Setting Up Two-Factor Authentication in FFAIR
Understand what two-factor authentication is, why it matters, and how to set it up on your account.
Every sign-in to FFAIR is protected by your password, SSO, or Magic Link alone by default. Two-factor authentication (2FA) adds a second step to that process, so a password on its own is no longer enough to get into your account — this is how the platform keeps your account secure even if your password is ever compromised.
This article covers:
- How 2FA works
- Choosing and setting up a verification method
- Saving your recovery codes
- Signing in once 2FA is switched on
- Managing trusted devices
- Turning 2FA off
- What to do if you're locked out
How 2FA works
2FA is optional and available to every user — Organisers, Exhibitors, and Suppliers alike. Once it's switched on, FFAIR asks for a second verification step every time you sign in, on top of your usual password, SSO, or Magic Link:
- First factor entered — your usual password, SSO, or Magic Link sign-in.
- Second factor requested — FFAIR asks for a code or prompt from whichever verification method you've set as preferred.
- If correct — you're signed in as normal, and (optionally) the device is remembered for 90 days.
- If incorrect or expired — you'll see an error and can try again, switch to another method, or use a recovery code.
Note: 2FA is entirely optional. If you don't set it up, you'll continue signing in with just your password, SSO, or Magic Link as before.
Choosing and setting up a verification method
Go to Settings > 2FA Settings and select Enable 2FA to get started. You can set up more than one method and mark one as your Preferred verification method — this is the one offered by default when you sign in.
- Authenticator app — scan the QR code shown with an app such as Google Authenticator, Microsoft Authenticator, or Authy, then enter the 6-digit code it generates to confirm setup.
- Phone number (SMS) — add and verify a phone number. FFAIR texts a 6-digit code, valid for 15 minutes, each time it's needed.
- Email — add and confirm an email address for one-time codes, valid for 30 minutes. This must be different from the address you sign in with, and is available even on SSO or Magic Link accounts.
- Passkey — register a passkey using your device's built-in security (fingerprint, face recognition, or PIN). You can register a separate passkey for each device you use, and remove any of them later.
Note: Enabling, disabling, or changing any method asks you to confirm your identity first — for password accounts, this means re-entering your password.
⚠️ Important: If you enter your sign-in email address into the Email method's confirmation field, FFAIR blocks it with the error "Use an email address other than the one you sign in with." Use a different address instead.
Saving your recovery codes
When 2FA is switched on for the first time, FFAIR generates a set of recovery codes — a backup way in if you ever lose access to your other methods.
- Copy or download your codes — use "copy all" or "download .txt" on the Save recovery codes screen.
- Store them somewhere safe — they're shown only once and can't be viewed again.
- Use one if needed — enter it at the "Use a recovery code" prompt during sign-in. Each code works once only.
Note: Adding, changing, or removing a verification method later doesn't affect your existing recovery codes. If you run out, or need a fresh set, you'll need to disable 2FA and enable it again — codes can't be regenerated on their own.
Signing in once 2FA is switched on
Once enabled, FFAIR asks for your second factor every time you sign in — unless you're on a trusted device (see below).
- Enter your first factor — password, SSO, or Magic Link, as normal.
- Complete your preferred method — enter the code or complete the prompt for whichever method is marked preferred.
- Switch methods if needed — select "Try another method" to use a different verification method you've set up, or "Use a recovery code" if you can't access any of them.
- Remember this device, if you like — tick this to skip 2FA on that device for the next 90 days.
Note: An incorrect code shows an inline error and doesn't sign you in. An expired SMS or email code shows "This code has expired. Request a new one." — simply request a fresh one and try again.
Managing trusted devices
Any device you've chosen to remember during sign-in appears under Trusted devices in your 2FA Settings, along with its browser, approximate location, and last-seen date.
- Revoke a single device — 2FA is required again the next time you sign in from it.
- Sign out from all devices — revokes every trusted device and ends all active sessions at once, so 2FA is required everywhere on your next sign-in.
⚠️ Important: Signing out from all devices ends every active session immediately, including your own — you'll need to sign in again yourself afterwards.
Turning 2FA off
You can disable 2FA at any time from 2FA Settings.
- Select Disable 2FA — you'll be asked to confirm you want to proceed.
- Confirm your identity — for password accounts, by re-entering your password.
- 2FA is switched off — you'll sign in using your normal password, SSO, or Magic Link only, until you choose to set it up again.
Turning 2FA off invalidates any recovery codes from your previous setup. If you enable 2FA again later, you'll be issued a fresh set when you re-enable it.
Locked out?
If you lose access to every verification method and your recovery codes, contact FFAIR support — we can reset 2FA on your account so you can sign back in and set it up again.