Add a second step to signing in

Enrol an authenticator app and every protected page requires the code, including a password reset. It fails closed rather than open.

Walkthrough · 3 min read

Your workspace holds signed approvals, client contact details and the record of who owes you money. If someone reaches your inbox, they reach all of it — which is the argument for a second step that does not travel by email.

  1. Open Settings and find the two-step sign-in panel.
  2. Scan the QR code with any authenticator app.
  3. Enter the six-digit code it shows to confirm the app and Stria agree.
  4. Keep the app. From now on, signing in asks for a code from it.

Once a second factor is verified it applies to the entire signed-in area rather than to particular pages. A session that has authenticated but not yet cleared the second step is treated as not signed in at all, including a session restored from a previous visit. That is a deliberate choice: a check that covered most pages would be a check somebody could route around.

Resetting your password also asks for the code. Without that, the emailed recovery link would be a documented way past the second step, since possession of the inbox alone would be enough to change the password and get in. The same challenge is used in both places rather than a weaker version for recovery.

Important: Losing the authenticator app locks you out, and there is no way for anyone at Stria to code around it — that is what makes it worth having. Store the recovery option your authenticator offers, or enrol on a second device you keep, before you rely on it.

Note: Signing in normally uses an emailed one-time code rather than a password, so there is no password to reuse or leak. You can set one if you prefer, and the second step applies either way.

Open Settings — in your Stria workspace.

Read the security overview — in your Stria workspace.

More on account and plans

Start your 14-day trial · All help articles · Email support