SalesThumb supports two independent two-factor methods — an authenticator app (1Password, Authy, Google Authenticator, etc.) and SMS text codes. You can turn on either one, both, or neither. Manage them from Settings → Security (/app/settings/security).
Turning on both isn't redundant — each is a separate factor you can lose independently (phone lost vs. phone number changed), and having both gives you a fallback if one becomes unavailable.
Setting up your first factor
For the authenticator app: click "Set up authenticator app," then either scan the QR code with your app or paste the secret shown below it manually (there's also a raw otpauth:// link if you're setting it up on a paired device). Enter the 6-digit code your app generates into the "Verification code" field and click Verify.
For SMS: enter your phone number and click "Send code." A 6-digit code arrives by text and expires in 10 minutes — enter it and click Verify, or use "Resend code" if it doesn't arrive in time.
The first time you verify either method — when you have zero factors active — SalesThumb generates 10 backup codes and shows them to you once, immediately after verification. Copy or write them down before navigating away; there's no way to view them again later without regenerating a fresh set.
Adding a second factor
If you already have one factor active and go to set up the other, the form adds an extra field: "Enter your SMS or backup code to add an authenticator app" (or the mirror version for adding SMS). You need a live code from your existing factor, or a backup code, before the new factor will even be sent or saved. This exists specifically so that a hijacked, already-logged-in session can't silently register an attacker's own phone or authenticator app as a second factor — first-time setup skips this because there's nothing yet to protect. Note that backup codes granted on setup are shared across both methods, not tied to one or the other, and a second-factor enrollment does not mint a new set — you keep using the original 10.
Backup codes and removing a factor
Under "Backup codes," you can regenerate your 10-code set at any time (this invalidates the old codes) using an authenticator, SMS, or backup code to authorize it.
There's no way to remove just the authenticator app while keeping SMS — the page states this directly: to drop the authenticator app, use "Disable 2FA" (which turns off both at once) and then set SMS back up. Removing SMS on its own is supported via the "Remove" button on the SMS card, but it only leaves the account still protected if the authenticator app is also configured; if SMS is your only factor, removing it is treated as a full 2FA teardown rather than leaving the account in a half-enabled state.
If your organization requires 2FA, "Disable 2FA" and SMS removal are both blocked until the requirement is lifted — you'll see an "Org policy" badge explaining why.
Active sessions
Below your 2FA settings, "Active sessions" lists every device currently signed in, with a rough browser/OS guess and last-active date. You can sign out any single device, or use "Sign out all other devices" to keep only your current session. This is independent of 2FA — it's available whether or not you've enrolled a factor.