Two-factor authentication is a second proof of identity that Fincanva asks for after your first sign-in step succeeds, so that an email address or password on its own is not enough to reach your account. Fincanva accepts three kinds of second proof: a 6-digit code from an authenticator app, one of your saved backup codes, or — on some sign-in routes — a code emailed to you. It is off until you turn it on, and once on it applies to every way into the account.
Also seen as: 2FA, two-step verification, TOTP
What does two-factor authentication protect against?
It protects against someone who already has your first factor. A password can be guessed, reused, or leaked in another company's breach; an inbox can be left open on a shared machine. With a second factor on, none of that is sufficient on its own, because the attacker also needs the phone in your pocket or the codes you saved.
It does not protect against handing the second-factor code to someone who asked you for it. Fincanva never asks for your 6-digit code or a backup code outside the sign-in screen — not by email, not in a chat.
How do I turn two-factor authentication on?
Fincanva walks you through a three-step wizard titled "Set up two-factor authentication". First it shows a QR code: "Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password…)." — and if the camera route fails, "Can't scan? Enter this code manually" reveals the same secret as text. Second, you prove the pairing worked: "Enter the 6-digit code" and press Verify. Third, Fincanva shows your backup codes and makes you tick "I have saved my backup codes" before Done unlocks.
Before the wizard starts, Fincanva confirms it is really you. If your account has a password, it asks for it ("We ask for your password to confirm it's you."). If it has no password — a Google-only or email-only account — it emails you a confirmation link instead. Turning 2FA off and regenerating codes go through the same confirmation.
What are backup codes and when do I use them?
Backup codes are ten one-time recovery codes, shown once during setup, that stand in for your authenticator app when you can't reach it. The screen states the rule: "Save these one-time recovery codes somewhere safe. Each works once if you lose your authenticator app." You can Copy all or Download .txt on the spot.
At the sign-in screen, Use a backup code instead swaps the 6-digit field for a backup-code field, which takes the code in the two five-character groups it was issued in. A wrong or already-spent code returns "That backup code did not work. Try another." You can issue a fresh set at any time with Generate new backup codes; doing so kills the old set outright — "Your old backup codes will stop working. Save the new set somewhere safe."
What does "Trust this browser for 30 days" do?
Ticking Trust this browser for 30 days at the code screen tells Fincanva to skip the second-factor prompt for the next 30 days on that browser, for email + password sign-ins.
The scope is narrower than the label suggests, and it matters: an emailed link, an emailed code, or Continue with Google asks for the second factor every time, even on a browser you trusted. Trust is stored per browser, so a different browser, a different device, or a private window starts untrusted.
What if I lose my phone?
Use a backup code. At the code screen, Use a backup code instead takes one of the ten codes you saved during setup, and one code is all it takes to get in — then you can pair a new authenticator app and generate a new code set from your account settings.
If your first step was Continue with Google, one more door is open: "Can't access your authenticator app?" offers Email me a code, which sends a 6-digit code valid for 5 minutes. That offer is deliberately absent when you signed in by emailed link or emailed code, because a code sent to the same inbox would not be a second factor at all.
Defaults in Fincanva
- Two-factor authentication is off until you turn it on. There is no plan requirement and no forced enrolment.
- Once on, it applies to every sign-in route — password, emailed link, emailed code, and Continue with Google.
- An authenticator-app code is 6 digits and rotates on your device's clock; an emailed second-factor code is valid for 5 minutes.
- Setup issues ten one-time backup codes. Generating a new set invalidates the previous set.
- Trust this browser for 30 days suppresses the prompt only on email + password sign-ins from that browser.
- Turning 2FA on or off, and regenerating codes, always requires a confirmation — your password, or an emailed link if your account has none.
- Disabling it is reversible: "Your account will only require a password to sign in. You can re-enable 2FA later."
Worked example
Your phone goes into a river on Tuesday. Your authenticator app went with it, and its codes are not recoverable from the app store — they lived on the device.
You sign in from your laptop with email and password, reach "Two-factor verification", and instead of typing a code you press Use a backup code instead. You paste the first unused code from the ten you filed away at setup. You are in, and that code is now spent: nine remain.
Still signed in, you go to your security settings, turn 2FA off with your password, then turn it straight back on to pair the authenticator app on your replacement phone. The wizard's third step hands you a fresh set of ten codes, and the nine leftovers from the old set stop working the moment the new set is issued.
Had you had no backup codes and no password — a Google-only account — the recovery path would have been Email me a code at the challenge screen, which is offered on that route precisely because your inbox was not your first factor.
Where this term is used
Generated · 1 pagesThe pages that reference this term — so a term page is somewhere you pass through, not somewhere you land and stop.
Also referenced by 3 terms
Fincanva provides no financial advice. Backtests show what would have happened — not what will.
GLOSSARY · 193 TERMS