Two-factor authentication (2FA) adds a second step to signing in. After Google,
GitHub or your email link, Postbase asks for a 6-digit code from an
authenticator app on your phone. It’s optional and free on every plan.
Any app that supports time-based codes (TOTP) works: 1Password, Google
Authenticator, Microsoft Authenticator, Authy, Bitwarden and others. SMS codes
aren’t supported.
Turning it on
- Open Settings → Security and click Turn on.
- Name the device (for example “iPhone”) so you can tell your devices apart.
- Scan the QR code with your authenticator app, or type in the key shown
under it.
- Enter the 6-digit code the app shows and click Verify and turn on.
From then on, every new sign-in stops at Enter your code until you type a
current code. Sessions you’re already signed in on stay signed in.
Backup devices
Postbase doesn’t issue backup codes. Instead, add a second device as your
backup: Settings → Security → Add a backup device, and scan the new QR code
with another phone, a tablet, or a password manager that stores codes. When you
sign in, pick whichever device you have to hand.
You can add up to 5 devices.
A password manager that syncs codes (such as 1Password or Bitwarden) makes a
good backup, since it survives losing your phone.
Removing a device or turning 2FA off
In Settings → Security, click Remove next to a device and enter a current
code. If that device is lost, a code from any of your other devices works.
Removing your last device turns 2FA off.
If you’ve lost every device
Email team@postbase.so
from the address you sign in with. We’ll confirm it’s you, then turn 2FA off on
your account so you can sign in and set it up again. Your scheduled posts keep
going out in the meantime.
2FA protects signing in to the app. It also applies when you connect an AI tool
like Claude or Cursor: the consent screen asks for your code before you can
approve it.
API keys and AI tools you’ve already connected keep
working after you turn 2FA on, since they don’t use your sign-in. Revoke any you
don’t recognise on the AI & API page.
Self-hosting
2FA uses Supabase Auth’s TOTP support, which is on by default in every Supabase
project. Run the migrations in supabase/migrations so the database requires a
verified session for workspace data when a user has 2FA on. To reset a user who
has lost every device, delete their factors under Authentication → Users in
the Supabase dashboard.