Two Factor Authentication
LaunchBay supports Two-Factor Authentication (2FA) as an additional layer of security for both your team and your clients. Team and client 2FA can be enabled independently of each other, giving you flexible control over your account's security requirements.
Team Two-Factor Authentication
Enabling 2FA for Your Team
Team admins can require all team members to use 2FA when logging in to LaunchBay. To enable it, go to Settings → Security and toggle on the team 2FA option - note that you will need to set up 2FA in your account first. Once enabled, all team members will be required to set up 2FA on their next login.
Team members can also enable 2FA individually on their own accounts without an admin requirement. To do this, click your name in the bottom left corner of your account, select "Profile," and scroll to the Multifactor Authentication section. Click "Add Authenticator" and follow the prompts.

Setting Up an Authenticator App
An authenticator app on a separate device is required. Some popular options include Google Authenticator, Authy, and Bitwarden — any standard authenticator app will work.
When setting up 2FA, a QR code will appear on screen. Open your authenticator app, scan the code, and enter the verification code it generates to complete setup. Once configured, every login will require a code from the authenticator app.

Client Two-Factor Authentication
Requirements
Client 2FA requires Password-Protected Portals to be enabled first. Magic links are not compatible with client 2FA — when client 2FA is enabled, all magic links are disabled and clients will be directed to the password login page instead.
📢 Note: Password Protected Portals are available on the Premium plan. Click here to learn more.
Enabling 2FA for Clients

To require 2FA for all clients, go to Settings → Security and toggle on the client 2FA option - note that you will need to set up 2FA in your account first. This setting applies to all clients across your account — it cannot be enabled for individual clients only.
Once enabled, clients will be prompted to set up 2FA using an authenticator app either on their first login or on their first login after the setting is turned on. They will be shown a QR code to scan with their authenticator app before they can access their portal.
📢 Note: Enabling client 2FA will disable magic links account-wide. Any magic link emails previously sent to clients will now take them to the password login page instead of directly into their portal.
Quick Reference
|
|
Team 2FA | Client 2FA |
|---|---|---|
| Where to enable | Settings → Security | Settings → Security |
| Applies to | All team members | All clients |
| Requires | Authenticator app | Password Protected Portals + Authenticator app |
| Magic links | Not affected | Disabled when 2FA is on |
| Setup prompt | On next login | On first login post-enable |
Data safety is important to us at LaunchBay, so we offer a Two-Factor Authentication (2FA) option for your team and clients to add an extra level of security to your accounts.
Enabling 2FA
Team members must individually enable 2FA on their own LaunchBay profiles. They do this by clicking their name at the bottom left of the screen and selecting "Profile."
An authenticator app on a separate device is required. Some popular options are Google Authenticator, Authy, or bitwarden, but almost any other authenticator app that is available will work.
Scroll to the bottom of the Profile page to find "Multifactor Authentication." Click "Add Authenticator," and a pop-up will allow you to add a device. Open your authenticator app and scan the code that appears. The app should give you a code to enter.
Once added, every login will now require 2FA and a code generated by the authenticator app.