Skip to main content

Account Security: Two-Factor Authentication & Passkeys

How admins and members secure their accounts with passkeys and two-factor authentication: where to find security settings, how to add a passkey, and how to set up 2FA with backup codes.

CustomerHub gives every user two ways to make their account harder to break into: passkeys and two-factor authentication (2FA). Both are optional and both are managed by the account holder. Admins can use them on any theme; for your users, they require the Elevate theme. We recommend passkeys as the simplest and strongest option — you will be prompted to add one the first time you sign in.

ℹ️ Admins can use two-factor authentication and passkeys whichever theme the site uses. For your users, these options require the Elevate theme — on an older theme, users will not see the Two-factor authentication and Passkeys cards on their profile.


🔐 Where to find your security settings

Security settings live on your own profile. Where you find them depends on whether you are signing in as an admin or as a user.

  • Admins — Click your avatar in the bottom-left corner, then choose My profile.

  • Users — Open your Profile, then select the Account tab.

Both screens show the same three cards: Password, Two-factor authentication, and Passkeys.

Admin view

User view

Users see the same options on the Account tab of their profile, if your member site uses the Elevate theme. On an older theme, the Account tab shows the Password card only.

ℹ️ Each person manages their own 2FA and passkeys. Admins cannot enable 2FA on a user’s behalf, and cannot see a user’s backup codes.


🔑 Adding a passkey

A passkey lets you sign in with no password at all — using Face ID, Touch ID, Windows Hello, or a hardware security key instead. The passkey is stored on your device, so there is nothing to remember and nothing an attacker can steal by guessing.

On your profile, find the Passkeys card and click Add passkey. Your browser or device takes over from there and prompts you to confirm with your fingerprint, face, device PIN, or security key. The exact prompt depends on your browser and operating system.

💡 You can add more than one passkey — for example, one on your laptop and one on your phone. Add a passkey on each device you regularly use to sign in from.


🚪 Signing in with a passkey

After you add a passkey, click Sign in with a passkey on the login screen and confirm with your device. You will not need to type your email or password.

📄 For every other way to get into your account — email and password, Continue with Google, login links, and resetting a forgotten password — see Logging in to CustomerHub.


🛡️ Setting up two-factor authentication

With 2FA turned on, signing in requires your password and a six-digit code from an authenticator app on your phone. You will need an authenticator app such as Google Authenticator, Microsoft Authenticator, Authy, or 1Password before you start.

On your profile, find the Two-factor authentication card and click Enable 2FA. Then:

  1. Scan the QR code with your authenticator app. If you cannot scan it, use the Or enter this code manually key shown underneath — the copy icon puts it on your clipboard.

  2. Save your backup codes. CustomerHub shows eight one-time codes and a Download codes button. Each code can be used once if you ever lose access to your authenticator app.

  3. Enter the 6-digit code from your authenticator app, then click Verify & enable.

⚠️ Save your backup codes before you finish. They are your only way back in if you lose your phone. Use Download codes and store them somewhere you can still reach if your phone is lost — ideally a password manager or vault separate from the one holding your CustomerHub password. CustomerHub does not keep a copy of your codes and cannot retrieve them for you. The QR code and manual key in the screenshot above are blurred because they are unique to each account and should never be shared.

Once 2FA is enabled, the card shows that two-factor authentication is on. From then on you will be asked for a six-digit code each time you sign in with your email and password.


❓ Frequently asked questions

Do I need both 2FA and a passkey?

No. Either one meaningfully improves your account security, and you can use both. CustomerHub recommends passkeys first — they are quicker to use and there is no code to type or password to steal. 2FA is a good addition if you prefer a verification step, or if you sign in from shared or managed computers where you cannot register a passkey.

What if I lose my phone and cannot get a 2FA code?

Use one of the eight backup codes you saved when you enabled 2FA. Each works once. Because those codes are stored wherever you chose to save them, CustomerHub cannot look them up for you — so if you have lost both your authenticator app and your backup codes, contact CustomerHub support and we will help you from there.

Can I require 2FA for all of my users?

Not at this time. 2FA is deliberately opt-in, so each person chooses whether to turn it on from their own Account tab — the goal is that anyone needing extra security can add it. If you want to raise the security bar for your users, encouraging passkeys is the better route today — and note that users only get 2FA and passkey options if your member site uses the Elevate theme.

I got a passkey prompt when signing in but I do not want one yet.

That prompt is expected — CustomerHub offers to set up a passkey at first sign-in because it is the recommended option. You can dismiss it and continue signing in normally, and add a passkey later from your profile whenever you are ready.

I sign in with Google. Does 2FA still apply?

Signing in with Google uses Google’s own security, including any two-step verification you have set up there. CustomerHub’s 2FA applies when you sign in with your CustomerHub email and password.

Did this answer your question?