Setting Up Two-Factor Authentication (2FA)
How to turn on 2FA for your Spark Shipping login, and what to do when a code won't go through or you're locked out.
Setting Up Two-Factor Authentication (2FA)
Two-factor authentication adds a second step to logging in. After your email and password, Spark Shipping asks for a 6-digit code before it lets you in, so a stolen password on its own isn't enough to get into your account.
2FA is required on every Spark Shipping account. There's no way to opt out of it, and support can't opt you out either.
What login looks like now
Sign in the way you always have, with your email and password. A second screen then asks for a 6-digit code. Type in the current code and you're in.
Your two options
Authenticator app. An app on your phone generates a new code every 30 seconds. This is the more secure option and the one we recommend. It also works when your email is slow or down, since the code never has to travel anywhere.
Emailed codes. Spark Shipping emails you a code each time you sign in. This is the easier one to start with. Just make sure you can always get to the inbox on your account.
Setting it up the first time
- Open your Profile page and click Enable Two Factor Authentication. If you were sent to the setup screen at login, you're already in the right place.
- Choose Authenticator app or Email.
- If you picked the app, scan the QR code on screen with your authenticator app. Can't scan it? Type in the setup key shown under the QR code instead. If you picked email, we send a code to your inbox.
- Enter the 6-digit code and your current password, then click Confirm and Enable.
- Spark Shipping shows you 10 backup codes. This is the only time you'll see them, so copy them somewhere safe before you leave the page. Each code works once. They're how you get back in if you lose your phone or can't reach your email.
Which authenticator apps work
Any standard one. Google Authenticator, Microsoft Authenticator, 1Password and Authy all work. If you already use one for another service, use that.
The app only needs to live on your phone. When you sign in on a computer, glance at your phone for the current code and type it in. There's nothing to install on the desktop.
Where emailed codes go
Codes go to the primary email on your account, which is the same address you log in with. If that inbox isn't one you check, update your account email in your profile settings and codes will start going to the new address.
The grace period
New accounts get 7 days from the day the account was created to set 2FA up. Existing accounts were given a window when the requirement rolled out, counted from the day it was applied. Either way, the reminder banner at the top of the page tells you how much time is left.
During that window you can keep working as usual. Once it runs out, Spark Shipping sends you to the setup screen at login and keeps doing so until 2FA is enabled. Your account isn't locked, and there's nothing support needs to unlock. Finish the setup and you're back in.
Switching from email to the app (or back)
There's no switch to flip once 2FA is on. To change methods, go to your Profile page, turn 2FA off, then set it up again and pick the other option. Since 2FA is required, Spark Shipping will ask you to set it up again right away, so do the two steps back to back. You'll get a fresh set of backup codes at the end, and the old ones stop working.
You don't need to contact support for this as long as you can still log in.
Shared logins
If several people at your company sign in with the same email and password, 2FA is going to get in the way. The code goes to one inbox or one phone, and everyone else is stuck waiting on that person. Give each person their own login instead. 2FA is set per user, so each team member enrolls with their own phone or inbox, and each new team member gets their own 7-day window. See Adding and Managing Team Members for how to invite them and which role to give them.
If a code says it's invalid
You're looking in the wrong inbox. Codes go to your account's primary email, which may not be the address you expected. Check the address you actually sign in with.
The email landed in spam. Check your spam or junk folder, then click send a new code and try again.
Your password doesn't meet the current minimum requirements. The setup step asks for your password as well as the code. If your password predates the new requirements, the code can keep failing even when it's correct. Reset your password, then try again.
Your phone's clock is off. Authenticator codes depend on the time. Make sure your phone is set to update its clock automatically.
If you're fully locked out
Try one of your saved backup codes on the code screen. Each of the 10 works once, so cross it off after you use it. If you're out of them, or you never saved them, contact Spark Shipping support. We can reset 2FA on your account so you can set it up fresh, and you'll get a new set of backup codes when you do.