creativehub supports three two-factor (2FA) channels: an authenticator app, text message (SMS), and an emailed code. All are optional. Enable any one, or several, in the Two-factor authentication card under Settings → Security.
Two-factor isn't checked on every login. Once enabled, you're re-prompted only every 14 days of inactivity.
Three channels
Authenticator app (recommended)
The most secure option, and it works offline. Use an app like Google Authenticator, 1Password or Authy.
- Under Authenticator app, click Enable.
- Scan the QR code in your authenticator app, or type the secret in manually.
- Enter the 6-digit code your app shows.
- Click Verify code. The factor is linked.
To turn it off later, click Disable in the same section.
Text message (SMS)
Uses Supabase Auth's native phone factor.
- Under Text message (SMS), enter your phone number with country code (e.g.
+44 7700 900123). - Click Send verification code.
- Enter the 6-digit code you receive by SMS.
- Click Verify code. The factor is verified.
Click Disable to remove it.
Email code
A 6-digit code emailed to your account email.
- Toggle the Email code switch on.
- We email a 6-digit code (10-minute expiry) to confirm you can reach the inbox you signed up with — this stops an attacker enabling email 2FA on a hijacked session.
- Enter the code and click Verify code. The switch flips on.
Toggle the switch off to disable. Disabling email 2FA isn't guarded by a code.
Enabling more than one
You can enable any combination. With more than one channel on, you choose which to use at sign-in — handy as a fallback if you lose access to one (e.g. you lose your phone but still have email).
There are no recovery or backup codes. Having a second channel enabled is the only built-in fallback, so consider turning on at least two.
At login
Once 2FA is enabled and you're due a check:
- Sign in with email and password as usual.
- You're sent to
/login/mfa. - If you have exactly one channel, the page goes straight to that channel's verify form. With more than one, pick a channel first (you can switch with Use a different method).
- Enter the 6-digit code and click Verify.
When a channel is auto-picked, the order of preference is authenticator app, then SMS, then email.
When to enable
- Always for admin / agency accounts — broader access means a bigger blast radius if compromised.
- For artist accounts with revenue — your saved card and Shopify store sit behind your account; 2FA adds a second wall.
- If you've reused passwords elsewhere — 2FA is the one mitigation that survives a password leak.
If you're locked out
There are no recovery codes. If you can't reach any of your enabled channels, contact help@theprintspace.co.uk from an email you can prove ownership of, and support can disable 2FA after identity verification.