Skip to main content

Two-factor authentication

Add a second sign-in step with an authenticator app, and how an organisation can require it for every operator.

Bookboost holds guest and reservation data, so a single leaked or reused password is worth closing off. Two-factor authentication adds a second step to signing in: your password, then a six-digit code from an authenticator app. Anyone can turn it on for their own login, and an organisation can require it for every operator.

What it does

  • Adds a six-digit, time-based code from an authenticator app as a second sign-in step, alongside your password.

  • Works with any app that supports the standard time-based one-time-password (TOTP) method, including Google Authenticator, 1Password, and Authy.

  • Is off by default for each operator, and can also be required for everyone in an organisation.

  • Once required, an operator without a second factor is enrolled the next time they sign in, before they can reach the platform or its data.

  • Enrolments and resets are recorded in the organisation's authentication events, alongside logins and logouts.

How to set this up?

Setting it up for yourself. Go to Settings > Operators and open your own profile, then select Add 2FA. Scan the QR code shown (or enter the setup key by hand) in your authenticator app, then enter the six-digit code it generates to confirm.

Requiring it for your organisation. This is switched on for the whole organisation at once. There is no self-service control for it yet, so contact support to have it turned on. Once it is on, any operator who has not already set up a second factor is taken straight to the setup screen the next time they sign in, and cannot reach the platform until they complete it.

What this does not do

  • It is all-or-nothing for an organisation. Two-factor authentication cannot be required for some operators and not others, and cannot be limited to specific properties.

  • There are no printed backup codes. Recovery codes written down beside a shared reception desk would undermine the second factor, so there are none to lose. If you lose your authenticator, for example a lost or wiped phone, contact support to reset your second factor so you can set up a new one.

  • Turning the organisation-wide requirement on, and resetting a lost second factor, currently go through Bookboost. Self-service admin controls for both are on the roadmap, not available yet.

What to do next

If Bookboost is asking for a code you cannot produce, or you cannot get in at all, see Why can't I log in?.

Getting help

Open Help at the bottom of the left menu and choose Talk to Us, or email support@bookboost.io.

Did this answer your question?