Two-Factor Authentication (2FA) & Account Security
Secure your account and database infrastructure with TOTP authenticator apps and emergency backup recovery codes.
Two-Factor Authentication (2FA) & Account Security
Two-Factor Authentication (2FA) adds an essential second layer of defense to your NoCodeBackend account. By requiring both your password and a rotating 6-digit verification code from your smartphone, 2FA prevents unauthorized access even if your password is leaked or compromised.
1. Overview: Why Enable 2FA?
Your NoCodeBackend account controls critical production infrastructure:
- Live production databases and relational schemas.
- Database master secret keys and REST API access tokens.
- Cloudflare R2 storage credentials.
- Connected Stripe payment configurations and customer subscription policies.
Enabling 2FA ensures that even if an attacker gains access to your primary email and password, they cannot access your dashboard, modify your schemas, or read your data without physical access to your authenticator device.
2. Supported Authenticator Apps
NoCodeBackend utilizes the industry-standard Time-Based One-Time Password (TOTP) protocol (RFC 6238). You can use any standard authenticator app, including:
- Google Authenticator (iOS & Android)
- Apple Passwords / iOS Keychain (Built into iOS 15+ and macOS)
- 1Password / Bitwarden / Dashlane (Desktop & Mobile)
- Microsoft Authenticator (iOS & Android)
- Twilio Authy (iOS & Android)
3. Step-by-Step Guide: Enabling 2FA
Step 3.1: Navigate to Security Settings
- Log in to your NoCodeBackend dashboard.
- In the top-right profile menu or sidebar, select Security (or navigate directly to
/security). - Under the Two-Factor Authentication (2FA / TOTP) section, click Enable 2FA.
Step 3.2: Scan the QR Code
- Open your authenticator app on your smartphone or password manager.
- Tap Add Account or the + icon, and select Scan QR Code.
- Point your camera at the QR code displayed in the NoCodeBackend modal.
- Manual Entry Alternative: If you cannot scan the QR code, click Can't scan? Copy code to reveal the secret text key and manually paste it into your app.
- Your authenticator app will display a new entry:
NoCodeBackend (<your-email>)with a rotating 6-digit code.
Step 3.3: Verify and Activate
- In the NoCodeBackend modal, enter the current 6-digit verification code displayed in your authenticator app.
- Click Verify and Enable.
- Once verified, 2FA is immediately activated across your account.
4. Emergency Backup Recovery Codes
When you activate 2FA, NoCodeBackend generates 10 single-use emergency backup recovery codes.
Why Backup Codes Are Critical
If your smartphone is lost, damaged, stolen, or reset, your authenticator app will be inaccessible. Backup codes are your only self-serve way to regain access to your account.
Best Practices for Storing Backup Codes:
- Copy or Download: Click Copy All or Download as Text File immediately during the setup process.
- Offline Storage: Store the codes in a secure, encrypted password vault or print a copy and keep it in a secure location.
- Single-Use: Each backup code can only be used once. Once used, it is permanently consumed.
5. Signing In with 2FA
Once 2FA is enabled, signing in follows a two-step flow:
- Enter your Email and Password on the login page.
- You will be redirected to the Two-Factor Verification screen (
/auth/2fa). - Open your authenticator app and enter the current 6-digit TOTP code.
- Click Verify & Sign In to access your dashboard.
Using a Backup Code Instead
If you do not have your phone:
- On the 2FA verification screen, click Use an emergency backup code.
- Paste one of your saved 10-character backup codes.
- Click Verify. You will be logged in, and that specific code is marked as consumed.
6. Managing 2FA & Regenerating Backup Codes
Checking Remaining Backup Codes
Navigate to /security at any time to view your 2FA status and the number of unused backup codes remaining (e.g., 8 of 10 codes remaining).
Regenerating Backup Codes
If you have used several backup codes or suspect they were exposed:
- Go to
/security. - Click Regenerate Backup Codes.
- Confirm the action. A brand new set of 10 backup codes will be generated, and all previous backup codes will be instantly invalidated.
Disabling 2FA
If you are changing phones or need to disable 2FA:
- Go to
/security. - Click Disable 2FA.
- Enter your current password or 6-digit TOTP code to confirm your identity.
- 2FA will be removed from your account. You can re-enable it with your new device at any time.
7. Troubleshooting
Common Errors
Error: Invalid or expired 2FA code
- Cause 1 (Time Drift): TOTP codes change every 30 seconds and rely on strict clock synchronization. If your phone's clock is off by more than 30 seconds from internet time, the code will fail.
- Resolution: In your phone's settings, ensure Date & Time is set to Set Automatically (Network Time). In Google Authenticator on Android, go to
Settings > Time correction for codes > Sync now.
- Resolution: In your phone's settings, ensure Date & Time is set to Set Automatically (Network Time). In Google Authenticator on Android, go to
- Cause 2 (Typo or Lag): You entered the code right as the 30-second window expired.
- Resolution: Wait for the next 6-digit code to appear in your app and enter it immediately.
Error: Lost authenticator device and have no backup codes
- Cause: You switched or lost your phone without saving your 10 backup codes.
- Resolution: Contact NoCodeBackend Support via email from your verified account address. Identity verification and proof of account ownership will be required before manual 2FA recovery can be performed.
