Account and billing
Signing in securely
Two-factor authentication and passkeys for yourself, requiring two-factor company-wide, and why a passkey does not satisfy that requirement.
Last updated 10 August 2026.
Two-factor authentication
Two-factor authentication means signing in takes a password and a code from an authenticator app on your phone, so someone who learns your password still cannot get in. Anyone on the account can turn it on for themselves — you do not need to be an owner or an admin.
Set it up from your profile. You will be asked to confirm your password first, then shown a QR code to scan with an authenticator app — Google Authenticator, 1Password, Authy, anything that speaks the standard. Scanning it is not enough on its own: you have to type in a code the app generates to prove it actually holds the secret, and two-factor stays off until you do. That one step is what stops someone turning the switch on, photographing nothing, and finding out at their next sign-in that no device they own can produce a code.
The moment you confirm it, you're shown a set of recovery codes. Each one signs you in exactly once, in place of a code from your phone, and together they exist for one situation: your phone is lost, stolen, wiped, or simply somewhere else, and you still need to get in. They are shown to you once — write them down or save them somewhere that is not the phone your authenticator app is on. A recovery code kept only on the device it's meant to be a backup for is not a backup.
If you lose both your phone and your recovery codes, you cannot get past the code prompt on your own — get in touch and a person will help you back in.
Passkeys
A passkey lets you sign in with your fingerprint, your face, or your device's PIN, instead of typing a password at all. It's created and held by your device — nothing about it is a shared secret sitting on a server for someone to steal — so a convincing fake sign-in page has nothing to phish. Add one from your profile, the same place two-factor lives; you'll confirm your password once, then your device will ask you to complete the ceremony (a fingerprint, a face scan, a PIN).
A passkey is a different way of proving it's you, not a second thing checked in addition to a password. It replaces the password step entirely for the device it's registered on. That matters because of the next section: if your company requires two-factor authentication, signing in with a passkey does not satisfy that requirement. Two-factor asks for a password plus a code; a passkey is neither of those on its own. If your company has switched two-factor on for your role, you still need an authenticator app set up even if you also have a passkey.
Requiring two-factor for your whole company
By default, two-factor authentication is optional — anyone can turn it on for themselves, and nobody is made to. An owner can change that from Settings → Security, with three choices:
- Off. The default. Anyone may still turn it on for themselves.
- Required for owners and admins. Technicians are not affected and may still opt in if they want to.
- Required for everyone. Every person on the account, technicians included, must set it up before they can use the site.
This is a website-login setting only — it has no effect on the mobile app, which signs in with a one-time code issued to that person, or on the links you send customers to track their jobs. The app has no password for a second factor to sit behind; see signing in on your phone for what does control who can get onto a phone.
Before you save, the screen tells you how many people the setting you've selected would catch — anyone in a covered role who hasn't set up two-factor yet, named outright when there are only a few of them. That's the reason not to be nervous about the switch: you're never guessing at the size of the disruption, you're looking straight at it before you commit to it. Nobody already signed in is thrown out the moment you save — anyone caught by the new setting stays signed in until their next visit.
A person caught by the requirement is sent to a setup screen the next time they open the site and cannot get into the app until they've been through it. They are never locked out of fixing it, though — their own profile (where two-factor is set up) and, for an owner, billing, stay reachable the whole time, so the way past the requirement is never itself behind the requirement.
Other things on your profile
Changing your password asks for your current one first. It doesn't sign out your other sessions on its own — that's a separate, deliberate choice, covered next.
Signing out other browsers lists everywhere you're currently signed in — a laptop at the office, a phone, a browser you forgot was still logged in — each with enough detail to recognise it, and marks which one is the one you're using right now. You can end any single session, or sign out everywhere else at once with your password. This is worth doing any time a device you signed in on is lost, sold, or no longer yours.
Email verification
WorkOrders offers to verify your email address, and it's one of the steps on the getting-started checklist — but it isn't enforced. Nothing about the account is limited or restricted while an address is unverified; you can use every part of the product either way.