> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.crisp.chat/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to enable Two Factor Authentication (2FA)

*Learn how to enable Two-Factor Authentication for your Crisp account and enforce it for your workspace.*

Two-Factor Authentication adds a second verification step when signing in to Crisp. It is optional by default, but strongly recommended for every operator because it helps protect your workspace even if a password is compromised.

| This guide uses Google Authenticator as an example, but other apps that generate time-based one-time passwords can also be used.

---

# ${color}[#0080dd](What Two-Factor Authentication does)

Two-Factor Authentication, also called **2FA** or **MFA**, requires more than a password to access an account. In Crisp, the second factor is usually a 6-digit code generated by an authenticator app and rotated every 30 seconds.

__Common compatible authenticator options include:__
* **Google Authenticator** → mobile authenticator app from Google
* **Microsoft Authenticator** → mobile authenticator app from Microsoft
* **YubiKey** → hardware-backed authentication option
* **1Password** → password manager with one-time password support
* **LastPass** → password manager with one-time password support

|| Crisp can also send 2FA requests by SMS, but SMS requests are heavily rate limited for security reasons.

---

# ${color}[#0080dd](Enable Two-Factor Authentication on your account)

There are two ways 2FA can be enabled for an operator account.

#### ${color}[#445055](When your workspace enforces 2FA)

If your company enforces 2FA, Crisp can ask you to scan a QR code during signup or login. Follow the on-screen instructions to register your authenticator app before accessing the workspace.

#### ${color}[#445055](When you enable 2FA manually)

To enable 2FA yourself, open [Crisp](https://app.crisp.chat), then go to **Settings → Account → Account Information** and click **Enable Two Factor Authentication**.

You may need to add your mobile phone number to your Crisp account first.

---

# ${color}[#0080dd](Set up your authenticator app)

Download your authenticator app, then scan the QR code shown by Crisp. The app will start generating 6-digit codes you can use when logging in.

![Scan the Crisp 2FA QR code](https://storage.crisp.chat/users/helpdesk/website/87ae2703583ac800/cleanshot-2024-10-28-at-102500_1pxi5xn.png =1000xauto)

__Basic setup flow:__
* Download an authenticator app such as [Google Authenticator](https://support.google.com/accounts/answer/1066447)
* Click **Scan a QR code** in the app
* Scan the QR code shown by Crisp
* Confirm the setup by entering the generated code when requested

---

# ${color}[#0080dd](Log in with Two-Factor Authentication)

Once 2FA is enabled, Crisp asks for a code each time you log in. Open your authenticator app and enter the current 6-digit code before it rotates.

![2FA code generated by Google Authenticator](https://storage.crisp.chat/users/helpdesk/website/87ae2703583ac800/cleanshot-2024-10-28-at-102716_1f26lpj.png =1000xauto)

---

# ${color}[#0080dd](Change your 2FA app)

If your workspace requires 2FA and you need to switch authenticator apps, temporarily remove the workspace enforcement before replacing your app.

__Recommended order:__
* Turn off the workspace setting that forces operators to enable 2FA
* Remove 2FA from your own account
* Set up 2FA again with the new authenticator app
* Turn the workspace enforcement setting back on

||| Make sure all required operators have working 2FA again before re-enabling enforcement.

---

# ${color}[#0080dd](Enforce Two-Factor Authentication for your workspace)

Workspace owners can require all operators to use 2FA.

Before enforcing it, make sure every current operator already has 2FA enabled. Operators with 2FA enabled show a green padlock icon next to their email.

![Operators with 2FA enabled in Crisp](https://storage.crisp.chat/users/helpdesk/website/-/8/7/a/e/87ae2703583ac800/cleanshot-2026-02-02-at-153249_qzsidx.png =1000xauto)

Open [Crisp](https://app.crisp.chat), then go to **Settings → Workspace Settings → Operators in the Team** and enable **Force Operators to have their Two Factor Authentication Enabled**.

![Force operators to enable 2FA setting](https://storage.crisp.chat/users/helpdesk/website/-/8/7/a/e/87ae2703583ac800/cleanshot-2026-02-02-at-153539_13lmx1x.png =1000xauto)

---

# ${color}[#0080dd](Regain access if you are locked out)

If you cannot log in because 2FA is enabled, first try the alternative SMS method when available. If you cannot receive the SMS, Crisp support will need to verify your identity.

__To request help recovering access:__
* Contact Crisp support from your registered email address
* Send a photo of your ID showing your first and last name when requested by the support agent
* Wait for identity verification before 2FA is disabled or a password reset is sent

Once your identity is confirmed, the support team may disable 2FA on your account and send a password reset email so you can regain access.

---

# ${color}[#0080dd](Frequently Asked Questions)

*Still have questions which were not covered in this article? Here is a collection of the most frequently asked questions on this topic.*

###### ${color}[#F08820](Is 2FA required for every Crisp account?)

**No, 2FA is optional by default.** A workspace owner can enforce it for all operators from the workspace team settings.

Even when it is not enforced, enabling 2FA is strongly recommended.

###### ${color}[#F08820](Can Crisp support disable 2FA if I am locked out?)

**Yes, but only after identity verification.** Contact support from your registered email address and follow the verification steps requested by the support agent.