Home/Help Center/Two-factor authentication

Account, billing and security

Turn on two-factor authentication

Enable 2FA on your VGraple CRM login with an authenticator app in two minutes: scan the QR code, confirm a code, save the backup codes, and know how to turn it off.

By Chirag Darji · Updated 27 Aug 2026 · 5 min read

On this page
  1. Before you start
  2. Steps
  3. What you will see
  4. Turning it off
  5. Settings and options
  6. Troubleshooting
  7. What changes for the Android app
  8. If a teammate cannot enable it
  9. Backup codes, explained
  10. Moving to a new phone
  11. For owners and admins
  12. Why this matters more than usual
Team members in VGraple CRM with owner, admin and agent roles and their permissions

Two-factor authentication (2FA) adds a six-digit code from an authenticator app to your password at sign-in, so a leaked or reused password alone cannot open the account that holds every customer conversation. It is set per user from the profile page and takes about two minutes.

Two-factor authentication: first 5 of 6 steps

  1. 1Go to Settings
  2. 2Click Enable
  3. 3Open the authenticator app
  4. 4Enter the 6-digit code
  5. 5Save the backup codes
The steps on this page, in order.

Before you start

  • Install an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, Authy, 1Password and Bitwarden all work).
  • Have somewhere safe to store backup codes: a password manager, not a screenshot in the gallery.
  • If you sign in with Google, your Google account's own two-step verification is what protects you; the steps below apply to email and password accounts.

Steps

  1. Go to Settings, then Profile, and find the Two-factor authentication section.
  2. Click Enable. A QR code and a text secret appear.
  3. Open the authenticator app, add an account, and scan the QR code (or type the secret if the camera is unavailable).
  4. Enter the 6-digit code the app shows to confirm, and click Verify.
  5. Save the backup codes shown once. Each code works one time and replaces the authenticator when you cannot reach your phone.
  6. Sign out and back in to see the new step: password first, then the code.

Profile settings in VGraple CRM with two-factor authentication

What you will see

The profile page shows two-factor authentication as enabled with a Disable option. At every sign-in with email and password, after the password you are asked for the current code from the app; a backup code works in its place. The audit log records that 2FA was enabled on your account.

Turning it off

Click Disable in the same section, enter your password and a current code (or a backup code), and confirm. Turn it back on with a fresh QR code whenever you like; old codes stop working the moment it is disabled.

Settings and options

SettingWhat it doesDefault
EnableStarts setup with a QR code and secretOff
VerifyConfirms the first code and activates 2FARequired to finish
Backup codesOne-time codes for use without the phoneShown once at activation
DisableTurns 2FA off after password and codeRequires both

Troubleshooting

SymptomLikely causeFix
"Invalid code" during setupPhone clock drift, or the code expired while typingLet the phone set time automatically and try the next code
Lost the phone and the backup codesNo second factor availableFollow the login and 2FA recovery guide; an Owner can request a reset through support
Code accepted on web but not on the Android appOld app versionUpdate the app from the Play Store
QR code will not scanScreen brightness or a very small windowType the text secret into the app instead

What changes for the Android app

The app signs in with the same email and password and asks for the code once; after that the phone keeps its own session, rotating its token every six hours and expiring after 24 hours idle, so you are not asked for a code on every launch. If you sign in on a second phone, that device asks for the code too. Revoking a session from organisation sessions forces a fresh sign-in, code included.

If a teammate cannot enable it

The section is on every user's own profile page; nobody can enable it for someone else. A teammate who does not see it is signed in with Google, which carries Google's own second factor instead. Ask them to turn on two-step verification in their Google account, which then protects their VGraple CRM sign-in as well.

Backup codes, explained

You receive a short list of one-time codes when 2FA is activated. Each works exactly once in place of the authenticator code, and the list is shown only at activation. Store them in a password manager or print them and keep them where only you can reach them. When you have used most of them, disable and re-enable 2FA to get a fresh set. Anyone who holds a backup code and your password can sign in, so treat the list as a key, not a note.

Moving to a new phone

Before wiping the old phone, open the authenticator app on the new phone and use its transfer feature (Google Authenticator and Authy both offer one), or disable 2FA in VGraple CRM from the old phone and re-enable it on the new one. If the old phone is already gone, sign in with a backup code and set 2FA up again with a new QR code; the old app entry stops working the moment the new one is verified.

For owners and admins

Encourage the whole team to enable 2FA, starting with anyone who can send broadcasts, change templates or export contacts. The audit log records 2FA enablement per user, so you can check coverage from the member list without asking. Combine it with periodic reviews of organisation sessions and with the Owner-only rule on secrets, and the account is well protected against the common attacks.

Why this matters more than usual

A CRM login can read every customer's number and send messages in the business's name. Password reuse across sites is the most common way such accounts are taken over. Pair 2FA on the login with Meta's two-step verification PIN on the WhatsApp number, and review organisation sessions occasionally to see who is signed in and from where.

Frequently asked questions

Which apps work?
Any TOTP authenticator: Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden.
What if I lose my phone?
Use one of the backup codes shown when you enabled 2FA. If those are lost too, an Owner can contact support to reset it after identity checks; see the login recovery guide.
Does 2FA apply to Google sign-in?
Google sign-in relies on your Google account's own second factor; the authenticator step here applies to email and password logins.
Can the Owner force 2FA for everyone?
Not as a workspace switch today. Ask teammates to enable it from their profile; the audit log shows who has.
Is this the same as the WhatsApp two-step PIN?
No. This protects your VGraple CRM login. The two-step verification PIN protects the WhatsApp number's registration at Meta. Use both.
Does the Android app ask for the code?
Yes, at sign-in with email and password. Sessions on the phone then stay signed in as usual.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.