Blog

Two-factor authentication, for teams

How teams share two-factor authentication codes without passing the secret around: practical guides, tool-by-tool walkthroughs and answers to the questions that come up.

Two-factor authentication was designed for one person with one phone. Teams still have to run shared accounts on it. These are the questions that come out of that gap, answered as plainly as we can.

Sharing codes with a team

Getting a code to the people who need it, without handing out the secret behind it.

Shared accounts

One login, several people, and a phone that is not always in the room.

Authenticator apps

What Google Authenticator, Microsoft Authenticator and their QR codes can and cannot do for a team.

Tool by tool

Stripe, AWS, social accounts: how 2FA actually gets shared on the tools teams live in.

5 min read

How to Manage 2FA for a Shared Stripe Account

Stripe has team members, roles and restricted API keys, so most shared Stripe logins are unnecessary. What is genuinely left, and how to run 2FA on it.

How TOTP works

The mechanics behind the six digits, and what follows from them.

10 min read

The Complete Guide to TOTP for TeamsGuide

How time-based one-time passwords work, which properties of the algorithm cause every shared-account problem, and what a team needs to run TOTP.