Password and two-factor authentication (2FA)
Changing your password, setting up 2FA with an authenticator app, backup codes and what to do if you lose access.
Your password is the key to your account; two-factor authentication (2FA) is its second lock. This page explains how to change your password, how to set up 2FA, and what to do if you lose access.
Changing your password
- In the app, go to User Settings → Account & Security.
- In the Sign-in details section, choose Change password on the password row.
- Verify your identity with your current password and set your new one.
Your password is not kept in plain text on our servers; it is stored as an Argon2 hash — meaning no one, including us, can read it. Choose a strong password you use nowhere else; a password manager makes this easy.
Setting up two-factor authentication (2FA)
On TEBHOS, 2FA works with an authenticator app you install on your phone (the TOTP standard — any of Aegis, Ente Auth, Google Authenticator, Microsoft Authenticator and the like will do):
- In User Settings → Account & Security → Security, start the authenticator-app setup.
- Scan the QR code on screen with your authenticator app (or enter the provided key manually).
- Confirm the setup by entering the 6-digit code the app generates.
When setup completes you are given backup codes. Save them somewhere safe: if you lose your phone, these codes let you into your account. You can regenerate your backup codes from the same section at any time; the old ones become invalid immediately.
With 2FA on, every sign-in asks for the current code from your authenticator app alongside your password.
Turning 2FA off
You can turn two-factor authentication off from the Security section; for safety you are first asked to re-verify your identity. We do not recommend turning it off — 2FA is the second lock that keeps your account standing even if your password leaks.
If you lose access
- No phone, but you have your backup codes: when asked for a code at sign-in, use one of your backup codes. Each backup code works once.
- No backup codes either: write to [email protected] from the email address registered to your account. After verifying your identity we will help you. This process is deliberately slow and careful, to protect your account.
- Forgot your password: use the password-reset path on the sign-in screen; the reset link is sent to the email address registered to your account.
The support team will never ask for your password or your authenticator code. If you receive such a request, do not respond and report it to us: Reporting bugs and abuse.