Docs

Account

Two-factor authentication

Two-factor authentication (2FA) asks for a six-digit code from an authenticator app after your password. Anyone who learns your password still cannot sign in without your phone.

Short answer

Open Account → Security and choose the two-factor button. Scan the QR code with an authenticator app, type the code it shows, and save the 8 recovery codes somewhere safe. From then on Glimana asks for a code at sign-in.

Turn it on

You need a verified email address first; if you have not confirmed it yet, the setup page asks you to do that.

  1. Open the avatar menu → Account → Security and choose the two-factor button. It opens the setup page (/account/2fa).
  2. Scan the QR code with an authenticator app (any app that shows six-digit time-based codes works).
  3. Enter the six-digit code the app shows to confirm.
  4. Save your recovery codes (see below) before you leave the page.
The setup page: scan the QR code, then enter the six-digit code. The QR code and key are blurred here.
The setup page: scan the QR code, then enter the six-digit code. The QR code and key are blurred here.

When 2FA is switched on, Glimana sends an email to the account owner with a link to undo it (see "This was not me").

Required for administrator accounts

Glimana staff accounts with administrator access cannot use the panel without 2FA; they are sent to the setup page until it is on. For everyone else it is optional and recommended.

Signing in with a code

After your email and password, Glimana shows the code screen (/2fa). Open your authenticator app and type the current code. Codes change every 30 seconds; if one is rejected, wait for the next.

The sign-in code screen, with "remember this device".
The sign-in code screen, with "remember this device".

After too many wrong codes the screen asks you to try again in an hour. This protects the account if someone has your password.

Recovery codes

When you turn 2FA on you get 8 recovery codes in the form A1B2C3-D4E5. Each one works once, in place of an app code, for example when your phone is lost.

  • Store them outside Glimana: a password manager or a printed copy.
  • When you have used some, generate a new set on the setup page. A new set replaces the old one; the old codes stop working.
Recovery codes are shown once, right after you turn 2FA on; copy or download them. The codes are blurred here.
Recovery codes are shown once, right after you turn 2FA on; copy or download them. The codes are blurred here.

Remember this device

On the code screen you can tick remember this device. Glimana then skips the code on that browser for 30 days. Do not tick it on a shared or public computer.

The email sent when 2FA is switched on contains a "This was not me — undo" link. It is signed and valid for 24 hours.

The link does not change anything by itself: it opens a confirmation page. Turn it off and sign out everywhere switches 2FA off and ends every session on the account, so whoever turned it on is signed out too. Then sign in, change your password and set 2FA up again on your own phone.

Turning it off

Two-factor authentication is switched off on the same setup page. Turning it off starts the 72-hour pause described below.

Support cannot change it for you

When a Glimana support team member opens your workspace to help you, they cannot turn 2FA on or off or generate new recovery codes. Security settings change only from your own session.

Why money actions pause for 72 hours

Some changes are what an attacker would do right after taking over an account. After any of them, actions that move money are paused for 72 hours:

  • turning 2FA off,
  • changing the password,
  • resetting a forgotten password,
  • changing the account email.

Turning 2FA on for the first time does not start the pause.

Money actions are part of Glimana Market, which is not open yet. Until it opens, this pause has no visible effect on your account.

Was this page helpful?

Last updated 2026-10-10 · Contact support