Two-factor authentication (2FA) adds a second step when you sign in: as well as your password, you enter a 6-digit code from an authenticator app on your phone. Even if someone learns your password, they can't get into your account without your phone too. Office and admin accounts can see everything in the business - clients, prices, jobs and financials - so two-factor authentication is required for them. Field users protect the mobile app a different way, by locking it with Face ID, a fingerprint or their phone's passcode.
What is an authenticator app?
An authenticator app runs on your phone and shows a 6-digit code that changes every 30 seconds. When you sign in, BuilderDash asks for the current code, and only your phone knows it. It works completely offline - no text messages, no signal needed.
If you don't already have one, any of these free apps will do the job:
You're not tied to any particular one; they all work the same way.
How to set up two-factor authentication
You'll do this once, on the setup screen shown automatically the first time you sign in as an office or admin user, or any time via Settings > Profile > Two-factor authentication > Set up.
- Install an authenticator app on your phone if you don't already have one.
- Open the app and choose to add an account - the button is usually a plus sign, "Add", or "Scan a QR code".
- Scan the QR code shown on the BuilderDash screen with your phone. The app adds BuilderDash and immediately starts showing a 6-digit code. Can't scan it? Tap 'Enter a setup key' in your authenticator app and type in the key shown under 'Or enter this key' instead, choosing 'time-based' if asked.
- Type the current 6-digit code from the app into BuilderDash and click 'Verify & turn on'. The code refreshes every 30 seconds, so if it's about to change, just wait for the next one.
- Save your backup codes. You're shown a set of one-time codes - copy or download them and keep them somewhere safe, not on the same phone. Each one lets you sign in once if you ever lose your phone, and this is the only time they're shown in full.
That's it - your account is protected.
How to sign in once it's set up
- Enter your email and password as usual.
- Open your authenticator app, read the current 6-digit BuilderDash code, and type it in.
- You're in. If you've lost your phone, enter one of your backup codes instead - each one works once.
Managing your backup codes and switching phones
Head to Settings > Profile > Two-factor authentication > Manage, then enter a current code to confirm it's you. From there you can regenerate a fresh set of backup codes at any time - useful if you're running low or think an old set may have been seen by someone else. Office and admin accounts can't switch two-factor authentication off, since it's required, but can always regenerate their backup codes.
Got a new phone? Set up your authenticator app on it from the same Manage screen, or sign in with a backup code first and then re-scan the QR code to link the new device.
Locking the mobile app
Open the field app and go to Profile > Security > App lock, then turn it on - you'll confirm with Face ID, fingerprint or your passcode. From then on, the app asks you to unlock it when you open it, and again if it's been in the background for a while.
If something goes wrong
- "That code isn't right." The most common cause is your phone's clock being slightly off. Turn on automatic date and time in your phone settings, since authenticator codes rely on the exact time, then try the next code.
- The code expired before you entered it. Codes only last 30 seconds, so always enter the one showing right now rather than one you copied earlier.
- You've lost your phone. Sign in with a backup code, then set your authenticator app up again on your new phone.
Good to know
- Two-factor authentication is required for office and admin accounts, since the web app holds client and financial data. It stays optional for client portal and supplier accounts, and for field users, who use the mobile app lock instead.
- BuilderDash uses standard authenticator app codes, which are more secure than text message codes - they work offline and can't be intercepted over the phone network.
- Backup codes are one-time only. Each one works once and is then used up, and generating a new set replaces the old one.
- You're only asked for a code after the correct password - BuilderDash never reveals whether an account has two-factor authentication switched on if the password is wrong.
- The mobile app lock protects the device, not your account login. It's separate from web two-factor authentication and is set up per device.
- Your two-factor authentication details and backup codes are stored securely and can't be read back, even by BuilderDash.