Set Up Two-Factor Authentication
Settings → Security in the dashboard, under Two-factor authentication.
What it is
Section titled “What it is”Baiyar’s two-factor authentication is TOTP (time-based one-time password) — the same standard used by apps like Google Authenticator, Authy, and 1Password. Once it’s on, it becomes the step-up check for sensitive actions like changing your password or disabling 2FA itself, instead of an emailed code.
- Confirm your current password to start setup.
- Baiyar emails you a one-time code — enter it. This step-up proves it’s really you before showing any 2FA secrets.
- Baiyar shows a QR code (labeled with your email, under “Baiyar”, so it’s identifiable in your authenticator app) and a manual setup key as a fallback if you can’t scan it. Add it to your authenticator app.
- Enter the 6-digit code your app is now generating, to confirm the app is set up correctly.
Once confirmed, 2FA is active immediately.
Turning it off
Section titled “Turning it off”Disabling 2FA is guarded more heavily than turning it on: you need a current code from your authenticator app and a fresh one-time code emailed to you, both confirmed against your current password.