## Two-factor authentication is required

Perimeter enforces TOTP two-factor authentication for every account. There is no way to skip it and no product page renders until it is enabled.

## Setting it up

The setup flow has three steps and is forward-only — there is no back button.

**1. Confirm your password.** Re-enter your current password.

**2. Save your recovery codes.** You'll see a QR code and a copyable secret. Scan the QR with any TOTP authenticator app (1Password, Authy, Google Authenticator, Microsoft Authenticator — anything standards-compliant). Perimeter uses standard 6-digit codes on a 30-second period.

You'll also get a set of one-time backup codes. **Save them somewhere you can reach without your phone.** You must confirm you've saved them before continuing.

**3. Confirm.** Enter the current 6-digit code from your app. Two-factor is now enabled and you land on your dashboard.

## Signing in

After your email and password, you'll be asked for a 6-digit code.

If you don't have your authenticator, choose **Use a backup code** and enter one of the codes you saved. Backup codes are **single-use** — each one works once. Switching between the two inputs clears whatever you typed and any error message.

## Sessions

Sessions last 24 hours and refresh as you use them. You can see and manage them under **Settings → Security**, which lists your active sessions with a Revoke button on each and a **Revoke Other Sessions** action to sign out everywhere else.

Some administrative roles have deliberately shorter session limits.

## Changing your password

**Settings → Security → Password** opens a change-password dialog in place. You'll need your current password.

## Forgot your password

Use **Forgot password** on the sign-in screen. For your protection, this screen always reports that an email has been sent, whether or not the address exists. Reset links expire after one hour.

Sign-in, two-factor verification, backup-code entry and password reset are all rate-limited.

## Lost your authenticator and your backup codes

Ask a workspace administrator to reset your two-factor enrollment from **Settings → Members → Reset 2FA**. You'll go through setup again at your next sign-in.

If you are the only administrator and cannot get in, contact support — this cannot be self-served, by design.

## Single sign-on

Workspaces can be configured to sign in with Google, Microsoft Entra ID or Okta. When SSO is configured, those options appear on the sign-in screen. Ask your administrator whether it's available for your workspace.
