Setting up two-factor authentication
How to turn on 2FA for your staff accounts and what to do when someone loses their phone.
Updated June 4, 2026
Two-factor authentication (2FA) adds a second step to login, on top of a password. It is the single most effective protection against your account being compromised.
Who should turn it on
- Owners and admins. Required.
- Front desk and instructors. Strongly recommended.
- Parents. Optional, but every guardian account supports it.
How to turn it on
In the staff app, click your profile picture in the top right, then Security. Click Set up two-factor.
You will see a QR code. Scan it with an authenticator app:
- Google Authenticator (iOS and Android, free)
- 1Password (iOS, Android, desktop)
- Authy (iOS, Android, desktop)
- Microsoft Authenticator (iOS, Android, free)
The app generates a new 6-digit code every 30 seconds. Enter the current code in Rosterra to confirm setup is correct.
Save the 8 backup codes that Rosterra shows you. Print them, put them in a safe. They are your way back in if you lose your phone.
Logging in with 2FA on
- Email and password as usual.
- Rosterra prompts for a 6-digit code.
- Open your authenticator app, find Rosterra, type the code.
- Logged in.
You can mark a browser as trusted for 30 days so you do not get prompted every login from the same computer.
What happens when you lose your phone
Two paths:
- You saved your backup codes. Use one of them at the 2FA prompt. Re-set up 2FA from a new phone immediately after.
- You did not save backup codes. Contact another owner or admin at your school. They can disable your 2FA from the staff page. If you are the only owner, contact the Rosterra team and they will verify your identity (multiple checks) before disabling.
Requiring 2FA for staff
Owners can require 2FA for all staff at /settings/security. Toggling this on forces every staff member to set up 2FA on their next login. Strongly recommended if you have any sensitive data (you do; you have payment info and minors' info).
What about families?
Guardian accounts also support 2FA. They turn it on themselves at /portal/account/security. Optional for families; most do not enable it. But if a family is concerned about account security (a co-parent issue, for example), they can.
Why not SMS-based 2FA?
Authenticator-app 2FA is more secure than SMS. SMS is vulnerable to SIM swapping (an attacker convinces the phone company to move your number to their phone). Authenticator apps live entirely on your device; SIM swapping does not affect them.
For this reason, Rosterra does not offer SMS as a 2FA factor.
