On this page

Two-factor authentication (2FA) adds a six-digit code from an authenticator app to your password at sign-in, so a leaked or reused password alone cannot open the account that holds every customer conversation. It is set per user from the profile page and takes about two minutes.
Two-factor authentication: first 5 of 6 steps
- 1Go to Settings
- 2Click Enable
- 3Open the authenticator app
- 4Enter the 6-digit code
- 5Save the backup codes
Before you start
- Install an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, Authy, 1Password and Bitwarden all work).
- Have somewhere safe to store backup codes: a password manager, not a screenshot in the gallery.
- If you sign in with Google, your Google account's own two-step verification is what protects you; the steps below apply to email and password accounts.
Steps
- Go to Settings, then Profile, and find the Two-factor authentication section.
- Click Enable. A QR code and a text secret appear.
- Open the authenticator app, add an account, and scan the QR code (or type the secret if the camera is unavailable).
- Enter the 6-digit code the app shows to confirm, and click Verify.
- Save the backup codes shown once. Each code works one time and replaces the authenticator when you cannot reach your phone.
- Sign out and back in to see the new step: password first, then the code.

What you will see
The profile page shows two-factor authentication as enabled with a Disable option. At every sign-in with email and password, after the password you are asked for the current code from the app; a backup code works in its place. The audit log records that 2FA was enabled on your account.
Turning it off
Click Disable in the same section, enter your password and a current code (or a backup code), and confirm. Turn it back on with a fresh QR code whenever you like; old codes stop working the moment it is disabled.
Settings and options
| Setting | What it does | Default |
|---|---|---|
| Enable | Starts setup with a QR code and secret | Off |
| Verify | Confirms the first code and activates 2FA | Required to finish |
| Backup codes | One-time codes for use without the phone | Shown once at activation |
| Disable | Turns 2FA off after password and code | Requires both |
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| "Invalid code" during setup | Phone clock drift, or the code expired while typing | Let the phone set time automatically and try the next code |
| Lost the phone and the backup codes | No second factor available | Follow the login and 2FA recovery guide; an Owner can request a reset through support |
| Code accepted on web but not on the Android app | Old app version | Update the app from the Play Store |
| QR code will not scan | Screen brightness or a very small window | Type the text secret into the app instead |
What changes for the Android app
The app signs in with the same email and password and asks for the code once; after that the phone keeps its own session, rotating its token every six hours and expiring after 24 hours idle, so you are not asked for a code on every launch. If you sign in on a second phone, that device asks for the code too. Revoking a session from organisation sessions forces a fresh sign-in, code included.
If a teammate cannot enable it
The section is on every user's own profile page; nobody can enable it for someone else. A teammate who does not see it is signed in with Google, which carries Google's own second factor instead. Ask them to turn on two-step verification in their Google account, which then protects their VGraple CRM sign-in as well.
Backup codes, explained
You receive a short list of one-time codes when 2FA is activated. Each works exactly once in place of the authenticator code, and the list is shown only at activation. Store them in a password manager or print them and keep them where only you can reach them. When you have used most of them, disable and re-enable 2FA to get a fresh set. Anyone who holds a backup code and your password can sign in, so treat the list as a key, not a note.
Moving to a new phone
Before wiping the old phone, open the authenticator app on the new phone and use its transfer feature (Google Authenticator and Authy both offer one), or disable 2FA in VGraple CRM from the old phone and re-enable it on the new one. If the old phone is already gone, sign in with a backup code and set 2FA up again with a new QR code; the old app entry stops working the moment the new one is verified.
For owners and admins
Encourage the whole team to enable 2FA, starting with anyone who can send broadcasts, change templates or export contacts. The audit log records 2FA enablement per user, so you can check coverage from the member list without asking. Combine it with periodic reviews of organisation sessions and with the Owner-only rule on secrets, and the account is well protected against the common attacks.
Why this matters more than usual
A CRM login can read every customer's number and send messages in the business's name. Password reuse across sites is the most common way such accounts are taken over. Pair 2FA on the login with Meta's two-step verification PIN on the WhatsApp number, and review organisation sessions occasionally to see who is signed in and from where.