How to Activate Two-Factor Authentication
HOME> Setup > Users
Two-Factor Authentication (2FA) adds an extra layer of security to your GuestCentric account by requiring a 6-digit verification code from an authentication app in addition to your login credentials. Important Notes Before Getting Started
- Individual: Must be activated individually by each user on their own account. Hoteliers or administrators cannot activate it on behalf of another user
- Mandatory: From November 30, 2026, having Two-Factor Authentication (2FA) enabled will be mandatory for all users
- Requirements: You must have an authentication app installed on your personal device/phone prior to starting setup.
Examples: Google Authenticator, Microsoft Authenticator, Twilio Authy...
A) How to enable 2FA [step-by-step]
You do not need to be in "Edit" mode on your user profile.
Both enabling and disabling 2FA can be done directly from the View page using the corresponding button.
1. Log in to GuestCentric using your own credentials
2. In the top-right corner, navigate to: Setup > Administration > Users
3. Select your user profile to open the View page
4. Under the Security section, click the Enable Two Factor Authentication button. A popup modal will appear displaying a QR code along with instructions
5. Open your mobile authentication app and scan the QR code displayed on the screen
6. Enter the 6-digit verification code generated by your app into the modal prompt
7. Click Verify to complete the setup
8. Recovery Codes: Save Your Backup!
9. Once a valid verification code is entered, a popup modal will display eight 12-digit recovery codes
Note: The 6-digit code is valid for approximately 90 seconds. If you scan the QR code but close the modal without entering the code, the connection between your email and 2FA will not complete, and you will need to restart the process
Recovery Codes: What are they for?
Recovery codes are one-time-use backups in case you lose access to your phone or authentication app.
You must save these recovery codes in a secure location and confirm in the modal that you have saved them before closing it.
Usage Rules:
- Each recovery code can be used only once
- Using a recovery code logs you in securely without disabling 2FA
- An email notification will be sent to you whenever a recovery code is used
- When your last recovery code is used, you will receive notification on how to obtain new ones
B) How to connect a "New Device"
If you get a new phone or need to switch to a different authentication app:
1. Go to your user profile (Setup > Administration > Users)
2. Click the Link new device button on your profile view page
3. Follow the onscreen prompt to scan the new QR code and verify the new device
C) How [2FA] works at login
1. Go to the login page, enter your email address and password, and click Login to Account. A prompt will appear asking for the 6-digit code from your authentication app.
2. Open your authentication app, copy the current 6-digit code, and enter it in the verification field to log in.
Additional Login Options: Below the login button, you will see two links:
- "Sign in to a different account": Takes you back to the main login page.
- "Use recovery code": Prompts you to enter one of your saved 12-digit recovery codes if you do not have access to your phone/app.
Frequently Asked Question (FAQ)
Q: WILL I NEED TO ENTER THE 2FA CODE EVERY SINGLE TIME I LOG IN?
Not necessarily. You can select the option to remember the device on your browser.
However, you will still be prompted to enter a 2FA code in the following situations:
- Every 30 days (periodic security check)
- When logging in from a different country
- After clearing your browser cache/cookies or revoking access for that browser
Didn't find your answer?
If you have any questions or need assistance setting up 2FA, please reach out to our support team. We're here to help!