Two-Factor Authentication (2FA) adds an extra layer of security by requiring more than just an email address and password to log in.
Enabling Two-Factor Authentication
Tito does not send codes via SMS or email. Instead, 2FA on Tito requires the use of an authentication app on your smartphone. Some popular options are:
Once you have downloaded an authenticator app, log into Tito. Click on the Edit Profile link from the dropdown menu under your avatar in the top-right of the display.
Then click the Two-Factor Authentication button and then on Enable.
Open the authenticator app and scan the QR code that appears. The authenticator app will generate a 6-digit code. Type this code into the provided field and click Enable.
You have now enabled 2FA and will be asked for an authentication code each time you login.
Tito does not generate recovery codes by default when you enable 2FA. If you lose access to your authenticator app then you will lose access to your account. We recommend creating recovery codes.
Log in using Two-Factor Authentication
To log in to Tito, enter your email address, password, and authentication code from your authentication app (or a recovery code) and click Verify code.
Disabling Two-Factor Authentication
If you no longer wish to have 2FA enabled on your Tito account, click on the Edit Profile link from the dropdown menu under your name and email address in the top right of the display. Then click on Two-Factor Authentication and then on Disable.
You will then be able to log into Tito with just your email address and password.
Creating Recovery Codes
Recovery codes can be used to access Tito in the event you lose access to your authenticator app and cannot access 2FA codes. Head to the Two-Factor Authentication section and click Create recovery codes.
You will be shown 5 recovery codes only once so please copy them to a secure location, such as your password manager.
Once you have copied the recovery codes click I have copied the recovery codes.
A recovery code can be used in place of an authentication code from your app when you log in. Each recovery code can only be used once. To generate a fresh set of recovery codes, simply repeat the process above. Please be aware that all your previous recovery codes — including those you’ve not yet used — will become invalid.
What to do if you're locked out of your account
If you don’t have access to your authentication app or recovery codes, you’ll need to contact our support team. We will take you through an identity verification procedure before allowing you back into your account.
Still need help? Search our FAQs for instant answers. You can also leave a message for our support team by email or in-app, and we'll get back to you by the next working day.