Account & settings
Securing your account (2FA)
Add two-factor authentication to your staff login with an authenticator app, save your recovery codes, and optionally set up a passkey.
Updated Jul 23, 2026
Your TableStack login opens onto your guest book, your reservations, and your whole floor — so it's worth a second layer of protection. Two-factor authentication (2FA) means that even if someone learns your password, they still can't get in without your phone. Setting it up takes a couple of minutes.
Two-factor is opt-in per person today — each staff member turns it on for their own account. It's a good habit for anyone, and especially for managers and owners.
Turning on two-factor authentication
You'll need an authenticator app on your phone first — Google Authenticator, Microsoft Authenticator, 1Password, Authy, or any app that generates time-based codes (TOTP) all work.
- Go to Settings → Security.
- Confirm your current password when asked — this proves it's really you making the change.
- Under Two-factor authentication, select Enable 2FA.
- Scan the QR code that appears with your authenticator app.
- Enter the 6-digit code the app shows to confirm the connection.
From then on, each time you sign in you'll enter your password and then the current 6-digit code from your authenticator app.
Save your recovery codes
When you enable 2FA, TableStack gives you a set of recovery codes. These are your way back in if you ever lose your phone or can't open your authenticator app — without them, a lost phone can mean a locked account.
- Save them somewhere safe — a password manager is ideal; a printed copy in a secure place works too.
- Don't store them in the same place as your phone — that defeats the purpose.
- Each code works once. If you use some, or think they've been seen, regenerate a fresh set from the same Security page.
Treat these codes as seriously as the password itself.
Passkeys — a passwordless alternative
If you'd rather skip codes entirely, TableStack also supports passkeys. A passkey lets you sign in with your device's own security — a fingerprint, face, or screen unlock — instead of typing a password and a code. You can add one under Settings → Security → Passkeys, and you can register more than one (say, your phone and your laptop). Passkeys and an authenticator-app 2FA can both be set up; use whichever fits how you work.
What this affects
- Your login — after enabling 2FA, every sign-in on a new session asks for your authenticator code (or your passkey).
- Only your own account — turning on 2FA secures you; it doesn't change how your teammates sign in. Encourage them to do the same from their own Security settings.
What affects this
- Access to your authenticator app or passkey device — keep at least one available, and your recovery codes saved, so you're never locked out.
- Your role doesn't matter here — anyone with a login can and should secure their own account. For what each role can do inside TableStack, see Your team and their roles.