Help › Settings
Two-factor authentication and your recovery codes
Two-factor authentication means signing in takes your password and a six-digit code from an app on your phone. Someone who learns your password still cannot get in.
It is optional for the account as a whole, and required before you connect a bank. A bank connection brings your transactions and balances into TALISK_HQ, and a password on its own is not enough to stand in front of that.
Turn it on
- Go to Settings › My Account, section Two-Factor Authentication.
- Click Enable Two-Factor Authentication.
- Scan the QR code with an authenticator app on your phone: Google Authenticator, Authy, 1Password and Microsoft Authenticator all work. If the camera will not cooperate, open Can't scan? Enter manually and type the key in by hand.
- Enter the six digits the app is showing under Verification code and click Verify & Enable.
- TALISK_HQ shows your recovery codes. Save them before you carry on, as described below.
Your recovery codes
You get eight of them, and they are the way back into your account if you lose the phone with your authenticator app on it. Each one works a single time.
They are shown once and never again. TALISK_HQ keeps only a scrambled copy, so this is not a case where support can read them out to you later: nobody here can see them. Use Copy to put them on the clipboard, or Download to save them as a file. Keeping them in a password manager is ideal. Keeping them only on the same phone as the authenticator app is not, because losing that phone then costs you both at once.
TALISK_HQ will not let you leave the screen until you say you have saved them. That is deliberate, and it is the one time we get in your way on purpose.
Signing in once it is on
Enter your email and password as usual. TALISK_HQ then asks for a Two-factor code: open your authenticator app and type the six digits it shows for TALISK_HQ. The code changes every thirty seconds, so if it is about to roll over, wait for the next one.
If you lose your authenticator app
On the code screen, use Lost access to your authenticator? Use a recovery code. Enter one of your saved codes and you are in. That code is then spent, so once you are signed in, generate a fresh set.
If you have lost your recovery codes too
There is a way back, and it starts from the sign-in screen. Sign in with your email and password as usual, and on the code screen follow Lost access to your authenticator? Use a recovery code, then Don't have a recovery code? Verify your identity instead.
TALISK_HQ asks you to confirm the email address on your account, then shows you a number between one and five. Photograph two things: your government photo ID, and yourself holding up that many fingers. The number is what proves the selfie was taken just now, for this request, so take the photo after you see it rather than using one you already had.
Send them, and a person here checks the ID against your account. This is not instant, and it is not meant to be: it is the only step standing between a stranger and your books. You get an email when it is decided.
When it is approved, two-factor authentication is switched off on your account so you can sign straight in with just your email and password. Turn it back on and save the new recovery codes before you carry on.
TALISK_HQ keeps the two photos encrypted, uses them only to confirm who you are, and destroys them 90 days after the decision. The record that you asked and what was decided is kept.
If the photos are hard to read, or the selfie does not show the number of fingers we asked for, the request is turned down and you can get in touch directly.
Get a new set of recovery codes
Go to Settings › My Account and click Generate new recovery codes. Confirm your password, and the new set appears. Save it the same way.
Do this whenever you have used one, whenever you are not certain your saved copy is still somewhere you can reach, or if you were never shown a set in the first place. Generating a new set replaces every unused code you had, so an old list you no longer trust stops working the moment you do it.
Your existing codes cannot be recovered or re-displayed, only replaced. That is the same property that makes them safe to store, so replacing them is the answer whenever there is any doubt.
Turn it off
Settings › My Account, then Disable 2FA. You confirm your password first.
Turning it off deletes your recovery codes along with it, which is what you want: they are no use without the app they back up, and leaving them alive would be a surprise the next time you switch two-factor authentication on. You get a completely new set when you do.
Bear in mind that you cannot connect a bank while it is off. Existing bank connections carry on working normally.