How to set up two-factor authentication

creativehub supports three two-factor (2FA) channels: an authenticator app, text message (SMS), and an emailed code. All are optional. Enable any one, or several, in the Two-factor authentication card under Settings → Security.

Two-factor isn't checked on every login. Once enabled, you're re-prompted only every 14 days of inactivity.

Three channels

The most secure option, and it works offline. Use an app like Google Authenticator, 1Password or Authy.

  1. Under Authenticator app, click Enable.
  2. Scan the QR code in your authenticator app, or type the secret in manually.
  3. Enter the 6-digit code your app shows.
  4. Click Verify code. The factor is linked.

To turn it off later, click Disable in the same section.

Text message (SMS)

Uses Supabase Auth's native phone factor.

  1. Under Text message (SMS), enter your phone number with country code (e.g. +44 7700 900123).
  2. Click Send verification code.
  3. Enter the 6-digit code you receive by SMS.
  4. Click Verify code. The factor is verified.

Click Disable to remove it.

Email code

A 6-digit code emailed to your account email.

  1. Toggle the Email code switch on.
  2. We email a 6-digit code (10-minute expiry) to confirm you can reach the inbox you signed up with — this stops an attacker enabling email 2FA on a hijacked session.
  3. Enter the code and click Verify code. The switch flips on.

Toggle the switch off to disable. Disabling email 2FA isn't guarded by a code.

Enabling more than one

You can enable any combination. With more than one channel on, you choose which to use at sign-in — handy as a fallback if you lose access to one (e.g. you lose your phone but still have email).

There are no recovery or backup codes. Having a second channel enabled is the only built-in fallback, so consider turning on at least two.

At login

Once 2FA is enabled and you're due a check:

  1. Sign in with email and password as usual.
  2. You're sent to /login/mfa.
  3. If you have exactly one channel, the page goes straight to that channel's verify form. With more than one, pick a channel first (you can switch with Use a different method).
  4. Enter the 6-digit code and click Verify.

When a channel is auto-picked, the order of preference is authenticator app, then SMS, then email.

When to enable

  • Always for admin / agency accounts — broader access means a bigger blast radius if compromised.
  • For artist accounts with revenue — your saved card and Shopify store sit behind your account; 2FA adds a second wall.
  • If you've reused passwords elsewhere — 2FA is the one mitigation that survives a password leak.

If you're locked out

There are no recovery codes. If you can't reach any of your enabled channels, contact help@theprintspace.co.uk from an email you can prove ownership of, and support can disable 2FA after identity verification.

Still need a hand?

Ask the in-app help assistant from your creativehub dashboard, or email us — a real person replies. info@theprintspace.co.uk