Bookboost holds guest and reservation data, so a single leaked or reused password is worth closing off. Two-factor authentication adds a second step to signing in: your password, then a six-digit code from an authenticator app. Anyone can turn it on for their own login, and an organisation can require it for every operator.
What it does
Adds a six-digit, time-based code from an authenticator app as a second sign-in step, alongside your password.
Works with any app that supports the standard time-based one-time-password (TOTP) method, including Google Authenticator, 1Password, and Authy.
Is off by default for each operator, and can also be required for everyone in an organisation.
Once required, an operator without a second factor is enrolled the next time they sign in, before they can reach the platform or its data.
Enrolments and resets are recorded in the organisation's authentication events, alongside logins and logouts.
How to set this up?
Setting it up for yourself. Go to Settings > Operators and open your own profile, then select Add 2FA. Scan the QR code shown (or enter the setup key by hand) in your authenticator app, then enter the six-digit code it generates to confirm.
Requiring it for your organisation. This is switched on for the whole organisation at once. There is no self-service control for it yet, so contact support to have it turned on. Once it is on, any operator who has not already set up a second factor is taken straight to the setup screen the next time they sign in, and cannot reach the platform until they complete it.
What this does not do
It is all-or-nothing for an organisation. Two-factor authentication cannot be required for some operators and not others, and cannot be limited to specific properties.
There are no printed backup codes. Recovery codes written down beside a shared reception desk would undermine the second factor, so there are none to lose. If you lose your authenticator, for example a lost or wiped phone, contact support to reset your second factor so you can set up a new one.
Turning the organisation-wide requirement on, and resetting a lost second factor, currently go through Bookboost. Self-service admin controls for both are on the roadmap, not available yet.
What to do next
If Bookboost is asking for a code you cannot produce, or you cannot get in at all, see Why can't I log in?.
Getting help
Open Help at the bottom of the left menu and choose Talk to Us, or email support@bookboost.io.