Two-step sign-in & devices
Two-step sign-in with an authenticator app, recovery codes, lost phone resets by email or via Support, security alerts on LINE and devices, and signing out devices.
- What is two-step sign-in?
- How do I turn it on?
- How do I sign in with two-step sign-in on?
- What are recovery codes?
- How do I change phones or turn it off?
- Lost your phone and your recovery codes?
- Which security emails do I get?
- Security alerts on LINE and your devices
- Opening BoardMark from LINE
- How do I see and sign out my devices?
- Does two-step sign-in affect AI agents?
What is two-step sign-in?
Besides your password or your Google / Microsoft / LINE account, you also enter a 6-digit code from an authenticator app on your phone, so someone who gets your password still cannot get in. It is free on every plan, and each person turns it on for their own account in Settings → Two-step sign-in.
It works with any TOTP app — Google Authenticator, Microsoft Authenticator, 1Password, Authy, Bitwarden and others. The code in the app changes every 30 seconds, and a code that was already used cannot be used again.
How do I turn it on?
- Open Settings → Two-step sign-in and press Turn on
- Step 1 of 3: scan the QR code with your authenticator app (in the app, tap + → scan a QR code). Can't scan? Copy the key and enter it in the app instead
- Step 2 of 3: enter the 6-digit code the app shows for “BoardMark (your email)”
- Step 3 of 3: save your 10 recovery codes — Download .txt, Copy or Print — tick “I have saved my recovery codes” and press Done
Finish within 15 minutes, or start again for a new key. From then on every new sign-in asks for a code from the app, and we email you that two-step sign-in is on.
How do I sign in with two-step sign-in on?
Sign in as usual — with a password, Google, Microsoft or LINE, or when you restore a deleted account (welcome back) — and BoardMark then asks for the 6-digit code from your app. You can paste the whole code; it is sent as soon as all 6 digits are in.
- “Remember this device for 30 days” (on to start with) skips the second step in this browser for 30 days; you can sign that browser out in Settings → Devices signed in
- 5 wrong codes per sign-in and 15 minutes to finish — after that, sign in again
- Phone not with you? Press Use a recovery code instead
- If every code is wrong, check that your phone's time is set automatically
What are recovery codes?
When you turn it on you get 10 recovery codes (like k7qm-2xvd). Each works once in place of an app code, for when you lose your phone. They are shown only once — keep them in a password manager or print them.
- Settings → Two-step sign-in shows how many are left and warns you when you are running out
- New set makes 10 new codes, and every code of the old set stops working at once
- Each time a recovery code is used to sign in, we email you how many are left
- Upper or lower case, spaces and the dash do not matter when you type one
How do I change phones or turn it off?
In Settings → Two-step sign-in: Change app sets up the authenticator app on a new phone (codes from the old app stop working; your recovery codes stay as they are), New set makes new recovery codes, and Turn off goes back to just a password or your Google / Microsoft / LINE account. Each asks for a code from your app first (Turn off also takes a recovery code). Turning it off also forgets every remembered device, and every change is emailed to you.
Lost your phone and your recovery codes?
On the second step of signing in, press Lost my phone and have no recovery codes. We email a 6-digit code to your address; enter it and press Confirm and start the 24 hours. Two-step sign-in is then turned off after a 24-hour wait, so the real owner has time to cancel if it was not them.
- We email you as soon as the request is made, and again about 1 hour before the 24 hours end; the page shows the time left
- After 24 hours, sign in as usual: no second step is asked, two-step sign-in is turned off and your recovery codes removed, every device is signed out, remembered devices are forgotten, and we email you
- Not you? Press Cancel the request in the email (no sign-in needed), or sign in with a code from your app or a recovery code — the request is cancelled at once. While you are signed in, Settings → Two-step sign-in has Cancel the request too
- One pending request per account; a new email code can be sent every 2 minutes
Can't get into your email either? Contact Support (the Can't sign in? Tell us link on the sign-in page). The BoardMark team can ask for it to be turned off once it is confirmed that it is really you. It is never immediate.
- If your company has another company admin, one of them gets an email and a bell notice, opens the confirmation page in the web app and confirms it is you with a code sent to the admin's own email (or answers no, which cancels the request). They have 72 hours to answer
- If not, the BoardMark team checks your identity itself (a video call or documents) and another team member approves it, also within 72 hours
- Once it is confirmed, the same 24-hour wait as the email reset starts; it turns off at your first sign-in after that. With no answer within 72 hours the request expires
- You are told at every step by email, LINE and on your devices. Not you? Press Cancel the request, or sign in with a code from your app or a recovery code — the request is cancelled at once
Which security emails do I get?
Every change is emailed to you, in English then Thai. These are account security emails: always sent, and they cannot be turned off.
- Two-step sign-in turned on, or turned off
- Authenticator app changed
- New recovery codes made
- A recovery code was used to sign in (with how many are left)
- Someone asked to turn it off because of a lost phone (with a Cancel the request button), and the reminder 1 hour before
- The BoardMark team received a request to turn it off, it was confirmed (with when it turns off), or it was cancelled (by you, a company admin, the team, or because it expired)
- Company admins: a member's request is waiting for you to confirm it is them
- Turned off after the 24-hour wait
Wrong codes do not send an email.
Security alerts on LINE and your devices
Every two-step security email above also goes to LINE and to your devices (Web Push), on every plan, and these cannot be switched off. A notice with a Cancel the request link has the same button as the email.
- LINE: when you have linked LINE (Settings → Sign-in methods) and are a friend of the BoardMark LINE Official Account — no Premium needed (LINE notifications about issues stay Premium)
- Devices: every device where you turned on notifications (Settings → Notifications), even when other kinds are switched off in the Device column
Opening BoardMark from LINE
Links you tap in a LINE chat open in LINE's own browser.
- Two-step sign-in still applies — coming from LINE does not skip the second step
- “Remember this device for 30 days” is already ticked; LINE's browser remembers separately from Safari / Chrome
- Google does not allow signing in inside LINE's browser: the Google button says so and offers Open in Safari / Chrome, which opens the same page in your normal browser. Signing in with your email and password works as usual
How do I see and sign out my devices?
Settings → Devices signed in lists every browser and phone signed in to your account — such as Chrome · macOS — with when it signed in and when it was last active. This device is marked, and so are remembered devices (no second step for 30 days). It works whether or not two-step sign-in is on.
- Sign out on a row signs that device out at once (for the device you are using, sign out the usual way)
- Sign out all other devices signs out every other browser and phone and clears “remember this device” on them; this device stays signed in
Does two-step sign-in affect AI agents?
No. Two-step sign-in protects signing in to the web app. AI agent tokens — personal access tokens and AI clients already connected — keep working; manage them on the Agent & MCP access page. Turning two-step sign-in on or off, recovery codes and signed-in devices are web app only: AI agents cannot touch them over MCP.