Two-factor authentication (2FA) adds an extra layer of security to your Gelato account. When it's turned on, signing in requires both your password and a six-digit code from an authenticator app on your phone.
This means that even if someone learns your password, they can't access your account without your mobile device.
2FA is optional. It's turned off by default, and you can enable or disable it at any time from your account settings.
What you'll need
An authenticator app installed on your phone, such as Microsoft Authenticator, Google Authenticator, or Authy.
Enabling two-factor authentication
Two-factor authentication is not available for users who don't log in using their e-mail and password (i.e. via Continue with Google, Facebook or Apple).
Sign in to your Gelato account.
Go to Settings / Profile and find the Two-factor authentication section.
Click Enable. Your account will show 2FA as Setup pending. It will be fully configured the next time you sign in.
You can keep using Gelato as normal. When you next sign out (or your session times out) and sign back in, you'll be prompted to finish the setup.
Completing setup at your next sign-in
Sign in with your email and password as usual.
When prompted, open your authenticator app and scan the on-screen QR code.
Your authenticator app will start generating a six-digit code that refreshes periodically.
Optionally, give the account a device name in your authenticator app so it's easy to identify.
Enter the current six-digit code to confirm.
Once confirmed, you'll be signed in and your settings will show two-factor authentication as active.
Signing in with 2FA turned on
After 2FA is active, each sign-in takes two steps:
Enter your email and password.
Enter the current six-digit code shown in your authenticator app.
Disabling two-factor authentication
Go to Settings and open the Two-factor authentication section.
Click Disable and confirm in the window that appears.
Your account will return to signing in with just your email and password.
You can re-enable 2FA again at any time.
Tips and troubleshooting
Codes refresh on a timer. If a code is rejected, wait for your authenticator app to generate the next one and try again.
Keep your device handy. You'll need your authenticator app each time you sign in, so make sure you have access to your phone.
Changing phones? Disable 2FA before switching devices, then re-enable it on your new phone to scan a fresh QR code.
2FA is enabled individually for each user. To guarantee full security, ensure that at least all Admin users have enabled 2FA.



