4 min read

Securing Your Account: Password, 2FA, Passkeys & Devices

The complete guide to eGrow's Security settings β€” set or change your password, turn on two-factor authentication (authenticator app or email) with recovery codes, require 2FA for your team, add passkeys for fingerprint/face sign-in, and review and log out devices and trusted devices.

Your eGrow account holds your customers, orders, and revenue data β€” so keeping it secure matters. The Security settings are where you control how you sign in and which devices can access your account. Open them at https://v2.egrow.com/settings/security.

The page has four sections, top to bottom: Password, Two-factor authentication, Passkeys, and Devices. This guide covers every option in each.

Note: for sensitive changes (like disabling two-factor or removing a device), eGrow shows a "Confirm it's you" prompt asking for your password, a code, or a passkey before it proceeds β€” a safeguard so no one can weaken your security from an already-open session.

Password

The first card lets you set or change your account password. Click Change password (or Create password if your account was created via social/SSO login and has none yet) and:

  • Enter a new password and confirm it β€” the two must match.
  • Use the show/hide eye icon to check what you typed.
  • Click Save.

Choose something long and unique that you don't reuse elsewhere.

Two-factor authentication (2FA)

Two-factor adds a second step at login, so a stolen password alone isn't enough to get in. A status pill at the top shows whether it's On or Off.

Turning it on

Click Turn on to start the enrollment flow:

  1. Choose a method:
    • Authenticator app (TOTP) β€” recommended. Works with Google Authenticator, Authy, and similar apps.
    • Email β€” codes are sent to your email address.
  2. Verify:
    • For the authenticator app, scan the QR code with your app (or copy the shown secret key if you can't scan), then enter the 6-digit code it generates.
    • For email, enter the code that was sent to your inbox.
  3. Save your recovery codes (see below) to finish.

Recovery codes

When you enable 2FA, eGrow gives you a set of one-time recovery codes. These let you back into your account if you ever lose your phone or can't receive codes. Save them somewhere safe β€” each works once. From the Security page you can Regenerate them at any time (which invalidates the old set).

Managing 2FA once it's on

  • The card shows your active method (authenticator app or email).
  • Disable turns 2FA off (after the "Confirm it's you" check).
  • Require 2FA for members β€” an org-wide toggle for admins that forces every team member to set up two-factor before they can use eGrow. Strongly recommended if your team handles customer data.

Tip: the authenticator-app method is more secure than email β€” email codes are only as safe as your inbox. Use an app, and keep your recovery codes somewhere your team can't lose them.

Passkeys

A passkey lets you sign in with your device's built-in security β€” a fingerprint, face scan, or PIN β€” instead of typing a password. It's both faster and harder to phish. In this section you can:

  • Add a passkey β€” click Add and follow your device/browser prompt to register it (Touch ID, Windows Hello, a security key, etc.).
  • See each registered passkey with its name and details.
  • Remove a passkey you no longer use.

You can register more than one (say, your laptop and your phone) so you're never locked out.

Devices

The last section shows where your account is signed in, so you can spot and cut off anything you don't recognize.

  • Your devices β€” one row per device that's logged in, with its type, location, and a count if it has several sessions. Your current device is marked This device. For any other device, click Log out to end its session remotely. Click a device to see its full detail.
  • Trusted devices β€” devices you told eGrow to remember (so they skip the 2FA step). You can Remove a trusted device, which forces two-factor again on its next login.

Important: if you ever see a device or location you don't recognize, log it out immediately, then change your password and regenerate your recovery codes. That fully cuts off the intruder.

A quick security checklist

  • βœ… Set a strong, unique password.
  • βœ… Turn on two-factor with an authenticator app.
  • βœ… Save your recovery codes somewhere safe.
  • βœ… Add a passkey for fast, phishing-resistant sign-in.
  • βœ… Review your devices periodically and log out anything unfamiliar.
  • βœ… Admins: require 2FA for all members.

What's next

Security works hand in hand with access control β€” decide who can do what in Managing Users & Teams, and set up the rest of your workspace from your account & profile.

Was this article helpful?

Previous

πŸ“„ Team management

Next

Screen Recording: Monitoring Your Team's Work πŸ–₯️

Related Articles

Can't find what you're looking for?

Our support team is here to help. Submit a ticket and we'll get back to you as soon as possible.

Contact Support
Need Help?