Set up 2FA

2FA is mandatory for every Schoolysoft account.

Option 1 — TOTP app (recommended)

Compatible apps: Google Authenticator, Authy, Microsoft Authenticator, 1Password.

  1. Log in with your password.
  2. The 2FA setup page appears.
  3. In your TOTP app: tap + -> Scan a QR code.
  4. Scan the QR code shown.
  5. Enter the 6-digit code -> click Confirm.

Tolerance window

Schoolysoft accepts TOTP codes within a tolerance of +/- 60 seconds around the current time. This covers small clock drifts without weakening security. If your code is consistently rejected beyond this window, resync your phone’s clock.

Recovery codes

After setup, 8 single-use codes are provided. Store them in a password manager.

Option 2 — FIDO2/WebAuthn key (mandatory for Super Admin)

Compatible keys: YubiKey 5, Google Titan, TouchID/FaceID.

  1. Choose Use a security key.
  2. Insert the YubiKey or activate TouchID.
  3. Touch the key’s button when it blinks.

Common problems

SymptomLikely causeSolution
Code rejected (“The code you entered was not recognised”)Clock drift, or expired codeCheck your authenticator app and try again with the code currently shown
Code rejected every timeClock drift > 60 sSync the phone’s clock
App deletedPhone lostUse a backup code
Key not recognisedBrowser without WebAuthnUse Chrome, Firefox, Safari or Edge

Error messages are intentionally generic (e.g. “The code you entered was not recognised”), without detail on the exact cause, for security reasons.

  • Phone lost: use a recovery code to log in. Regenerating recovery codes is available in My account -> Security, but reconfiguring MFA (changing method or device) is not self-service.
  • No backup codes left / authenticator lost with no code available: contact Schoolysoft support — only support can reset a user’s MFA. Your school’s administrator cannot perform this reset.