Two-Factor Authentication and Account Security
Here's every second factor ShipGenius supports, how to set each one up, how recovery codes and trusted devices work, and how to check which sessions and devices have been on your account.
Your ShipGenius account can buy postage, so it's worth a few minutes to lock it down. Two-factor authentication is the best thing you can do here, and this article walks through every option so you can pick the ones that fit how you work.
You'll find everything below on your account settings page.
Your First Factor
This is what you sign in with. There are two options, and you're welcome to use both:
Password
Set or change your password from account settings. We check its strength as you type, and you confirm the entry before it's saved. The check looks at how hard the password would actually be to guess rather than counting capitals and symbols, so a long, memorable passphrase scores well and something like "P@ssw0rd1!" does not.
Third-Party Provider
Link a provider such as Google and sign in through it. There's a bonus here: a linked provider can double as your second factor, so one setup covers both halves of signing in.
Second Factors
We support several, listed here strongest first. You can enroll more than one, and it's worth doing -- if you ever lose access to one, another one is waiting for you.
Authenticator App (TOTP)
This is the strongest option and the one we recommend. Setup shows a QR code you can scan with any authenticator app -- Google Authenticator, Authy, and 1Password all work, among others. If you're setting this up on the same phone that holds the app, tap the setup link instead of trying to scan a code on the screen you're looking at.
Setup isn't finished until you enter a code from the app. That step is there for your benefit: it confirms the app is producing valid codes before we start relying on it, so you can't get locked out by a setup that never quite took.
Third-Party Provider
A linked provider can also act as your second factor, which is handy if you already sign in that way. It's as strong as the account behind it, so it's worth having good protection on that account too.
We email a code to your verified email address, so you'll need a verified email on file. It's not as strong as an authenticator app, since it's only as secure as your email account, but it's a solid choice and far better than no second factor.
SMS
We text a code to your verified phone number. It's the least strong of the options, because a phone number can be moved to a new SIM by someone who convinces your phone company they're you. If SMS is the one you'll actually use, use it -- it beats having no second factor. If you have the choice, an authenticator app is the sturdier pick.
Recovery Codes
These are single-use codes that get you back in if you ever lose access to your other factors. Generate a set and keep them somewhere separate from your phone and your password manager -- printed and filed away works well -- so losing one device doesn't take your backup with it. They open your account just like your password does, so give them the same care.
Account settings shows how many you have left. When the count gets low, generate a fresh set -- the new codes replace the old ones, so you can safely discard the old copies.
Keeping at Least One Second Factor
If you have exactly one second factor set up, its toggle is greyed out and a tooltip explains why. It's not us being difficult -- it just keeps a single click from leaving your account with nothing but a password behind it. We'd stop the change on our end too, so the greyed-out control is a heads-up before the click rather than a surprise after it.
Swapping factors is easy. If you're moving from SMS to an authenticator app, say, set up the new one first and then remove the old one.
Trusted Devices
When you sign in, you can mark a device as remembered so it skips the second-factor challenge next time. That's a nice bit of convenience on a computer only you use. On a shared or public machine, it's better to leave the box unchecked.
Trusted devices aren't something you turn on from account settings -- you mark them at sign-in, and you can review or remove them from the devices list whenever you like.
Sessions and Devices
Account settings shows you both, and each answers a different question.
Active Sessions
This is everywhere you're currently signed in. You can sign out any session except the one you're using right now, which is handy if you've left yourself signed in on a computer you no longer have.
Known Devices
This is every device that has signed in to your account. If one doesn't look familiar, you can report it, and reporting it blocks it.
Reporting a device does two things: it blocks that device, and it lets our security team know something may be off with your account. If you spot a device you can't place, report it and change your password -- and get in touch if you'd like a hand, we're happy to take a look with you.
Glancing at this list now and then is one of the most useful security habits there is. It's usually where anything unusual turns up first, which means there's plenty of time to sort it out.
Extra Confirmation on Sensitive Actions
A few actions ask you to confirm with a second factor even though you're already signed in. Being an administrator doesn't skip that step -- it's a separate check, and having a second factor set up is what makes those actions available to you at all.
Admin approvals work the same way: an administrator can approve a restricted action for someone else right in the app by confirming with their own password or second factor. The approval covers that one action only and doesn't change anyone's role. See The Packout Flow for how this plays out in fulfillment.
Account Recovery
If you ever can't get in, here are the ways back, easiest first:
- Another second factor you've already set up. This is the whole reason it's worth having more than one.
- One of your recovery codes.
- A password reset by email, if you still have your email but not your second factor.
- Get in touch with support. We'll need to confirm who you are before restoring access, so this route takes a little longer than the others -- but it is a real way back in, and we'll stay with you through it.
Worth separating out: identity verification is a different thing from two-factor authentication. It's a fraud check that only appears when it has been required on a specific account, and most accounts never see it. If it is ever required on yours, you'll see a banner and a prompt, and rating, buying labels, and everything else keeps working in the meantime. Separately, coming back in with a recovery code or a password reset is a good moment to set up a fresh second factor and generate new recovery codes.
FAQs
Which second factor should I use?
An authenticator app, with your recovery codes stored somewhere safe. Then add email or a linked provider as a backup, so losing your phone is a minor annoyance rather than a real problem.
I lost my phone with my authenticator app on it.
You're not stuck. Sign in with another factor you've set up or with a recovery code, then remove the old authenticator app and set up a new one. If you don't have either, get in touch with support -- we'll confirm who you are and get you back in.
Why can't I turn off my only second factor?
Because it would leave your account with just a password. Set up a replacement first and you'll be able to remove the original right after.
Is SMS good enough?
It's much better than nothing, and not as strong as an authenticator app -- moving a phone number to a new SIM is a real and well-documented attack. Use it as your backup rather than your main second factor if you can.
What does reporting a device do?
It blocks that device and lets our security team know something may be wrong. Do it for anything you don't recognize, and change your password at the same time.
Should I trust my work computer?
Remember devices that only you use. On a shared or public machine it's best to skip it, since anyone who sits down there later would get the same shortcut you do.
Do API keys use two-factor authentication?
No -- API keys sign in on their own. That's why it's worth scoping their permissions tightly and rotating them now and then. See API Keys and Connected Apps.