Two-factor sign-in

Two-factor sign-in adds a second step when you sign in to Tickiti: after your password, you enter a six-digit code from an authenticator app on your phone. The code changes every 30 seconds and only your phone can produce it, so your password on its own is not enough to get into your account.

What you need

An authenticator app on your phone. Tickiti uses standard time-based codes (TOTP), so any authenticator app works — for example Google Authenticator, Microsoft Authenticator or Authy.

Setting it up

  1. Open your account menu → Settings → Profile. In the Security card, click Set up next to Two-factor sign-in. (See Your profile.)
  2. On the Two-factor sign-in page, click Set up two-factor sign-in.
  3. If Tickiti asks you to confirm your password, enter it and click Confirm Password.
  4. Scan the QR code with your authenticator app. If you can’t scan it, add the account in the app by typing the Setup key shown under the code.
  5. Enter the six-digit code the app shows and click Confirm.

Tickiti confirms that two-factor sign-in is on. Click Continue to go back to Tickiti. From now on, every sign-in asks for a code.

Two-factor sign-in starts only once you have entered a code. If you leave the page before that, open it again from your profile and the same QR code is waiting for you.

Signing in with a code

  1. Sign in with your email address and password as usual — see Logging in.
  2. Tickiti asks for your authentication code. Open your authenticator app and enter the six-digit code it shows for your Tickiti account.
  3. Click Continue.

If the code is refused, the boxes clear: enter the code the app shows now, as each one lasts only 30 seconds. If codes are refused every time, check that your phone sets its date and time automatically — the codes are worked out from the phone’s clock.

When your account must use it

An administrator can require two-factor sign-in for selected users or for all staff (see System settings). If your account must use it and you have not set it up, Tickiti takes you to the Two-factor sign-in page with the message Your account must use two-factor sign-in. Set it up to continue. Follow the steps above; the rest of Tickiti opens once it is set up. The page also has a Log out link.

While your account must use two-factor sign-in, it cannot be turned off.

Turning it off

Once two-factor sign-in is on, your profile shows On and a Manage button. Manage opens the Two-factor sign-in page, where Turn off two-factor sign-in removes it; Tickiti may ask for your password first. The button is not offered while your account must use two-factor sign-in.

If you lose your phone

There are no backup or recovery codes: the code from your authenticator app is the only second step. If you lose your phone, replace it or remove the app, ask a system administrator to reset your two-factor sign-in. After the reset you sign in with your password alone. If your account must use two-factor sign-in, Tickiti then takes you straight to set it up again on your new phone; otherwise, set it up again from your profile.

Changing phones? While you still have the old phone, turn two-factor sign-in off and set it up again on the new one. If your account must use it, ask a system administrator to reset it instead.

For administrators

  • Requiring it — Who must use two-factor sign-in in System settings: Off, Selected users or All staff.
  • Choosing users and seeing who has set it up — Must use two-factor and the set-up badge in User management.
  • Resetting it after a lost device — a system administrator selects the user in User admin and clicks Reset two-factor.
  • A system administrator’s own device — another system administrator resets it. On a site hosted by Tickiti with no other system administrator, get in touch with Tickiti support.