Two-step verification

Two-step verification adds a 6-digit code from an authenticator app on your phone to your sign-in. Ressura asks for it before an admin connects a bank, because a bank holds your company's money; signing in never asks for it.

When Ressura asks for a code

An admin enters a code before Plaid's window opens to connect a bank or to reconnect one (see Your bank). Ressura asks once each time you sign in, and doesn't ask again until you sign out. An admin with no authenticator app sets one up right there, then carries on connecting.

Google's own 2-Step Verification doesn't count, even when you sign in with Google: Ressura asks for a code from your authenticator app.

Entering a code signs you out of Ressura in every other browser where you haven't entered one since signing in.

Setting it up

You need an authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator or 1Password.

  1. Open Account settings in Settings. Two-step verification is set up for you, not for your company, so every member can set it up.
  2. Under Two-step verification, choose Set up an authenticator app.
  3. Scan the QR code with your authenticator app. If you can't scan it, type the key shown below it into the app instead.
  4. Enter the 6-digit code the app shows, and choose Turn on.

The section then says On and lists Authenticator app with the date you added it. A wrong code is refused, and nothing is set up until a right one.

Adding a second app as a backup

A second authenticator app, on another phone or in a password manager, lets you in when you lose the first. Choose Add a second authenticator app, and enter a code from the app you already have if you haven't entered one since signing in. Then scan the new QR code and enter a code from the new app. It is listed as Authenticator app 2, and a code from either app works.

Removing an app

Choose Remove beside the app, and enter a code from any of your apps if you haven't entered one since signing in. Removing your last app warns that you'll be asked to set it up again before connecting a bank. Ressura's team is told whenever an app is removed, since someone taking over an account often starts there.

When you lose your phone

If you set up a second app, use it, then remove the lost one and add a new one.

If you have no app left, write to contact@ressura.com. Ressura removes your apps once the Owner or another admin of a company you belong to confirms in writing that the request is yours. If you are that company's only admin, Ressura confirms it with you on a video call, with photo ID. The removal is recorded in each of your companies' Activity in Settings as Two-step verification removed by Ressura, with whose confirmation it acted on. You then set up a new app the next time you connect a bank.

Members and roles says what an admin and a member can each do. Who can see what covers who can reach your company's data, and Cash & Bank is the Module that checks the bank accounts an admin connects.