Using an Authenticator App
Authenticator App Login
What is it?
The authenticator app adds an extra security step when signing in.
After entering your email address and password, you will also enter a 6-digit code from an authenticator app on your phone, such as:
- 1Password
- Google Authenticator
- Microsoft Authenticator
This helps protect your account, even if someone knows your password.
Before you start
You will need:
- your normal Marlinspike login details
- a phone or device with an authenticator app installed
If your company requires extra login security, Marlinspike may ask you to set this up before you can continue.
Setting up the authenticator app
- Sign in to Marlinspike.
- Open your user settings.
- Go to the security section.
- Choose
Authenticator appas your preferred sign-in method. - Click the button to set up the app.
- A window will open with a QR code.
- Open your authenticator app and add a new account.
- Scan the QR code with your phone.
- Your app will show a 6-digit code.
- Enter that code in Marlinspike.
- Finish the setup.
After setup is complete, Marlinspike will also show backup codes.
Important: Save these backup codes in a safe place. They can help you sign in if you lose access to your phone.
[Add screenshot: security settings with “Set up authenticator app” button]
[Add screenshot: QR code setup window]
[Add screenshot: backup codes after setup]
Signing in with the authenticator app
Once setup is complete, signing in works like this:
- Enter your email address and password.
- Marlinspike will ask for a security code.
- Open your authenticator app.
- Find your Marlinspike account.
- Enter the current 6-digit code.
- Continue signing in.
[Add screenshot: login verification screen for authenticator app]
Using a backup code
If you do not have access to your authenticator app, you can use one of your backup codes instead.
To do this:
- Sign in with your email address and password.
- When Marlinspike asks for a security code, enter one of your saved backup codes.
- Continue signing in.
Important:
- each backup code can only be used once
- after using one, it will no longer work again
Removing the authenticator app
You can remove the authenticator app from your own account in your security settings.
If needed, an administrator can also remove it for you from the user management screen.
When the authenticator app is removed:
- login with app codes will stop working
- existing backup codes will also be removed
Notes for users working on local and online Marlinspike
You only need to set up the authenticator app once.
The same authenticator app can be used for both:
- the online Marlinspike environment
- the local Marlinspike environment
Troubleshooting
The code does not work
Check the following:
- you entered the newest 6-digit code
- the time on your phone is correct
- you scanned the correct QR code
- you are using the correct Marlinspike account in your app
If it still does not work, try a backup code.
I lost my phone
Use one of your backup codes to sign in.
If you do not have backup codes anymore, contact your administrator so they can remove the authenticator app from your account and let you set it up again.
I closed the backup code screen without saving them
If you are still signed in, remove the authenticator app and set it up again. A new set of backup codes will be shown during setup.
Summary
The authenticator app gives you a safer login process:
- sign in with password
- confirm with a code from your phone
- keep backup codes in case your phone is unavailable