have saved them. Changing the language, or stepping away to another screen and coming back, does not lose them. Closing the tab does, and so does confirming — after that the only way to have a list again is to print a new set, which needs your phone or one of the codes you still hold.

Keeping track of them

Back on the two-step screen, the account shows how many codes are still unused, and when the set you are holding was printed. That number is there to be noticed in advance. Discovering you are out of codes on the morning you need one is too late; noticing “three left” on a screen you were visiting anyway is not.

Below three, the screen says so plainly and suggests printing a new set.

Printing a new set

Print a new set replaces all ten. The ones you have now stop working the moment the new list appears, so only do it when you can print or write the new list down straight away.

It asks for the number from your phone, or for one of the codes you are about to replace, before it will do anything. Being signed in is not enough on its own — and that is the point. Somebody who sits down at a screen you left open in a staff room has your session; what they do not have is your phone or the paper in your drawer, and without one of those they cannot walk away with ten fresh keys to your account.

That check is also why this action does not ask for a fingerprint or a face. It already carries its own proof, and demanding a passkey instead would shut out exactly the people who have never enrolled one.

What happens at sign-in now

Once you have set this up, signing in has a second step. You type your email and your password as always, and then the screen asks for your number: the six digits from your app, or the six digits emailed to you.

One box takes either the number or one of your ten recovery codes. You are never asked which kind you are about to type — type whichever you have.

If you get it wrong, nothing is lost. The message says so, the box is still there, and your password does not have to be typed again. Only two things send you back to the beginning: leaving the screen sitting for more than five minutes, and an administrator resetting your two-step verification while you are part-way through. Both say which.

Whether you have to set it up

It depends on what your account does.

If you are an administrator, a class teacher, or one of our platform staff, you do. Your account can reach the school’s records, so a second check is now part of signing in. You will not be turned away and nothing is taken from you: the next time you sign in, after your password, the screen asks you to set two-step verification up there and then, and signs you in as soon as it is done. Your ten recovery codes appear on the screen straight afterwards.

Set aside a few minutes for it the first time. You may need to install an authenticator app, and you will want somewhere to write the ten codes down. The screen gives you fifteen minutes, which is plenty, and if it runs out you simply type your password again and start over. Nothing is lost.

If you are a security officer, nothing changes. You sign in exactly as you always have — same screen, same two things to type, no number asked for. That is on purpose rather than an oversight: a gate phone is shared between officers, and an authenticator app on a shared phone would end up holding everybody’s numbers on one device, which is worse than not having one at all. What protects a gate phone instead is a passkey, which belongs to one person on one device and cannot be handed round. You may still set two-step verification up if you want it.

If an administrator resets your two-step verification and your role is one of the three above, your next sign-in asks you to set it up again before it lets you in. That is the point of the reset — it is a way back in for somebody who has lost their phone, not a way to stop being asked.