Securing Your Account with Two-Factor Authentication

Last updated August 5, 2026

Two-factor authentication (2FA) adds a second layer of protection to your account. Even if someone gets hold of your password, they still can't log in without the time-based code from your authenticator app. For travel advisors, this matters — your account holds client personal data, payment records, and commission information worth protecting.

What You'll Need

Any TOTP-compatible authenticator app:

  • Google Authenticator (iOS / Android)
  • Authy (iOS / Android / Desktop)
  • 1Password (iOS / Android / Mac / Windows)
  • Microsoft Authenticator (iOS / Android)
  • Any other TOTP-compatible app

Enabling 2FA on Your Account

  1. Go to Settings → Profile
  2. Scroll to the Security section
  3. Click Enable next to "Authenticator app"
  4. Scan the QR code with your authenticator app
    • Can't scan? Click "Can't scan? Enter code manually" to get the text secret instead
  5. Enter the 6-digit code shown in your app
  6. Click Verify and enable

That's it. From now on, after entering your password you'll be prompted for a code from your app.

Disabling 2FA

  1. Go to Settings → Profile → Security
  2. Click Disable next to "Authenticator app"
  3. Confirm when prompted

Note: If your agency owner has required 2FA for the team, you won't be able to disable it until they remove that requirement.

Logging In with 2FA

After entering your email and password, JourneyFuse will prompt you for your 2FA code. Open your authenticator app, find the JourneyFuse entry, and enter the 6-digit code shown. Codes refresh every 30 seconds — if a code isn't working, wait for the next one.

You are only asked for a code when you sign in, not while you are working. Staying signed in on a browser keeps you signed in.

Remembering a Device

If you sign in often on the same computer, tick Remember this device for 30 days on the code screen. That browser skips the code prompt for the next 30 days, while any new computer, phone, or private window still asks for one.

Use it only on devices that are yours. A shared front-desk computer should not be remembered.

Managing Remembered Devices

Go to Settings → Profile → Security → Remembered devices to see every browser currently skipping the code, when it was added, and when it was last used. Remove one, or click Remove all to require a code everywhere on the next sign-in.

Remembered devices are cleared automatically whenever your account's security changes: turning 2FA off, or changing your password.

Two things a remembered device does not skip: viewing a saved card number and changing your password. Both always ask for a fresh code, even on a device you trust.

If You Lose Access to Your Authenticator App

Contact JourneyFuse support at support@journeyfuse.com. We'll verify your identity and help you regain access to your account.


For Owners & Admins: Requiring 2FA for Your Team

You can require all agents on your team to set up 2FA before they can access JourneyFuse.

Turning On the Requirement

  1. Go to Settings → Agency & Branding → Team & Portal
  2. Scroll to the Team Security card
  3. Toggle Require two-factor authentication to ON

What Happens Next

  • Agents who already have 2FA — no change, they continue working normally
  • Agents who don't have 2FA — on their next login, they'll be redirected to set it up before they can access the app. They cannot skip or dismiss this prompt

Turning It Off

Toggle the same switch to OFF in Settings → Agency & Branding → Team & Portal → Team Security. Agents can then disable 2FA on their own accounts if they choose.

Recommendation: Requiring 2FA is a good practice for any agency storing client financial data or personal information. It takes agents about two minutes to set up and significantly reduces the risk of unauthorized access.