Skip to main content

Using an Authenticator App

Authenticator App Login

What is it?

The authenticator app adds an extra security step when signing in.

After entering your email address and password, you will also enter a 6-digit code from an authenticator app on your phone, such as:

  • 1Password
  • Google Authenticator
  • Microsoft Authenticator

This helps protect your account, even if someone knows your password.


Before you start

You will need:

  • your normal Marlinspike login details
  • a phone or device with an authenticator app installed

If your company requires extra login security, Marlinspike may ask you to set this up before you can continue.


Setting up the authenticator app

  1. Sign in to Marlinspike.
  2. Open your user settings.
  3. Go to the security section.
  4. Choose Authenticator app as your preferred sign-in method.
  5. Click the button to set up the app.
  6. A window will open with a QR code.
  7. Open your authenticator app and add a new account.
  8. Scan the QR code with your phone.
  9. Your app will show a 6-digit code.
  10. Enter that code in Marlinspike.
  11. Finish the setup.

After setup is complete, Marlinspike will also show backup codes.

Important: Save these backup codes in a safe place. They can help you sign in if you lose access to your phone.

[Add screenshot: security settings with “Set up authenticator app” button]

[Add screenshot: QR code setup window]

[Add screenshot: backup codes after setup]


Signing in with the authenticator app

Once setup is complete, signing in works like this:

  1. Enter your email address and password.
  2. Marlinspike will ask for a security code.
  3. Open your authenticator app.
  4. Find your Marlinspike account.
  5. Enter the current 6-digit code.
  6. Continue signing in.

[Add screenshot: login verification screen for authenticator app]


Using a backup code

If you do not have access to your authenticator app, you can use one of your backup codes instead.

To do this:

  1. Sign in with your email address and password.
  2. When Marlinspike asks for a security code, enter one of your saved backup codes.
  3. Continue signing in.

Important:

  • each backup code can only be used once
  • after using one, it will no longer work again

Removing the authenticator app

You can remove the authenticator app from your own account in your security settings.

If needed, an administrator can also remove it for you from the user management screen.

When the authenticator app is removed:

  • login with app codes will stop working
  • existing backup codes will also be removed

Notes for users working on local and online Marlinspike

You only need to set up the authenticator app once.

The same authenticator app can be used for both:

  • the online Marlinspike environment
  • the local Marlinspike environment

Troubleshooting

The code does not work

Check the following:

  • you entered the newest 6-digit code
  • the time on your phone is correct
  • you scanned the correct QR code
  • you are using the correct Marlinspike account in your app

If it still does not work, try a backup code.

I lost my phone

Use one of your backup codes to sign in.

If you do not have backup codes anymore, contact your administrator so they can remove the authenticator app from your account and let you set it up again.

I closed the backup code screen without saving them

If you are still signed in, remove the authenticator app and set it up again. A new set of backup codes will be shown during setup.


Summary

The authenticator app gives you a safer login process:

  • sign in with password
  • confirm with a code from your phone
  • keep backup codes in case your phone is unavailable