> ## Documentation Index
> Fetch the complete documentation index at: https://trybloom.co.uk/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Two-factor authentication

> Add a second step to sign-in and keep your account safe, even if your password leaks.

Your Bloom account holds sensitive client information, so it deserves more protection than a password alone. Two-factor authentication (often called 2FA or TOTP) adds a second step to sign-in: a 6-digit code from an authenticator app on your phone. Even if someone gets hold of your password, they can't get into your account without your device. Setup takes about two minutes, and in this guide we'll cover it from top to bottom.

## What you'll need

Bloom works with any standard authenticator app. If you already use one, you're ready to go. If not, all of these are free:

* **Google Authenticator** (iOS and Android)
* **Microsoft Authenticator** (iOS and Android)
* **Apple Passwords** (built into iPhone, iPad, and Mac)
* **1Password**, **Authy**, or any other app that supports authenticator codes

## Turning it on

Head to **Settings**, then **Profile**, and find the **Two-factor authentication** card:

<Frame>
  <img src="https://mintcdn.com/bloompracticemanagement/fJ2R2HXvfbSpNno5/images/two-factor-authentication/image.png?fit=max&auto=format&n=fJ2R2HXvfbSpNno5&q=85&s=05707a33e44f379d8f9e4bfbd2893364" alt="Two-factor authentication card in profile settings" width="1722" height="238" data-path="images/two-factor-authentication/image.png" />
</Frame>

<Steps>
  <Step title="Start setup">
    Select **Enable two-factor authentication**. Bloom generates a QR code and a setup key that are unique to your account.
  </Step>

  <Step title="Scan the QR code">
    Open your authenticator app, choose to add a new account, and scan the QR code. Can't scan? Enter the setup key manually instead - it's shown just below the code.

    <Frame>
      <img src="https://mintcdn.com/bloompracticemanagement/fJ2R2HXvfbSpNno5/images/two-factor-authentication/image-1.png?fit=max&auto=format&n=fJ2R2HXvfbSpNno5&q=85&s=f8fd8941b69109715a8738965db63dc1" alt="QR code and setup key during two-factor setup" width="1722" height="870" data-path="images/two-factor-authentication/image-1.png" />
    </Frame>
  </Step>

  <Step title="Confirm with a code">
    Your app will now show a 6-digit code for Bloom that changes every 30 seconds. Type it in and select **Verify and enable**.
  </Step>

  <Step title="Save your backup codes">
    Bloom shows you 8 backup codes, once. Select **Copy codes** and store them somewhere safe, like a password manager.

    <Frame>
      <img src="https://mintcdn.com/bloompracticemanagement/fJ2R2HXvfbSpNno5/images/two-factor-authentication/image-2.png?fit=max&auto=format&n=fJ2R2HXvfbSpNno5&q=85&s=ba8ff129f32f8118dd6ef96a7328cf0d" alt="Backup codes shown once after enabling two-factor authentication" width="1722" height="546" data-path="images/two-factor-authentication/image-2.png" />
    </Frame>
  </Step>
</Steps>

Once that's done, the card shows **Enabled** and your account is protected:

<Frame>
  <img src="https://mintcdn.com/bloompracticemanagement/fJ2R2HXvfbSpNno5/images/two-factor-authentication/image-3.png?fit=max&auto=format&n=fJ2R2HXvfbSpNno5&q=85&s=458908d9e5c677d55407a5c64c7c6276" alt="Two-factor authentication enabled" width="1722" height="222" data-path="images/two-factor-authentication/image-3.png" />
</Frame>

## Backup codes

Backup codes are your way back in if you lose access to your authenticator app. A few things to know:

* Each code signs you in **once**, then it stops working.
* They're shown **only at setup** - Bloom stores them securely and can't show them again.
* You can use one anywhere Bloom asks for a verification code, including when turning two-factor authentication off.

<Warning>
  Treat backup codes like passwords. Don't email them to yourself or leave them in your downloads folder - a password manager or a printed copy somewhere safe is best.
</Warning>

## Signing in

With two-factor authentication on, signing in takes two steps. Enter your email and password as usual, then Bloom asks for your verification code:

<Frame>
  <img src="https://mintcdn.com/bloompracticemanagement/fJ2R2HXvfbSpNno5/images/two-factor-authentication/image-4.png?fit=max&auto=format&n=fJ2R2HXvfbSpNno5&q=85&s=e6b0ab84648c3e4842757af1289b0d38" alt="Two-step verification during sign-in" width="768" height="784" data-path="images/two-factor-authentication/image-4.png" />
</Frame>

Open your authenticator app, find your Bloom account, and enter the 6-digit code it shows. A backup code works here too.

<Note>
  Codes refresh every 30 seconds, and each code works once. If a code is rejected, wait for your app to show the next one and try again.
</Note>

## Turning it off

You can remove two-factor authentication at any time:

1. Go to **Settings**, then **Profile**.
2. On the **Two-factor authentication** card, select **Disable**.
3. Enter a code from your authenticator app (or a backup code) to confirm.

Your next sign-in will be back to just email and password. You can re-enable it whenever you like - you'll get a fresh QR code and a new set of backup codes.

<Tip>
  Getting a new phone? Sign in before you wipe your old one, disable two-factor authentication, then re-enable it with the new device. If your old phone is already gone, use a backup code to sign in.
</Tip>

## Lost your device?

* **Have a backup code?** Use it to sign in, then disable and re-enable two-factor authentication with your new device.
* **Out of backup codes?** [Contact us](https://www.trybloom.co.uk/contact) and we'll verify your identity and remove two-factor authentication from your account so you can set it up again.
